Module Name
Juniper Networks SRX300, SRX320, SRX340, SRX345, SRX345-DUAL-AC, SRX550M, SRX5400, SRX5600 and SRX5800 Services Gateways
Validation Dates
10/27/2020
Caveat
When operated in FIPS mode, installed, initialized and configured as specified in Sections 1.2 and 5 of the Security Policy
Security Level Exceptions
- Roles, Services, and Authentication: Level 3
- Design Assurance: Level 3
- Mitigation of Other Attacks: N/A
Embodiment
Multi-Chip Stand Alone
Description
The Juniper Networks SRX Series Services Gateways are a series of secure routers that provide essential capabilities to connect, secure, and manage work force locations sized from handfuls to hundreds of users. By consolidating fast, highly available switching, routing, security, and applications capabilities in a single device, enterprises can economically deliver new services, safe connectivity, and a satisfying end user experience.
FIPS Algorithms
AES |
Certs. #C1084, #C1085, #C1107, #C1109 and #C1129 |
CVL |
Certs. #C1084, #C1085, #C1111 and #C1113 |
DRBG |
Certs. #C1079, #C1084, #C1085, #C1106 and #C1107 |
ECDSA |
Certs. #C1085, #C1107 and #C1151 |
HMAC |
Certs. #C1052, #C1079, #C1084, #C1085, #C1106, #C1107, #C1109 and #C1129 |
KAS-SSC |
vendor affirmed |
KTS |
AES Cert. #C1084 and HMAC Cert. #C1084; key establishment methodology provides between 128 and 256 bits of encryption strength |
KTS |
AES Cert. #C1085 and HMAC Cert. #C1085; key establishment methodology provides between 128 and 256 bits of encryption strength |
KTS |
AES Cert. #C1107 and HMAC Cert. #C1107; key establishment methodology provides between 128 and 256 bits of encryption strength |
KTS |
Triple-DES Cert. #C1084 and HMAC Cert. #C1084; key establishment methodology provides 112 bits of encryption strength |
KTS |
Triple-DES Cert. #C1085 and HMAC Cert. #C1085; key establishment methodology provides 112 bits of encryption strength |
KTS |
Triple-DES Cert. #C1107 and HMAC Cert. #C1107; key establishment methodology provides 112 bits of encryption strength |
RSA |
Certs. #C1107, #C1110 and #C1151 |
SHS |
Certs. #C1052, #C1079, #C1084, #C1085, #C1106, #C1107, #C1109 and #C1129 |
Triple-DES |
Certs. #C1084, #C1085, #C1107, #C1109 and #C1129 |
Allowed Algorithms
EC Diffie-Hellman (CVL Cert. #C1113, key agreement; key establishment methodology provides between 128 and 256 bits of encryption strength); NDRNG
Hardware Versions
[SRX300, SRX320, SRX340, SRX345, SRX345-DUAL-AC, SRX550, SRX5400, SRX5600 and SRX5800] with JNPR-FIPS-TAMPER-LBLS
Firmware Versions
JUNOS OS 19.2R1