Module Name
FireEye NX Series: NX1500V, NX2500V, NX2550V, NX4500V, NX6500V
Caveat
When operated in FIPS mode and installed, initialized and configured as specified in Section 3 of the Security Policy.
Security Level Exceptions
- Roles, Services, and Authentication: Level 3
- Physical Security: N/A
- Mitigation of Other Attacks: N/A
Embodiment
Multi-Chip Stand Alone
Description
The FireEye Network Threat Prevention Platform identifies and blocks zero-day Web exploits, droppers (binaries), and multi-protocol callbacks to help organizations scale their advanced threat defenses across a range of deployments, from the multi-gigabit headquarters down to remote, branch, and mobile offices. FireEye Network with Intrusion Prevention System (IPS) technology further optimizes spend, substantially reduces false positives, and enables compliance while driving security across known and unknown threats.
Tested Configuration(s)
- FEYE 9.0 on VMware ESXi 6.7 running on Dell PowerEdge R630 with Intel Xeon E5 (single-user mode)
FIPS Algorithms
AES |
Cert. #C1749 |
CKG |
vendor affirmed |
CVL |
Cert. #C1749 |
DRBG |
Certs. #C1749 and #C2043 |
DSA |
Cert. #C1749 |
ECDSA |
Cert. #C1749 |
HMAC |
Certs. #C1749 and #C2043 |
KAS-SSC |
vendor affirmed |
KTS |
AES Cert. #C1749 and HMAC Cert. #C1749; key establishment methodology provides 128 or 256 bits of encryption strength |
KTS |
Triple-DES Cert. #C1749 and HMAC Cert. #C1749; key establishment methodology provides 112 bits of encryption strength |
RSA |
Cert. #C1749 |
SHS |
Certs. #C1749 and #C2043 |
Triple-DES |
Cert. #C1749 |
Allowed Algorithms
NDRNG; RSA (key wrapping; key establishment methodology provides 112 or 128 bits of encryption strength)