Module Name
Juniper Networks SRX345/SRX345-DUAL-AC with Junos 15.1X49-D110
Validation Dates
07/25/2018
Caveat
When operated in FIPS mode and with tamper-evident seals installed as indicated in the Security Policy
Security Level Exceptions
- Roles, Services, and Authentication: Level 3
- Design Assurance: Level 3
- Mitigation of Other Attacks: N/A
Embodiment
Multi-Chip Stand Alone
Description
The Juniper Networks SRX Series Services Gateways are a series of secure routers that provide essential capabilities to connect, secure, and manage work force locations sized from handfuls to hundreds of users. By consolidating fast, highly available switching, routing, security, and applications capabilities in a single device, enterprises can economically deliver new services, safe connectivity, and a satisfying end user experience.
FIPS Algorithms
AES |
Certs. #4941, #4942 and #4943 |
CKG |
vendor affirmed |
CVL |
Certs. #1542 and #1543 |
DRBG |
Cert. #1770 |
ECDSA |
Certs. #1264 and #1267 |
HMAC |
Certs. #3289, #3290 and #3291 |
KTS |
AES Certs. #4941 and #4943 and HMAC Certs. #3289 and #3291; key establishment methodology provides between 128 and 256 bits of encryption strength |
KTS |
Triple-DES Certs. #2568 and #2570 and HMAC Certs. #3289 and #3291; key establishment methodology provides 112 bits of encryption strength |
RSA |
Certs. #2688 and #2693 |
SHS |
Certs. #4030, #4031, #4032 and #4033 |
Triple-DES |
Certs. #2568, #2569 and #2570 |
Allowed Algorithms
Diffie-Hellman (CVL Certs. #1542 and #1543, key agreement; key establishment methodology provides 112 bits of encryption strength); EC Diffie-Hellman (CVL Certs. #1542 and #1543, key agreement; key establishment methodology provides 128 or 192 bits of encryption strength); NDRNG
Hardware Versions
SRX345, SRX345-DUAL-AC with JNPR-FIPS-TAMPER-LBLS
Firmware Versions
JUNOS-FIPS-MODE 15.1X49-D110