Certificate 2240 - PA-200, PA-500, PA-2000 Series, PA-3000 Series, PA-4000 Series and PA-5000 Series Firewalls
intCertNum 2240
strVendorName Palo Alto Networks
strURL http://www.paloaltonetworks.com
strAddress1 4301 Great America Parkway
strAddress2
strAddress3
strCity Santa Clara
strStateProv CA
strPostalCode 95054
strCountry 95054
strContact Jake Bajic
strEmail jbajic@paloaltonetworks.com
strPhone 408-753-3901
strFax 408-753-4001
strContact2 Richard Bishop
strEmail2 rbishop@paloaltonetworks.com
strFax2 408-753-4001
strPhone2 408-753-4061
intCertNum 2240
strModuleName PA-200, PA-500, PA-2000 Series, PA-3000 Series, PA-4000 Series and PA-5000 Series Firewalls
strPartNumber Hardware Versions: PA-200 P/N 910-000015-00E Rev. E [1], PA-500 P/N 910-000006-00O Rev. O [2], PA-500-2GB P/N 910-000094-00O Rev. O [2], PA-2020 P/N 910-000004-00Z Rev. Z [3], PA-2050 P/N 910-000003-00Z Rev. Z [3], PA-3020 P/N 910-000017-00J Rev. J [4], PA-3050 P/N 910-000016-00J Rev. J [4], PA-4020 P/N 910-000002-00AB Rev. AB [5], PA-4050 P/N 910-000001-00AB Rev. AB [5], PA-4060 P/N 910-000005-00S Rev. S [5], PA-5020 P/N 910-000010-00F Rev. F [6], PA-5050 P/N 910-000009-00F Rev. F [6] and PA-5060 P/N 910-000008-00F Rev. F [6];
FIPS Kit P/Ns: 920-000084-00A Rev. A [1], 920-000005-00A Rev. A [2], 920-000004-00A Rev. A [3], 920-000081-00A Rev. A [4], 920-000003-00A Rev. A [5] and 920-000037-00A Rev. A [6];
Firmware Versions: 5.0.11 and 5.0.16
memModuleNotes When operated in FIPS mode and with the tamper evident seals and opacity shields installed as indicated in the Security Policy
str140Version 140-2
_sp_ Security Policy   [pdf][html][txt]
_cert_ Certificate   [pdf]
strPURL
strModuleType Hardware
strValidationDate 09/08/2014;05/18/2015
intOverallLevel 2
memIndividualLevelNotes -Cryptographic Module Specification: Level 3;-Roles, Services, and Authentication: Level 3;-Design Assurance: Level 3;-Mitigation of Other Attacks: N/A
strFIPSAlgorithms AES (Cert. #2728);
CVL (Cert. #227);
HMAC (Cert. #1707);
RNG (Cert. #1263);
RSA (Cert. #1420);
SHS (Cert. #2298)
strOtherAlgorithms Diffie-Hellman (key agreement: key establishment methodology provides 112 bits of encryption strength);
RSA (key wrapping;
key establishment methodology provides 112 bits of encryption strength);
NDRNG;
MD5;
RC4;
Camellia;
RC2;
SEED;
DES
strConfiguration Multi-chip standalone
memModuleDescription The Palo Alto Networks PA-200, PA-500, PA-2000 Series, PA-3000 Series, PA-4000 Series, and PA-5000 Series next-generation firewalls are multi-chip standalone modules that provide network security by enabling enterprises to see and control applications, users, and content using three unique identification technologies: App-ID, User-ID, and Content-ID. This unique ability empowers customers to safely enable applications, make informed decisions on network access, and strengthen network security.
intModuleCount 1
memAdditionalNotes 05/18/15: Added FW 5.0.16 and updated the security policy.
strFirstValidtionDate 09/08/14 00:00:00
strLabName InfoGard
strValidationYear 2014