Module Name
Panorama 8.1 M-100, M-200, M-500 and M-600
Validation Dates
09/19/2019
Caveat
When operated in FIPS mode and with the tamper evident seals and opacity shields installed as indicated in the Security Policy. The module generates cryptographic keys whose strengths are modified by available entropy
Security Level Exceptions
- Design Assurance: Level 3
- Mitigation of Other Attacks: N/A
Embodiment
Multi-Chip Stand Alone
Description
Panorama on the M-100, M-200, M-500 and M-600 provides centralized management and visibility of multiple Palo Alto Networks next-generation firewalls and supports distributed management and logging functions. It allows you to oversee all applications, users, and content traversing the network and then create application enablement policies that protect and control the entire network. The M-500 and M-600 provide an additional service, the PAN-DB private cloud, which is an on-premise solution suitable for organizations that prohibit or restrict the use of the PAN-DB public cloud service.
FIPS Algorithms
AES |
Cert. #5890 |
CKG |
vendor affirmed |
CVL |
Certs. #2119, #2120, #2121 and #2122 |
DRBG |
Cert. #2451 |
DSA |
Cert. #1485 |
ECDSA |
Cert. #1570 |
HMAC |
Cert. #3865 |
KAS |
SP 800-56Arev2 with CVL Certs. #2119 and #2120, vendor affirmed |
KTS |
AES Cert. #5890; key establishment methodology provides 128 or 256 bits of encryption strength |
KTS |
AES Cert. #5890 and HMAC Cert. #3865; key establishment methodology provides between 128 and 256 bits of encryption strength |
RSA |
Cert. #3086 |
SHS |
Cert. #4641 |
Allowed Algorithms
Diffie-Hellman (CVL Cert. #2119 with CVL Cert. #2120, key agreement; key establishment methodology provides 112 bits of encryption strength); MD5; NDRNG; RSA (CVL Cert. #2121, key wrapping; key establishment methodology provides 112 or 128 bits of encryption strength)
Hardware Versions
P/Ns 910-000030 Version 00D [1], 910-000092 Version 00D [1], 910-000176 Version 00A [2], 910-000073 Version 00D [3], and 910-000175 Version 00A [4]; FIPS Kit P/Ns 920-000140 Version 00A [1], 920-000208 Version 00A [2], 920-000145 Version 00A [3], and 920-000209 Version 00A [4]