Certificate 2616 - PA-3060 and PA-7080 Firewalls
intCertNum 2616
strVendorName Palo Alto Networks
strURL http://www.paloaltonetworks.com
strAddress1 4301 Great America Parkway
strAddress2
strAddress3
strCity Santa Clara
strStateProv CA
strPostalCode 95054
strCountry 95054
strContact Richard Bishop
strEmail rbishop@paloaltonetworks.com
strPhone 408-753-4000
strFax 408-783-4000
strContact2 Jake Bajic
strEmail2 jbajic@paloaltonetworks.com
strFax2
strPhone2 408-753-4000
intCertNum 2616
strModuleName PA-3060 and PA-7080 Firewalls
strPartNumber Hardware Versions: PA-3060 P/N 910-000104-00C Rev. C and PA-7080 P/N 910-000122-00A with 910-000028-00B or 910-000117-00A;
FIPS Kit P/Ns: 920-000138-00A Rev. A and 920-000119-00A Rev. A;
Firmware Versions: 7.0.1-h4 and 7.0.3
memModuleNotes When operated in FIPS mode and with the tamper evident seals and opacity shields installed as indicated in the Security Policy
str140Version 140-2
_sp_ Security Policy   [pdf][html][txt]
_cert_ Certificate   [pdf]
strPURL
strModuleType Hardware
strValidationDate 04/18/2016
intOverallLevel 2
memIndividualLevelNotes -Roles, Services, and Authentication: Level 3;-Design Assurance: Level 3;-Mitigation of Other Attacks: N/A;-Operational Environment: N/A
strFIPSAlgorithms AES (Cert. #3475);
ECDSA (Cert. #713);
RSA (Cert. #1782);
HMAC (Cert. #2220);
SHS (Cert. #2870);
DRBG (Cert. #870);
CVL (Certs. #564, #565, #566 and #567)
strOtherAlgorithms EC Diffie-Hellman (CVL Cert. #567, key agreement: key establishment methodology provides 128 bits or 192 bits of encryption strength);
Diffie-Hellman (key agreement: key establishment methodology provides 112 bits of encryption strength);
AES (Cert. #3475, key wrapping;
key establishment methodology provides 128 or 256 bits of encryption strength);
RSA (key wrapping;
key establishment methodology provides 112 bits or 128 bits of encryption strength);
NDRNG;
MD5;
RIPEMD;
Camellia;
SEED;
Triple-DES (non-compliant);
Blowfish;
CAST;
RC4;
UMAC;
HMAC-MD5;
HMAC-RIPEMD
strConfiguration Multi-Chip Stand Alone
memModuleDescription The Palo Alto Networks PA-3060 and PA-7080 firewalls provide network security by enabling enterprises to see and control applications, users, and content using three unique identification technologies: App-ID, User-ID, and Content-ID. These identification technologies, found in Palo Alto Networks' enterprise firewalls, enable enterprises to create business-relevant security policies - safely enabling organizations to adopt new applications, instead of the traditional ""all-or-nothing"" approach offered by traditional port-blocking firewalls used in many security infrastructures.
intModuleCount 2
memAdditionalNotes
strFirstValidtionDate 04/18/16 00:00:00
strLabName InfoGard
strValidationYear 2016