All modules
CMVP Validated Module · FIPS 140-3 Security Policy

Cisco Adaptive Security Appliance Cryptographic Module (FPR 4200 Series)

Certificate#5067StandardFIPS 140-3Level2TypeHardwareEmbodimentMulti-Chip Stand AloneStatusActiveVendorCisco Systems, Inc.
High review priority  ·  no TCB surface named  ·  last validated 10 months ago. How this is derived →

Certificate

StandardFIPS 140-3
Overall level2
Module typeHardware
EmbodimentMulti-Chip Stand Alone
StatusActive
Sunset date9/21/2030
CaveatWhen installed, initialized and configured as specified in Section Life-Cycle Assurance of the Security Policy. The tamper evident seals installed as indicated in the Security Policy
VendorCisco Systems, Inc.

Derived Review-Risk Graph (review prompts, not findings)

flowchart LR
  %% Deterministic review-risk graph for Cisco Adaptive Security Appliance Cryptographic Module (FPR 4200 Series)
  %% Review prompts and evidence gaps, NOT vulnerability findings.
  subgraph CMVP["CMVP-disclosed clues"]
    C2["[low] Firmware update / recovery<br/>/ rollback (referenced in<br/>text)<br/><i>Firmware Load</i>"]
    C3["[low] Self-test / status surface<br/>(referenced in text)<br/><i>Self-Test<br/>UnAuth</i>"]
    C5["[low] Protocol / secure-channel<br/>references (may be KDF<br/>names, not a live channel)<br/><i>TLS<br/>SSH<br/>IKEV</i>"]
    C6["[low] Operating system / runtime<br/>referenced (boundary<br/>membership not asserted)<br/><i>application</i>"]
  end
  subgraph Inference["Derived inference"]
    I2["Possible only, trusted<br/>code is reachable through<br/>update and recovery paths."]
    I3["Possible only, some<br/>services may process input<br/>before, or without,<br/>operator authentication."]
    I5["Possible only, a protocol<br/>is referenced, but whether<br/>it is a live channel or<br/>only a KDF/algorithm name<br/>is unconfirmed."]
    I6["Possible only, a<br/>runtime/OS is referenced,<br/>but its membership in the<br/>cryptographic boundary is<br/>not established."]
  end
  subgraph Risk["Reviewer question"]
    R2["Are update images<br/>authenticated before<br/>parsing, and are<br/>downgrade/rollback paths<br/>constrained?"]
    R3["Can unauthenticated<br/>services leak state,<br/>consume resources, or<br/>transition security state?"]
    R5["If a live TLS/SSH/IKE<br/>channel exists, could<br/>library CVEs apply, or is<br/>this only a<br/>KDF/documentation name?"]
    R6["If the OS/runtime is<br/>in-boundary, could its<br/>CVEs be hidden by<br/>firmware-only versioning?"]
  end
  subgraph Evidence["Evidence needed to close"]
    E2["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>update image format ·<br/>signature-before-parse<br/>proof · anti-rollback /<br/>downgrade policy"]
    E3["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>pre-auth reachability<br/>matrix · rate limits and<br/>output redaction ·<br/>abuse-case tests"]
    E5["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>library identity and<br/>version ·<br/>certificate-validation<br/>behaviour · protocol-CVE<br/>disposition"]
    E6["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>runtime identity and<br/>config · kernel/runtime<br/>hardening profile ·<br/>patch/backport manifest"]
  end
  C2 --> I2 --> R2 --> E2
  C3 --> I3 --> R3 --> E3
  C5 --> I5 --> R5 --> E5
  C6 --> I6 --> R6 --> E6
  classDef clue fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef infer fill:#fff7e6,stroke:#b98500,color:#6b4e00;
  classDef risk fill:#fbe9e9,stroke:#b02a2a,color:#7a1f1f;
  classDef evidence fill:#e6f4ea,stroke:#1e7d34,color:#14532d;
  class C2,C3,C5,C6 clue;
  class I2,I3,I5,I6 infer;
  class R2,R3,R5,R6 risk;
  class E2,E3,E5,E6 evidence;
Underlying clues
flowchart LR
  %% Deterministic clue tier for Cisco Adaptive Security Appliance Cryptographic Module (FPR 4200 Series)
  %% confidence: high = structured record field; medium = structured but soft; low (dashed) = bare keyword hit, context unverified
  subgraph CMVP["CMVP-disclosed clues (deterministic)"]
    C2["[low] Firmware update / recovery / rollback (referenced in text)<br/><i>Firmware Load</i><br/>src: text:keyword"]
    C3["[low] Self-test / status surface (referenced in text)<br/><i>Self-Test<br/>UnAuth</i><br/>src: text:keyword"]
    C5["[low] Protocol / secure-channel references (may be KDF names, not a live channel)<br/><i>TLS<br/>SSH<br/>IKEV</i><br/>src: text:keyword"]
    C6["[low] Operating system / runtime referenced (boundary membership not asserted)<br/><i>application</i><br/>src: text:keyword"]
  end
  classDef clueHigh fill:#eef3f9,stroke:#2f6fb0,stroke-width:2px,color:#1f3a5f;
  classDef clueMedium fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef clueLow fill:#f7f7f7,stroke:#999,stroke-dasharray:4 4,color:#444;
  class C2,C3,C5,C6 clueLow;

Security Policy, page by page

Page 1

Cisco Systems, Inc. Cisco Adaptive Security Appliance Cryptographic Module (FPR 4200 Series) Americas Headquarters: Cisco Systems, Inc., 170 West Tasman Drive, San Jose, CA 95134-1706 USA © 2021-2025 Cisco Systems, Inc. Cisco Systems logo is registered trademark of Cisco Systems, Inc.

Page 2
Table of Contents
#SectionPage
Page 4
List of Tables
ItemPage
Table 1: Security Levels5
Table 2: Tested Module Identification – Hardware6
Table 3: Modes List and Description7
Table 4: Approved Algorithms - CiscoSSL FOM Cryptographic Implementation9
Table 5: Approved Algorithms - Nitrox-V GC9
Table 6: Vendor-Affirmed Algorithms9
Table 7: Security Function Implementations15
Table 8: Entropy Certificates16
Table 9: Entropy Sources16
Table 10: Ports and Interfaces18
Table 11: Authentication Methods19
Table 12: Roles20
Table 13: Approved Services39
Table 14: Mechanisms and Actions Required41
Table 15: Storage Areas46
Table 16: SSP Input-Output Methods46
Table 17: SSP Zeroization Methods47
Table 18: SSP Table 154
Table 19: SSP Table 264
Table 20: Pre-Operational Self-Tests64
Table 21: Conditional Self-Tests69
Table 22: Pre-Operational Periodic Information70
Table 23: Conditional Periodic Information73
Table 24: Error States73
Figure 1. FPR 4215, FPR 4225, FPR 42456
Figure 2. FPR-4200 Front view41
Figure 3. FPR-4200 Back view42
Figure 4. FPR-4200 Left view42
Figure 5. FPR-4200 Right view42
Figure 6. FPR-4200 Bottom view42
Figure 7. FPR-4200 Top view43
Figure 8 Opacity Shield Brackets45
Page 5
SectionTitleSecurity Level
1General2
2Cryptographic module specification2
3Cryptographic module interfaces2
4Roles, services, and authentication3
5Software/Firmware security2
6Operational environmentN/A
7Physical security2
8Non-invasive securityN/A
9Sensitive security parameter management2
10Self-tests2
11Life-cycle assurance2
12Mitigation of other attacksN/A
Overall Level2

table indicates the actual security levels for each area of the cryptographic module.

1.2 Security Levels
2.1 Description

Purpose and Use: This module is a multi-chip standalone hardware cryptographic module deployed under the Next-Generation Firewall (NGFW) with Adaptive Security Appliance (ASA). The module operates in a limited operational environment. ASA delivers enterprise-class firewall for businesses, improving security at the Internet edge, high performance and throughput for demanding enterprise data centers. The ASA solution offers the combination of the industry's most deployed stateful firewall with a comprehensive range of next-generation network security services, intrusion prevention system (IPS), content security and secure unified communications, HTTPS/TLSv1.2, SSHv2, IPsec/IKEv2, SNMPv3 and Cryptographic Cipher Suite B using the ASA Cryptographic Module. Module Type: Hardware Module Embodiment: MultiChipStand Module Characteristics: Cryptographic Boundary: © 2021-2025 Cisco Systems, Inc.

Page 6
Model and/or Part NumberHardware VersionFirmware VersionProcessorsFeatures
FRP 4215FPR-42159.20AMD EPYC 7543 (Zen 3), Marvell Cavium Nitrox V CNN5560-900BG676-C45-G
FRP 4225FPR-42259.20AMD EPYC 7763 (Zen 3), Marvell Cavium Nitrox V CNN5560-900BG676-C45-G
FRP 4245FPR-42459.20AMD EPYC 7763 (Zen 3), Marvell Cavium Nitrox V CNN5560-900BG676-C45-G

The Tested Operational Environment Physical Perimeter (TOEPP) is defined as the entire chassis unit’s physical perimeter encompassing the "top," "front," "left," "right," “rear” and "bottom" surfaces of the case as shown in the figures below and in the Physical Security section. The cryptographic boundary encompasses the entire TOEPP. The FPR 4215, FPR 4225, and FPR 4245 all have the same exterior appearance. Where they differ is in Firewall throughput, IPS throughput, IPsec VPN throughput and number of VPN peers allowed.

2.2 Tested and Vendor Affirmed Module Version and Identification

Tested Module Identification

Page 7
Mode NameDescriptionTypeStatus Indicator
Approved Mode of OperationThe module is always in the approved mode of operation after initial operations are performed.ApprovedApproved mode indicator: "FIPS is currently enabled."
AlgorithmCAVP CertPropertiesReference
AES-CBCA4446Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-GCMA4446Direction - Decrypt, Encrypt IV Generation - Internal IV Generation Mode - 8.2.1 Key Length - 128, 192, 256SP 800-38D
Counter DRBGA4446Prediction Resistance - Yes Mode - AES-128, AES-192, AES-256 Derivation Function Enabled - YesSP 800-90A Rev. 1
ECDSA KeyGen (FIPS186-4)A4446Curve - P-256, P-384, P-521 Secret Generation Mode - Testing CandidatesFIPS 186-4
ECDSA SigGen (FIPS186-4)A4446Curve - P-256, P-384, P-521 Hash Algorithm - SHA2-224, SHA2-256, SHA2- 384, SHA2-512FIPS 186-4
ECDSA SigVer (FIPS186-4)A4446Curve - P-256, P-384, P-521 Hash Algorithm - SHA2-224, SHA2-256, SHA2- 384, SHA2-512FIPS 186-4
HMAC-SHA-1A4446Key Length - Key Length: 256-448 Increment 8FIPS 198-1
HMAC-SHA2- 224A4446Key Length - Key Length: 256-448 Increment 8FIPS 198-1
2.3 Excluded Components

N/A for this module. Modes List and Description: Table 3: Modes List and Description operation after initial operations are performed (See Section 11). The module does not claim implementation of a degraded mode of operation. Section 4 provides details on the service

2.5 Algorithms

Approved Algorithms: CiscoSSL FOM Cryptographic Implementation © 2021-2025 Cisco Systems, Inc.

Page 8
AlgorithmCAVP CertPropertiesReference
HMAC-SHA2- 256A4446Key Length - Key Length: 256-448 Increment 8FIPS 198-1
HMAC-SHA2- 384A4446Key Length - Key Length: 256-448 Increment 8FIPS 198-1
HMAC-SHA2- 512A4446Key Length - Key Length: 256-448 Increment 8FIPS 198-1
KAS-ECC-SSC Sp800-56Ar3A4446Domain Parameter Generation Methods - P- 256, P-384, P-521 Scheme - ephemeralUnified - KAS Role - initiator, responderSP 800-56A Rev. 3
KAS-FFC-SSC Sp800-56Ar3A4446Domain Parameter Generation Methods - ffdhe2048, ffdhe3072, ffdhe4096, modp-2048, modp-3072, modp-4096 Scheme - dhEphem - KAS Role - initiator, responderSP 800-56A Rev. 3
KDF IKEv2 (CVL)A4446Diffie-Hellman Shared Secret Length - Diffie- Hellman Shared Secret Length: 2048 Derived Keying Material Length - Derived Keying Material Length: 3072 Hash Algorithm - SHA-1SP 800-135 Rev. 1
KDF SNMP (CVL)A4446Password Length - Password Length: 256, 64SP 800-135 Rev. 1
KDF SSH (CVL)A4446Cipher - AES-128, AES-192, AES-256 Hash Algorithm - SHA-1, SHA2-256SP 800-135 Rev. 1
RSA KeyGen (FIPS186-4)A4446Key Generation Mode - B.3.4 Modulo - 2048, 3072 Hash Algorithm - SHA2-256 Private Key Format - StandardFIPS 186-4
RSA SigGen (FIPS186-4)A4446Signature Type - PKCS 1.5, PKCSPSS Modulo - 2048, 3072FIPS 186-4
RSA SigVer (FIPS186-4)A4446Signature Type - PKCS 1.5, PKCSPSS Modulo - 2048, 3072FIPS 186-4
Safe Primes Key GenerationA4446Safe Prime Groups - ffdhe2048, ffdhe3072, ffdhe4096, modp-2048, modp-3072, modp- 4096SP 800-56A Rev. 3
SHA-1A4446Message Length - Message Length: 0-65536 Increment 8FIPS 180-4
SHA2-224A4446Message Length - Message Length: 0-65536 Increment 8FIPS 180-4
SHA2-256A4446Message Length - Message Length: 0-65536 Increment 8FIPS 180-4
SHA2-384A4446Message Length - Message Length: 0-65536 Increment 8FIPS 180-4
SHA2-512A4446Message Length - Message Length: 0-65536 Increment 8FIPS 180-4
Page 9
AlgorithmCAVP CertPropertiesReference
TLS v1.2 KDF RFC7627 (CVL)A4446Hash Algorithm - SHA2-256, SHA2-384, SHA2- 512SP 800-135 Rev. 1
AlgorithmCAVP CertPropertiesReference
AES-CBCC1026Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-GCMC1026Direction - Decrypt, Encrypt IV Generation - External Key Length - 128, 192, 256SP 800-38D
Hash DRBGC1026Prediction Resistance - No Mode - SHA2-512SP 800-90A Rev. 1
HMAC-SHA-1C1026-FIPS 198-1
HMAC-SHA2- 256C1026-FIPS 198-1
HMAC-SHA2- 384C1026-FIPS 198-1
HMAC-SHA2- 512C1026-FIPS 198-1
SHA-1C1026Message Length - Message Length: 0- 51200 Increment 8FIPS 180-4
SHA2-256C1026Message Length - Message Length: 0- 51200 Increment 8FIPS 180-4
SHA2-384C1026Message Length - Message Length: 0- 102400 Increment 8FIPS 180-4
SHA2-512C1026Message Length - Message Length: 0- 102400 Increment 8FIPS 180-4
NamePropertiesImplementationReference
CKGKey Type:AsymmetricN/ASP 800-133r2 Section 4, Method 1

Table 4: Approved Algorithms - CiscoSSL FOM Cryptographic Implementation Nitrox-V GC Table 5: Approved Algorithms - Nitrox-V GC Vendor-Affirmed Algorithms: Table 6: Vendor-Affirmed Algorithms Non-Approved, Allowed Algorithms: N/A for this module. Non-Approved, Allowed Algorithms with No Security Claimed: N/A for this module. © 2021-2025 Cisco Systems, Inc.

Page 10
NameTypeDescriptionPropertiesAlgorithms
KAS-ECC- KeyGen (SSHv2)KAS-KeyGen CKGKAS ECC keygen used in SSHv2 serviceBit-strength Caveat:Provides between 128 and 256 bits encryption strengthCounter DRBG: (A4446) Hash DRBG: (C1026) CKG: ()
KAS-FFC- KeyGen (SSHv2)KAS-KeyGen CKGKAS FFC keygen used in SSHv2 serviceBit-strength Caveat:Provides between 112 and 152 bits encryption strengthCounter DRBG: (A4446) Hash DRBG: (C1026) Safe Primes Key Generation: (A4446) Safe Prime Groups: MODP- 2048, MODP- 3072, MODP- 4096 CKG: ()
KAS-ECC- KeyGen (TLSv1.2)KAS-KeyGen CKGKAS ECC keygen used in TLSv1.2 serviceBit-strength Caveat:Provides between 128 and 256 bits encryption strengthCounter DRBG: (A4446) Hash DRBG: (C1026) CKG: ()
KAS-FFC- KeyGen (TLSv1.2)KAS-KeyGen CKGKAS FFC keygen used in TLSv1.2 serviceBit-strength Caveat:Provides between 112 and 152 bits encryption strengthCounter DRBG: (A4446) Hash DRBG: (C1026) Safe Primes Key Generation: (A4446) Safe Prime Groups: ffdhe2048, ffdhe3072, ffdhe4096 CKG: ()

Non-Approved, Not Allowed Algorithms: N/A for this module.

2.6 Security Function Implementations
Page 11
NameTypeDescriptionPropertiesAlgorithms
KAS-ECC- KeyGen (IKEv2)KAS-KeyGen CKGKAS ECC keygen used in TLSv1.2 serviceBit-strength Caveat:Provides between 128 and 256 bits encryption strengthCounter DRBG: (A4446) Hash DRBG: (C1026) CKG: ()
KAS-FFC- KeyGen (IKEv2)KAS-KeyGen CKGKAS FFC keygen used in IKEv2 serviceBit-strength Caveat:Provides between 112 and 152 bits encryption strengthCounter DRBG: (A4446) Hash DRBG: (C1026) Safe Primes Key Generation: (A4446) Safe Prime Groups: MODP- 2048, MODP- 3072, MODP- 4096 CKG: ()
KAS-ECC (SSHv2)KAS-FullKAS-ECC for SSHv2 serviceBit-strength Caveat:Provides between 128 and 256 bits of encryption strengthKDF SSH: (A4446) KAS-ECC-SSC Sp800-56Ar3: (A4446)
KAS-FFC (SSHv2)KAS-FullKAS-FFC SSHv2 serviceBit-strength Caveat:Provides between 112 and 152 bits of encryption strengthKDF SSH: (A4446) KAS-FFC-SSC Sp800-56Ar3: (A4446) Domain Parameter Generation Methods: MODP-2048, MODP-3072, MODP-4096
KAS-ECC (TLSv1.2)KAS-FullKAS-ECC for TLSv1.2 serviceBit-strength Caveat:Provides between 128 and 256 bits of encryption strengthTLS v1.2 KDF RFC7627: (A4446) KAS-ECC-SSC Sp800-56Ar3: (A4446)
KAS-FFC (TLSv1.2)KAS-FullKAS-FFC for TLSv1.2 serviceBit-strength Caveat:Provides between 112 and 152 bits of encryption strengthTLS v1.2 KDF RFC7627: (A4446) KAS-FFC-SSC Sp800-56Ar3: (A4446)
Page 12
NameTypeDescriptionPropertiesAlgorithms
Domain Parameter Generation Methods: ffdhe2048, ffdhe3072, ffdhe4096
KAS-ECC (IKEv2)KAS-FullKAS-ECC for IKEv2 ServiceBit-strength Caveat:Provides between 128 and 256 bits of encryption strengthKAS-ECC-SSC Sp800-56Ar3: (A4446) KDF IKEv2: (A4446)
KAS-FFC (IKEv2)KAS-FullKAS-FFC for IKEv2 serviceBit-strength Caveat:Provides between 112 and 152 bits of encryption strengthKAS-FFC-SSC Sp800-56Ar3: (A4446) Domain Parameter Generation Methods: MODP-2048, MODP-3072, MODP-4096 KDF IKEv2: (A4446)
KTS (TLSv1.2 with AES and HMAC)KTS-WrapKTS via TLSv1.2 service by using AES and HMACBit-strength Caveat:Provides between 128 and 256 bits of encryption strengthAES-CBC: (A4446) HMAC-SHA-1: (A4446) HMAC-SHA2- 256: (A4446) HMAC-SHA2- 384: (A4446) SHA-1: (A4446) SHA2-256: (A4446) SHA2-384: (A4446)
KTS (TLSv1.2 with AES-GCM)KTS-WrapKTS via TLSv1.2 service by using AES-GCMBit-strength Caveat:Provides between 128 and 256 bits of encryption strengthAES-GCM: (A4446)
KTS (SSHv2 with AES and HMAC)KTS-WrapKTS via SSHv2 service by using AES and HMACBit-strength Caveat:Provides between 128 and 256 bits ofAES-CBC: (A4446) HMAC-SHA-1: (A4446) HMAC-SHA2-
Page 13
NameTypeDescriptionPropertiesAlgorithms
encryption strength256: (A4446) SHA-1: (A4446) SHA2-256: (A4446)
KTS (SSHv2 with AES-GCM)KTS-WrapKTS via SSHv2 service by using AES-GCMBit-strength Caveat:Provides between 128 and 256 bits of encryption strengthAES-GCM: (A4446)
RSA KeyGen (SSHv2, TLSv1.2, IKEv2)AsymKeyPair- KeyGen CKGRSA KeyGen for SSHv2, TLSv1.2, and IKEv2 servicesRSA KeyGen (FIPS186-4): (A4446) Counter DRBG: (A4446) Hash DRBG: (C1026) CKG: ()
ECDSA KeyGen (SSHv2, TLSv1.2 and IKEv2)AsymKeyPair- KeyGen CKGECDSA KeyGen for TLSv1.2 and IKEv2 servicesECDSA KeyGen (FIPS186-4): (A4446) Counter DRBG: (A4446) Hash DRBG: (C1026) CKG: ()
RSA SigGen (SSHv2, TLSv1.2, IKEv2)DigSig-SigGenRSA SigGen for SSHv2, TLSv1.2, and IKEv2 servicesRSA SigGen (FIPS186-4): (A4446)
ECDSA SigGen (SSHv2, TLSv1.2 and IKEv2)DigSig-SigGenECDSA SigGen for TLSv1.2, and IKEv2 servicesECDSA SigGen (FIPS186-4): (A4446)
RSA SigVer (SSHv2, TLSv1.2, and IKEv2)DigSig-SigVerRSA SigVer for SSHv2, TLSv1.2, and IKEv2 servicesRSA SigVer (FIPS186-4): (A4446)
ECDSA SigVer (SSHv2, TLSv1.2, and IKEv2)DigSig-SigVerECDSA SigVer for TLSv1.2 and IKEv2 servicesECDSA SigVer (FIPS186-4): (A4446)
Block Cipher (SSHv2)BC-Auth BC-UnAuthBlock Cipher for SSHv2 serviceAES-CBC: (A4446) AES-GCM: (A4446)
Block Cipher (TLSv1.2)BC-Auth BC-UnAuthBlock Cipher for TLSv1.2 serviceAES-GCM: (A4446)
Page 14
NameTypeDescriptionPropertiesAlgorithms
AES-CBC: (A4446)
Block Cipher (IPSec/IKE)BC-Auth BC-UnAuthBlock Cipher for IPSec/IKEv2 serviceAES-CBC: (A4446, C1026) AES-GCM: (A4446, C1026)
Block Cipher (SNMPv3)BC-UnAuthBlock Cipher for SNMPv3 serviceAES-CBC: (A4446) KDF SNMP: (A4446)
MAC (SSHv2)MACMAC for SSHv2 serviceHMAC-SHA-1: (A4446) HMAC-SHA2- 256: (A4446) SHA-1: (A4446) SHA2-256: (A4446)
MAC (TLSv1.2)MACMessage Authentication for TLSv1.2 servicesHMAC-SHA-1: (A4446) HMAC-SHA2- 256: (A4446) HMAC-SHA2- 384: (A4446) SHA-1: (A4446) SHA2-256: (A4446) SHA2-384: (A4446)
MAC (IPSec/IKEv2)MACMessage Authentication for IPSec/IKEv2 servicesHMAC-SHA2- 256: (A4446, C1026) HMAC-SHA2- 384: (A4446, C1026) HMAC-SHA2- 512: (A4446, C1026) SHA2-256: (A4446, C1026) SHA2-384: (A4446, C1026) SHA2-512: (A4446, C1026) HMAC-SHA-1: (C1026) SHA-1: (C1026)
MAC (SNMPv3)MACMessage AuthenticationHMAC-SHA-1: (A4446) SHA-1: (A4446)
Page 15
NameTypeDescriptionPropertiesAlgorithms
for SNMPv3 serviceKDF SNMP: (A4446) HMAC-SHA2- 256: (A4446) HMAC-SHA2- 384: (A4446) SHA2-256: (A4446) SHA2-384: (A4446) HMAC-SHA2- 224: (A4446) SHA2-224: (A4446)
Firmware Load TestMACMAC for firmware load testHMAC-SHA2- 512: (A4446)

Table 7: Security Function Implementations

2.7 Algorithm Specific Information

The module’s AES-GCM implementation conforms to Implementation Guidance C.H scenario #1 following RFC 5288 for TLS. The module is compatible with TLSv1.2 and provides support for the acceptable GCM cipher suites from SP 800-52 Rev1, Section 3.3.1. The operations of one of the two parties involved in the TLS key establishment scheme were performed entirely within the cryptographic boundary of the module being validated. The counter portion of the IV is set by the module within its cryptographic boundary. When the IV exhausts the maximum number of possible values for a given session key, the first party, client or server, to encounter this condition will trigger a handshake to establish a new encryption key. The keys for the client and server negotiated in the TLSv1.2 handshake process (client_write_key and server_write_key) are compared and the module aborts the session if the key values are identical. In case the module’s power is lost and then restored, a new key for use with the AES GCM encryption/decryption shall be established. The module uses RFC 7296 compliant IKEv2 to establish the shared secret SKEYSEED from which the AES GCM encryption keys are derived. When the IV exhausts the maximum number of possible values for a given session key, the first party, client or server, to encounter this condition will trigger a handshake to establish a new encryption key. Two keys established by IKEv2 for one security association (one key for encryption in each direction between the parties) are not identical and abort the session if they are. In case the module’s power is lost and then restored, a new key for use with the AES GCM encryption/decryption shall be established. The module was algorithm tested based on the FIPS 186-4 standard for Digital Signatures. According to IG C.K, this module is 186-5 compliant as all 186-4 CAVP tests performed are mathematically identical to the 186-5 CAVP tests. The Module does not support 186-4 DSA or RSA X9.31 for Signature Generation or Signature Verification. © 2021-2025 Cisco Systems, Inc.

Page 16
Cert NumberVendor Name
E3Cisco Systems, Inc.
NameTypeOperational EnvironmentSample SizeEntropy per SampleConditioning Component
Cisco Jitter Entropy SourceNon- PhysicalAMD EPYC 7543 (Zen 3), AMD EPYC 7763 (Zen 3)256 bitsFull EntropyA2810 (SHA3- 256)
2.8 RBG and Entropy

Table 8: Entropy Certificates Table 9: Entropy Sources The module implements two approved DRBGs based on SP800-90Arev1, including CRT_DRBG with Algo Cert. #A4446, and HASH_DRBG with Algo Cert. #C1026. Those two DRBGs are used internally by the module (e.g. to generate symmetric keys, seeds for asymmetric key pairs, and random numbers for security functions). Each DRBG is seeded by the entropy source described in the table above. The CTR_DRBG (AES-128/192/256) enables Derivation Function capability, and the HASH_DRBG (SHA2-512) doesn’t support Prediction Resistance. Each DRBG is instantiated with a 384-bits long entropy input (corresponding to 384 bits of entropy) and provides at least 256 bits security strength for the cryptographic keys generation while in the approved mode. The Cisco JENT entropy source implementation generates an output that is considered to have full entropy. More information can be found in the public use document for ESV cert #E3.

2.9 Key Generation

The module generates RSA, ECDSA, ECDH, and DH asymmetric key pairs compliant with FIPS 186-4, using a NIST SP 800-90Arev1 CTR DRBG or NIST SP 800-90Arev1 Hash DRBG for random number generation. In accordance with FIPS 140-3 IG D.H, the cryptographic module performs CKG for asymmetric keys as per section 5.1 of NIST SP 800-133rev2 (vendor affirmed) by obtaining a random bit string directly from an approved DRBG. The random bit string supports the required security strength requested by the calling application (without any V, as described in Additional Comments 2 of IG D.H.).

2.10 Key Establishment

The module provides the following key/SSP establishment services in the approved mode of operation: • KAS-FFC Shared Secret Computation: - The module provides SP800-56Arev3 compliant key establishment according to FIPS 140-3 IG D.F scenario 2 path (2) with KAS-FFC shared secret computation.

Page 17
Physical PortLogical Interface(s)Data That Passes
Ethernet Port, SFP28 (1/10/25G) port, and Console PortData InputData input into the module for all the services defined in Approved Services Table, including TLSv1.2, SSHv2, SNMPv3 and IPsec/IKEv2 service data.
Ethernet Port, SFP28 (1/10/25G) port, and Console PortData OutputData output from the module for all the services defined in Approved Services Table, including TLSv1.2, SSHv2, SNMPv3 and IPsec/IKEv2 service data.

The shared secret computation provides between 112 and 152 bits of encryption strength. - The module supports the use of the safe primes defined in RFC 4419 (SSH), RFC

7919 (TLS) and RFC 3526 (IKE).

o SSH (RFC 4419): MODP-2048 (ID =

  1. MODP-3072 (ID =
  2. MODP-4096 (ID = 16) o TLS (RFC 7919): ffdhe2048 (ID = 256) ffdhe3072 (ID = 257) ffdhe4096 (ID = 258) o IKE (RFC 3526): MODP-2048 (ID =
  3. MODP-3072 (ID =
  4. MODP-4096 (ID = 16) • KAS-ECC Shared Secret Computation: - The module provides SP800-56Arev3 compliant key establishment according to FIPS 140-3 IG D.F scenario 2 path (2) with KAS-ECC shared secret computation. The shared secret computation provides between 128 and 256 bits of encryption strength.
2.11 Industry Protocols

The module supports SSHv2, TLS v1.2, SNMPv3 and IPsec/IKEv2 industrial protocols. Please refer to the Security Function Implementations Table for more information. No parts of IPSec/IKEv2, SNMPv3, SSH and TLS protocols, other than the KDFs, have been tested by the CAVP and CMVP.

3 Cryptographic Module Interfaces
3.1 Ports and Interfaces
Page 18
Physical PortLogical Interface(s)Data That Passes
Ethernet Port, SFP28 (1/10/25G) port, Console Port and RESETControl InputControl Data input into the module for all the services defined in Approved Services Table, including TLSv1.2, SSHv2, SNMPv3 and IPsec/IKEv2 service data.
Ethernet Port, SFP28 (1/10/25G) port, Console Port and LEDsStatus OutputStatus Information output from the module.
N/AControl OutputN/A
PowerPowerProvide the Power Supply to the module.
Method NameDescriptionSecurity MechanismStrength Each AttemptStrength per Minute
PasswordThe minimum length is eight (8) characters (94 possible characters). The configuration supports at most ten failed attempts to authenticate in a one- minute period.Password BasedThe probability that a random attempt will succeed or a false acceptance will occur is 1/(94^8) which is less than 1/1,000,000.The probability of successfully authenticating to the module within one minute is 10/(94^8), which is less than 1/100,000.
RSA- Based CertificateThe modules support RSA public-key based authentication mechanism using a minimum of RSA 2048 bits, which provides 112 bits of security strength. The probability that a random attempt will succeed is 1/(2^112) which is less thanRSA SigVer (FIPS186-4) (A4446)The probability that a random attempt will succeed is 1/(2^112). Please refer to Description section in this table for more detailsthe probability of successfully authenticating to the module within a one minute period is 17,000 * 60 = 1,020,000/(2^112). Please refer to Description section in this table for more details

The module’s physical perimeter encompasses the case of the tested platform mentioned in The module’s data output interface will be disabled when performing pre-operational self-tests, loading new firmware, zeroizing keys, or when in an error state.

4.1 Authentication Methods
Page 19
Method NameDescription 1/1,000,000. For multiple attacks during a one-minute period, as the module at its highest can support at most 17,000 new sessions per second to authenticate in a one- minute period, the probability of successfully authenticating to the module within a one minute period is 17,000 * 60 = 1,020,000/(2^112), which is less than 1/100,000.Security MechanismStrength Each AttemptStrength per Minute
ECDSA- Based CertificateThe modules support ECDSA public-key based authentication mechanism using a minimum of curve P- 256, which provides 128 bits of security strength. The probability that a random attempt will succeed is 1/(2^128) which is less than 1/1,000,000. For multiple attacks during a one-minute period, as the module at its highest can support at most 17,000 new sessions per second to authenticate in a one- minute period, the probability of successfully authenticating to the module within a one minute period is 17,000 * 60 = 1,020,000/(2^128), which is less than 1/100,000.ECDSA SigVer (FIPS186-4) (A4446)The probability that a random attempt will succeed is 1/(2^128) which is less than 1/1,000,000. Please refer to Description section in this table for more detailsthe probability of successfully authenticating to the module within a one minute period is 17,000 * 60 = 1,020,000/(2^128). Please refer to Description section in this table for more details

Table 11: Authentication Methods © 2021-2025 Cisco Systems, Inc.

Page 20
NameTypeOperator TypeAuthentication Methods
Crypto OfficerIdentityCOPassword RSA-Based Certificate ECDSA-Based Certificate
UserIdentityUserPassword RSA-Based Certificate ECDSA-Based Certificate
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access
Show StatusProvide Module's current status (return codes and/or syslog messages)Global Indicator or syslog messageCommand used to show Module's StatusModule's Operationa l StatusNoneCrypto Officer User
Show VersionProvide Module's name and version informationConsole messageCommand to show versionModule's ID and versioning informationNoneCrypto Officer User
Perform Self-TestsPerform Self-Tests (Pre- operational self-test and Conditional Self-Tests)Global Indicator or syslog messageCommand to trigger Self-TestStatus of the self- tests resultsNoneCrypto Officer User Unauthentic ated
Perform ZeroizationPerform ZeroizationSyslog messageCommand to zeroize the moduleStatus of the SSPs zeroizationNoneCrypto Officer - DRBG Entropy

and the User role. The module also allows the concurrent operators.

4.2 Roles

Table 12: Roles Unauthenticated Users can run the self-test service by power-cycling the module by removing the power and re-applying.

4.3 Approved Services
Page 21

Name

Descriptio n

Indicator

Inputs

Outputs

Security Functions

SSP Access Input: Z - DRBG Seed: Z - DRBG Internal State (V, Key): Z - DRBG Internal State (V, C): Z - User Password: Z - Crypto Officer Password: Z - RADIUS Secret: Z - TACACS+ Secret: Z - Firmware Load Test Key: Z - SSH DH Private Key: Z - SSH DH Public Key: Z - SSH Peer DH Public Key: Z - SSH DH Shared Secret: Z - SSH ECDH Private Key: Z - SSH ECDH Public Key: Z - SSH Peer ECDH Public Key: Z - SSH ECDH Shared Secret: Z - SSH RSA

Page 22

Name

Descriptio n

Indicator

Inputs

Outputs

Security Functions

SSP Access Private Key: Z - SSH RSA Public Key: Z - SSH ECDSA Private Key: Z - SSH ECDSA Public Key: Z - SSH Session Encryption Key: Z - SSH Session Authenticatio n Key: Z - TLS DH Private Key: Z - TLS DH Public Key: Z - TLS Peer DH Public Key: Z - TLS DH Shared Secret: Z - TLS ECDH Private Key: Z - TLS ECDH Public Key: Z - TLS Peer ECDH Public Key: Z - TLS ECDH Shared Secret: Z - TLS ECDSA Private Key:

Page 23

Name

Descriptio n

Indicator

Inputs

Outputs

Security Functions

SSP Access Z - TLS ECDSA Public Key: Z - TLS RSA Private Key: Z - TLS RSA Public Key: Z - TLS Master Secret: Z - TLS Session Encryption Key: Z - TLS Session Authenticatio n Key: Z - IPSec/IKE DH Private Key: Z - IPSec/IKE DH Public Key: Z - IPSec/IKE Peer DH Public Key: Z - IPSec/IKE DH Shared Secret: Z - IPSec/IKE ECDH Private Key: Z - IPSec/IKE ECDH Public Key: Z - IPSec/IKE Peer ECDH Public Key: Z - IPSec/IKE ECDH Shared

Page 24
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access Secret: Z - IPSec/IKE ECDSA Private Key: Z - IPSec/IKE ECDSA Public Key: Z - IPSec/IKE RSA Private Key: Z - IPSec/IKE RSA Public Key: Z - IPSec/IKE Pre-shared Secret: Z - SKEYSEED: Z - IPSec/IKE Session Encryption Key: Z - IPSec/IKE Authenticatio n Key: Z - SNMPv3 Shared Secret: Z - SNMPv3 Encryption Key: Z - SNMPv3 Authenticatio n Key: Z
Configure NetworkSets configurati on of the systemsNoneCommand s to configure the networkStatus of the completion of network configurati on statusNoneCrypto Officer
Crypto Officer Authenticat ionCO Role Authenticat ionN/ACO Authenticat ion RequestStatus of the CO authenticat ionNoneCrypto Officer - Crypto Officer Password: W,Z
Page 25
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access
User Authenticat ionUser Role Authenticat ionN/AUser role authenticat ion requestStatus of the User role authenticat ionNoneUser - User Password: W,Z
Configure Bypass CapabilitySets the Bypass capabilityNoneCLI Bypass commandsStatus of the completion of Bypass capability configurati onNoneCrypto Officer
Configure SSHv2 FunctionConfigure SSHv2 FunctionGlobal Indicator and SSHv2 configurat ion success status messageCommand s to configure SSHv2Status of the completion of the SSHv2 configurati onKAS-ECC- KeyGen (SSHv2) KAS-FFC- KeyGen (SSHv2) KAS-ECC (SSHv2) KAS-FFC (SSHv2) KTS (SSHv2 with AES and HMAC) KTS (SSHv2 with AES- GCM) RSA KeyGen (SSHv2, TLSv1.2, IKEv2) ECDSA KeyGen (SSHv2, TLSv1.2 and IKEv2) RSA SigGen (SSHv2, TLSv1.2, IKEv2) ECDSA SigGen (SSHv2,Crypto Officer - SSH DH Private Key: G,W,E - SSH DH Public Key: G,R,W - SSH Peer DH Public Key: W,E - SSH DH Shared Secret: G,W,E - SSH ECDH Private Key: G,W,E - SSH ECDH Public Key: G,R,W - SSH Peer ECDH Public Key: W,E - SSH ECDH Shared Secret: G,W,E - SSH RSA Private Key: G,W,E - SSH RSA Public Key: G,R,W - SSH ECDSA
Page 26
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access
TLSv1.2 and IKEv2) RSA SigVer (SSHv2, TLSv1.2, and IKEv2) ECDSA SigVer (SSHv2, TLSv1.2, and IKEv2) Block Cipher (SSHv2) MAC (SSHv2)Private Key: G,W,E - SSH ECDSA Public Key: G,R,W - SSH Session Encryption Key: G,W,E - SSH Session Authenticatio n Key: G,W,E - DRBG Entropy Input: G,W,E - DRBG Seed: G,W,E - DRBG Internal State (V, Key): G,W,E - DRBG Internal State (V, C): G,W,E - RADIUS Secret: W - TACACS+ Secret: W
Configure HTTPS over TLSv1.2 FunctionGlobal Indicator and HTTPS over TLSv1.2 configurat ion success status messageCommand s to configure TLSv1.2Status of the completion of TLSv1.2 configurati onKAS-ECC- KeyGen (TLSv1.2) KAS-FFC- KeyGen (TLSv1.2) KAS-ECC (TLSv1.2) KAS-FFC (TLSv1.2) KTS (TLSv1.2 with AES and HMAC) KTSCrypto Officer - TLS DH Private Key: G,W,E - TLS DH Public Key: G,R,W - TLS Peer DH Public Key: W,E - TLS DH Shared Secret: G,W,E - TLS ECDH
Page 27
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access
(TLSv1.2 with AES- GCM) RSA KeyGen (SSHv2, TLSv1.2, IKEv2) ECDSA KeyGen (SSHv2, TLSv1.2 and IKEv2) RSA SigGen (SSHv2, TLSv1.2, IKEv2) ECDSA SigGen (SSHv2, TLSv1.2 and IKEv2) RSA SigVer (SSHv2, TLSv1.2, and IKEv2) ECDSA SigVer (SSHv2, TLSv1.2, and IKEv2) Block Cipher (TLSv1.2) MAC (TLSv1.2)Private Key: G,W,E - TLS ECDH Public Key: G,R,W - TLS Peer ECDH Public Key: W,E - TLS ECDH Shared Secret: G,W,E - TLS ECDSA Private Key: G,W,E - TLS ECDSA Public Key: G,R,W - TLS RSA Private Key: G,W,E - TLS RSA Public Key: G,R,W - TLS Master Secret: G,W,E - TLS Session Encryption Key: G,W,E - TLS Session Authenticatio n Key: G,W,E - DRBG Entropy Input: G,W,E - DRBG Seed: G,W,E - DRBG Internal State (V, Key): G,W,E
Page 28
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access - DRBG Internal State (V, C): G,W,E
Configure IPsec/IKEv 2 FunctionConfigure IPSec/IKEv 2 FunctionGlobal Indicator with IPsec/IKE v2 configurat ion success status messageCommand s to configure IPsec/IKEv 2Status of the completion of IPsec/IKEv 2 configurati onKAS-ECC- KeyGen (IKEv2) KAS-FFC- KeyGen (IKEv2) KAS-ECC (IKEv2) KAS-FFC (IKEv2) RSA KeyGen (SSHv2, TLSv1.2, IKEv2) ECDSA KeyGen (SSHv2, TLSv1.2 and IKEv2) RSA SigGen (SSHv2, TLSv1.2, IKEv2) ECDSA SigGen (SSHv2, TLSv1.2 and IKEv2) RSA SigVer (SSHv2, TLSv1.2, and IKEv2) ECDSA SigVer (SSHv2, TLSv1.2, and IKEv2) Block Cipher (IPSec/IKE ) MACCrypto Officer - IPSec/IKE DH Private Key: G,W,E - IPSec/IKE DH Public Key: G,R,W - IPSec/IKE Peer DH Public Key: W,E - IPSec/IKE DH Shared Secret: G,W,E - IPSec/IKE ECDH Private Key: G,W,E - IPSec/IKE ECDH Public Key: G,R,W - IPSec/IKE Peer ECDH Public Key: W,E - IPSec/IKE ECDH Shared Secret: G,W,E - IPSec/IKE ECDSA Private Key: G,W,E - IPSec/IKE ECDSA Public Key: G,R,W - IPSec/IKE RSA Private Key: G,W,E - IPSec/IKE
Page 29
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access
(IPSec/IKE v2)RSA Public Key: G,R,W - IPSec/IKE Pre-shared Secret: G,W,E - SKEYSEED: G,W,E - IPSec/IKE Session Encryption Key: G,W,E - IPSec/IKE Authenticatio n Key: G,W,E - DRBG Entropy Input: G,W,E - DRBG Seed: G,W,E - DRBG Internal State (V, Key): G,W,E - DRBG Internal State (V, C): G,W,E
Configure SNMPv3 FunctionConfigure SNMPv3 FunctionGlobal Indicator and SNMPv3 configurat ion success status messageCommand s to configure SNMPv3Status of the completion of SNMPv3 configurati onBlock Cipher (SNMPv3) MAC (SNMPv3)Crypto Officer - SNMPv3 Shared Secret: W,E - SNMPv3 Encryption Key: G,W,E - SNMPv3 Authenticatio n Key: G,W,E
Run SSHv2 FunctionExecute SSHv2 FunctionGlobal Indicator and successfu l SSHv2Initiate SSHv2 tunnel establishm entStatus of SSHv2 tunnel establishm entKAS-ECC- KeyGen (SSHv2) KAS-FFC- KeyGen (SSHv2)Crypto Officer - SSH DH Private Key: G,W,E - SSH DH
Page 30
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access
log messageKAS-ECC (SSHv2) KAS-FFC (SSHv2) KTS (SSHv2 with AES and HMAC) KTS (SSHv2 with AES- GCM) RSA KeyGen (SSHv2, TLSv1.2, IKEv2) ECDSA KeyGen (SSHv2, TLSv1.2 and IKEv2) RSA SigGen (SSHv2, TLSv1.2, IKEv2) ECDSA SigGen (SSHv2, TLSv1.2 and IKEv2) RSA SigVer (SSHv2, TLSv1.2, and IKEv2) ECDSA SigVer (SSHv2, TLSv1.2, and IKEv2) Block Cipher (SSHv2) MAC (SSHv2)Public Key: G,R,W - SSH Peer DH Public Key: W,E - SSH DH Shared Secret: G,W,E - SSH ECDH Private Key: G,W,E - SSH ECDH Public Key: G,R,W - SSH Peer ECDH Public Key: W,E - SSH ECDH Shared Secret: G,W,E - SSH RSA Private Key: G,W,E - SSH RSA Public Key: G,R,W - SSH ECDSA Private Key: G,W,E - SSH ECDSA Public Key: G,R,W - SSH Session Encryption Key: G,W,E - SSH Session Authenticatio n Key: G,W,E - DRBG Entropy Input: G,W,E
Page 31

Name

Descriptio n

Indicator

Inputs

Outputs

Security Functions

SSP Access - DRBG Seed: G,W,E - DRBG Internal State (V, Key): G,W,E - DRBG Internal State (V, C): G,W,E - RADIUS Secret: W,E - TACACS+ Secret: R,E User - SSH DH Private Key: G,W,E - SSH DH Public Key: G,R,W - SSH Peer DH Public Key: W,E - SSH DH Shared Secret: G,W,E - SSH ECDH Private Key: G,W,E - SSH ECDH Public Key: G,R,W - SSH Peer ECDH Public Key: W,E - SSH ECDH Shared Secret: G,W,E - SSH RSA Private Key: E - SSH RSA Public Key: R

Page 32
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access - SSH ECDSA Private Key: E - SSH ECDSA Public Key: R - SSH Session Encryption Key: G,W,E - SSH Session Authenticatio n Key: G,W,E - DRBG Entropy Input: G,W,E - DRBG Seed: G,W,E - DRBG Internal State (V, Key): G,W,E - DRBG Internal State (V, C): G,W,E - RADIUS Secret: E - TACACS+ Secret: R,E
Run HTTPS over TLSv1.2 FunctionExecute HTTPS over TLSv1.2 functionGlobal Indicator and successfu l HTTPS over TLSv1.2 log messageInitiate TLSv1.2 tunnel establishm ent requestStatus of TLSv1.2 tunnel establishm entKAS-ECC- KeyGen (TLSv1.2) KAS-FFC- KeyGen (TLSv1.2) KAS-ECC (TLSv1.2) KAS-FFC (TLSv1.2) KTS (TLSv1.2 with AES andCrypto Officer - TLS DH Private Key: G,W,E - TLS DH Public Key: G,R,W - TLS Peer DH Public Key: W,E - TLS DH Shared Secret:
Page 33
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access
HMAC) KTS (TLSv1.2 with AES- GCM) RSA KeyGen (SSHv2, TLSv1.2, IKEv2) ECDSA KeyGen (SSHv2, TLSv1.2 and IKEv2) RSA SigGen (SSHv2, TLSv1.2, IKEv2) ECDSA SigGen (SSHv2, TLSv1.2 and IKEv2) RSA SigVer (SSHv2, TLSv1.2, and IKEv2) ECDSA SigVer (SSHv2, TLSv1.2, and IKEv2) Block Cipher (TLSv1.2) MAC (TLSv1.2)G,W,E - TLS ECDH Private Key: G,W,E - TLS ECDH Public Key: G,R,W - TLS Peer ECDH Public Key: W,E - TLS ECDH Shared Secret: G,W,E - TLS ECDSA Private Key: G,W,E - TLS ECDSA Public Key: G,R,W - TLS RSA Private Key: G,W,E - TLS RSA Public Key: G,R,W - TLS Master Secret: G,W,E - TLS Session Encryption Key: G,W,E - TLS Session Authenticatio n Key: G,W,E - DRBG Entropy Input: G,W,E - DRBG Seed: G,W,E - DRBG Internal
Page 34

Name

Descriptio n

Indicator

Inputs

Outputs

Security Functions

SSP Access State (V, Key): G,W,E - DRBG Internal State (V, C): G,W,E User - TLS DH Private Key: G,W,E - TLS DH Public Key: G,R,W - TLS Peer DH Public Key: W,E - TLS DH Shared Secret: G,W,E - TLS ECDH Private Key: G,W,E - TLS ECDH Public Key: G,R,W - TLS Peer ECDH Public Key: W,E - TLS ECDH Shared Secret: G,W,E - TLS ECDSA Private Key: E - TLS ECDSA Public Key: R - TLS RSA Private Key: E - TLS RSA Public Key: R - TLS Master

Page 35
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access Secret: G,W,E - TLS Session Encryption Key: G,W,E - TLS Session Authenticatio n Key: G,W,E - DRBG Entropy Input: G,W,E - DRBG Seed: G,W,E - DRBG Internal State (V, Key): G,W,E - DRBG Internal State (V, C): G,W,E
Run IPSec/IKEv 2 FunctionExecute IPsec/IKEv 2 FunctionGlobal Indicator and succesful IPsec/IKE v2 log messageInitiate IPsec/IKEv 2 tunnel establishm ent requestStatus of IPSec/IKE v2 tunnel establishm entKAS-ECC- KeyGen (IKEv2) KAS-FFC- KeyGen (IKEv2) KAS-ECC (IKEv2) KAS-FFC (IKEv2) RSA KeyGen (SSHv2, TLSv1.2, IKEv2) ECDSA KeyGen (SSHv2, TLSv1.2 and IKEv2) RSA SigGen (SSHv2, TLSv1.2,Crypto Officer - IPSec/IKE DH Private Key: G,W,E - IPSec/IKE DH Public Key: G,R,W - IPSec/IKE Peer DH Public Key: W,E - IPSec/IKE DH Shared Secret: G,W,E - IPSec/IKE ECDH Private Key: G,W,E - IPSec/IKE ECDH Public Key: G,R,W
Page 36
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access
IKEv2) ECDSA SigGen (SSHv2, TLSv1.2 and IKEv2) RSA SigVer (SSHv2, TLSv1.2, and IKEv2) ECDSA SigVer (SSHv2, TLSv1.2, and IKEv2) Block Cipher (IPSec/IKE ) MAC (IPSec/IKE v2)- IPSec/IKE Peer ECDH Public Key: W,E - IPSec/IKE ECDH Shared Secret: G,W,E - IPSec/IKE ECDSA Private Key: G,W,E - IPSec/IKE ECDSA Public Key: G,R,W - IPSec/IKE RSA Private Key: G,W,E - IPSec/IKE RSA Public Key: G,R,W - IPSec/IKE Pre-shared Secret: G,W,E - SKEYSEED: G,W,E - IPSec/IKE Session Encryption Key: G,W,E - IPSec/IKE Authenticatio n Key: G,W,E - DRBG Entropy Input: G,W,E - DRBG Seed: G,W,E - DRBG Internal State (V, Key): G,W,E - DRBG
Page 37

Name

Descriptio n

Indicator

Inputs

Outputs

Security Functions

SSP Access Internal State (V, C): G,W,E User - IPSec/IKE DH Private Key: G,W,E - IPSec/IKE DH Public Key: G,R,W - IPSec/IKE Peer DH Public Key: W,E - IPSec/IKE DH Shared Secret: G,W,E - IPSec/IKE ECDH Private Key: G,W,E - IPSec/IKE ECDH Public Key: G,R,W - IPSec/IKE Peer ECDH Public Key: W,E - IPSec/IKE ECDH Shared Secret: G,W,E - IPSec/IKE ECDSA Private Key: E - IPSec/IKE ECDSA Public Key: R - IPSec/IKE RSA Private Key: E - IPSec/IKE RSA Public Key: R

Page 38
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access - IPSec/IKE Pre-shared Secret: G,W,E - SKEYSEED: G,W,E - IPSec/IKE Session Encryption Key: G,W,E - IPSec/IKE Authenticatio n Key: G,W,E - DRBG Entropy Input: G,W,E - DRBG Seed: G,W,E - DRBG Internal State (V, Key): G,W,E - DRBG Internal State (V, C): G,W,E
Run SNMPv3 FunctionExecute SNMPv3 FunctionGlobal Indicator and successfu l SNMPv3 log messageInitiate SNMPv3 tunnel establishm ent requestStatus of SNMPv3 tunnel establishm entBlock Cipher (SNMPv3) MAC (SNMPv3)Crypto Officer - SNMPv3 Shared Secret: W,E - SNMPv3 Encryption Key: G,W,E - SNMPv3 Authenticatio n Key: G,W,E User - SNMPv3 Shared Secret: W,E - SNMPv3 Encryption Key: G,W,E - SNMPv3
Page 39
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access Authenticatio n Key: G,W,E
Firmware Load TestExecute the Firmware Load TestGlobal indicator and successfu l Firmware Loading status messageCommand s to load new firmware imageOutcome of the Firmware Load TestFirmware Load TestCrypto Officer - Firmware Load Test Key: R
4.4 Non-Approved Services
4.5 External Software/Firmware Loaded

The module supports the firmware load test by using HMAC-SHA2-512 (HMAC Cert. #A4446) for the new validated firmware to be uploaded into the module. A Firmware Load Test Key was preloaded to the module’s binary at the factory and used for firmware load test. In order to load This ensures that unauthorized access and use of the module is not performed. The module will load the new update upon reboot. The update attempt will be rejected if the verification fails. Any firmware loaded into the module that is not shown on the module certificate, is out of scope of this validation and requires a separate FIPS 140-3 validation.

4.6 Bypass Actions and Status

The module implements alternating Bypass service. Traffic output from the module’s data output interface can be cryptographically protected via IPSec/IKE VPN, or passed as plaintext (Bypass state), depending on the VPN tunnel establishment on the dedicated data output interface. The operator shall assume Crypto Officer role so as to configure IPSec/IKE VPN capability. If no IPSec/IKE VPN was configured, after running two independent internal actions, Module would enter the Bypass state. Before the module executes the Bypass service (sending out plaintext traffic via the data output interface), the module would conduct two independent internal actions to prevent the inadvertent bypass of plaintext data due to a single error. The Crypto Officer can use commands “show access-list” and “show crypto ipsec sa” to verify the module’s Bypass status. In Bypass tests fail, the module would enter an error state, and drop the traffic. © 2021-2025 Cisco Systems, Inc.

Page 40
4.7 Cryptographic Output Actions and Status

The module implements Self-initiated cryptographic output capability without external operator request. The Crypto Officer shall configure self-initiated cryptographic output capability. Prior to executing the self-initiated cryptographic output capability, the module conducts two independent internal actions to activate the capability to prevent the inadvertent output due to a single error.

4.8 Additional Information

The module supports unauthenticated service. The unauthenticated User/Operators can trigger the self-test service by power-cycling the module, and is able to observe the module’s LEDs status.

5 Software/Firmware Security
5.1 Integrity Techniques

The module is provided in the form of binary executable code. To ensure firmware security, the module is protected by RSA 2048 bits with SHA2-512 (RSA Cert. #A4446) algorithm. A Firmware Integrity Test Key (non-SSP) was preloaded to the module’s binary at the factory and used for firmware integrity test only at the pre-operational self-test. The module uses the RSA

2048 bits modulus public key to verify the digital signature. If the firmware integrity test fails, the

module would enter to an Error state with all crypto functionality inhibited.

5.2 Initiate on Demand

Integrity test is performed as part of the Pre-Operational Self-Tests. It is automatically executed at power-on. The operator can power-cycle or reboot the tested platform to initiate the firmware integrity test on-demand.

6 Operational Environment
6.1 Operational Environment Type and Requirements

Type of Operational Environment: Limited

7 Physical Security
7.1 Mechanisms and Actions Required
Page 41
MechanismInspection FrequencyInspection Guidance
Tamper labels (10) with Part number: AIR-AP-FIPSKIT=Recommend 30 DaysVisible inspection of platform for residual evidence of tampering
Opacity shield (1) with Part number: FPR4200-FIPS-KITRecommend 30 DaysVisible inspection of platform for evidence of tampering, removal or access
Production grade componentsN/AN/A

Table 14: Mechanisms and Actions Required The module utilizes a production-grade enclosure and removable cover along with tamper evidence labels as the physical security mechanisms. Step 1: Turn off and unplug the module. Step 2: Clean the chassis of any grease, dirt, oil or any other material other than the surface coating from manufacture before applying the tamper evident labels. Alcohol-based cleaning pads are recommended for this purpose. Step 3: Apply a label to cover the module as shown in the figures below. The tamper evident labels are produced from a special thin gauge vinyl with self-adhesive backing. Any attempt to open the module will damage the tamper evident labels or the material of the security appliance cover. Because the tamper evident labels have non-repeated serial numbers, they may be inspected for damage and compared against the applied serial numbers to verify that the security appliance has not been tampered with. Tamper evident labels can also be inspected for signs of tampering, which include the following: curled corners, rips, and slices. The word “FIPS” may appear if the label was peeled back.

7.2 User Placed Tamper Seals

Placement: Figure 2. FPR-4200 Front view TEL 1 TEL 2 TEL 3 TEL 4 © 2021-2025 Cisco Systems, Inc.

Page 42

Figure

  1. FPR-4200 Back view TEL 5 Figure
  2. FPR-4200 Left view TEL 6 Figure
  3. FPR-4200 Right view TEL 4 TEL 3 TEL 7 TEL 2 TEL 8 Figure
  4. FPR-4200 Bottom view © 2021-2025 Cisco Systems, Inc.
Page 43

TEL 1 TEL 6 TEL 9 TEL 10 TEL 5 Figure 7. FPR-4200 Top view Surface Preparation: Clean the chassis of any grease, dirt, or oil before applying the tamper evident labels. Alcohol-based cleaning pads are recommended for this purpose. Operator Responsible for Securing Unused Seals: Any unused TELs must be securely stored, accounted for, and maintained by the CO in a protected location. Part Numbers: AIR-AP-FIPSKIT=

7.3 Filler Panels

FPR 4215, FPR 4225 and FPR 4245 Opacity Shield FPR4200-FIPS-KIT= Step 1: Attach the Slide Rail Locking Bracket, #2 in diagram to the Side of the Chassis using the countersink screws #3 in diagram. © 2021-2025 Cisco Systems, Inc.

Page 44

Step 2: Attach the Cable Management Bracket (#1) to the Slide Rail Locking Bracket (#2) using the countersink screws (#3) Step 3: Route the Cables through the Cable Management Brackets Step 4: Attach the FIPS Opacity Shield (#1) to the Cable Management Brackets (#3) using the countersink screws (#2) © 2021-2025 Cisco Systems, Inc.

Page 45
Storage Area NameDescriptionPersistence Type
DRAMVolatile MemoryDynamic
FlashNon-Volatile MemoryStatic

Figure 8 Opacity Shield Brackets

8 Non-Invasive Security
9 Sensitive Security Parameters Management
9.1 Storage Areas
Page 46
Name Peer Public Key Input Module Public Key OutputFrom External (Outside of the Module's Boundary ) ModuleTo Module External (Outside of the Module's Boundary )Format Type Plaintext PlaintextDistributio n Type Automated AutomatedEntry Type Electroni c Electroni cSFI or Algorith m
Password/Secre t Input via SSHv2 encrypted by GCMExternal (Outside of the Module's Boundary )ModuleEncrypte dAutomatedElectroni cKTS (SSHv2 with AES- GCM)
Password/Secre t Input via SSHv2 encrypted by AES and HMACExternal (Outside of the Module's Boundary )ModuleEncrypte dAutomatedElectroni cKTS (SSHv2 with AES and HMAC)
Password/Secre t Input via TLS encrypted by GCMExternal (Outside of the Module's Boundary )ModuleEncrypte dAutomatedElectroni cKTS (TLSv1.2 with AES- GCM)
Password/Secre t Input via TLS encrypted by AES and HMACExternal (Outside of the Module's Boundary )ModuleEncrypte dAutomatedElectroni cKTS (TLSv1.2 with AES and HMAC)
9.2 SSP Input-Output Methods

m ) ) ) ) ) ) Table 16: SSP Input-Output Methods © 2021-2025 Cisco Systems, Inc.

Page 47
Zeroization MethodDescriptionRationaleOperator Initiation
Zeroization CommandCO issues zeroization servicethe zeroization command will erase all SSPs stored in the DRAM or in the Flash of the module.'configure factory- default'
Session terminationZeroization upon session terminationSession termination will automatically zeroize all session based temporary SSPsTerminate session
RebootZeroization upon rebooting the moduleReboot to zeroize all temporary SSPs stored in Module's DRAMReboot
NameDescriptionSize - StrengthType - CategoryGenerat ed ByEstablish ed ByUsed By
DRBG Entropy InputUsed to seed the DRBG384 bits - at least 256 bitsEntropy Input - CSPCounter DRBG (A4446) Hash DRBG (C1026)
DRBG SeedUsed in DRBG Generation256 bits - 256 bitsDRBG Seed - CSPCounter DRBG (A4446) Hash DRBG (C1026)
DRBG Internal State (V, Key)Used in DRBG Generation256 bits - 256 bitsDRBG Internal State - CSPCounter DRBG (A4446)
DRBG Internal State (V, C)Used in DRBG Generation256 bits - 256 bitsDRBG Internal State - CSPHash DRBG (C1026)
User PasswordUser authenticati on8-30 Characte rs - 8-30 Characte rsAuthenticati on Data - CSP
9.3 SSP Zeroization Methods

Table 17: SSP Zeroization Methods default configuration is completed" status message upon completion. Please note that the Firmware Load Test Key is only used for Firmware Load Test Authentication and not subject to the zeroization requirement. © 2021-2025 Cisco Systems, Inc.

Page 48
NameDescriptionSize - StrengthType - CategoryGenerat ed ByEstablish ed ByUsed By
Crypto Officer PasswordCrypto Officer authenticati on8-30 Characte rs - 8-30 Characte rsAuthenticati on Data - CSP
RADIUS SecretRADIUS Server Authenticati on16 Characte rs - 16 Characte rsAuthenticati on Data - CSP
TACACS+ SecretTACACS+ Authenticati on16 Characte rs - 16 Characte rsAuthenticati on Data - CSP
Firmware Load Test KeyUsed for Firmware Load Test112 bits - 112 bitsPublic Key - CSPFirmware Load Test
SSH DH Private KeyUsed to derive the SSH DH Shared SecretMODP- 2048, MODP- 3072, MODP- 4096 - 112-152 bitsPrivate Key - CSPKAS- FFC- KeyGen (SSHv2)KAS-FFC- SSC Sp800- 56Ar3 (A4446)
SSH DH Public KeyUsed to derive SSH DH Shared SecretMODP- 2048, MODP- 3072, MODP- 4096 - 112-152 bitsPublic Key - PSPKAS-FFC- KeyGen (SSHv2)
SSH Peer DH Public KeyUsed to derive SSH DH Shared SecretMODP- 2048, MODP- 3072, MODP- 4096 - 112-152 bitsPublic Key - PSPKAS-FFC- SSC Sp800- 56Ar3 (A4446)
SSH DH Shared SecretUsed to derive SSH Session Encryption Keys, SSH SessionMODP- 2048, MODP- 3072, MODP- 4096 -Shared Secret - CSPKAS-FFC- SSC Sp800- 56Ar3 (A4446)KDF SSH (A4446)
Page 49
NameDescriptionSize - StrengthType - CategoryGenerat ed ByEstablish ed ByUsed By
Authenticati on Keys112-152 bits
SSH ECDH Private KeyUsed to derive the SSH ECDH Shared SecretCurves: 256, 384, 521 bits - 128 to 256 bitsPrivate Key - CSPKAS- ECC- KeyGen (SSHv2)KAS-ECC- SSC Sp800- 56Ar3 (A4446)
SSH ECDH Public KeyUsed to derive SSH ECDHE Shared SecretCurves: 256, 384, 521 bits - 128-256 bitsPublic Key - PSPKAS-ECC- KeyGen (SSHv2)
SSH Peer ECDH Public KeyUsed to derive SSH DH Shared SecretCurves: 256, 384, 521 bits - 128 to 256 bitsPublic Key - PSPKAS-ECC- SSC Sp800- 56Ar3 (A4446)
SSH ECDH Shared SecretUsed to derive SSH Session Encryption Keys, SSH Session Authenticati on KeysCurves: 256, 384, 521 bits - 128 to 256 bitsShared Secret - CSPKAS-ECC- SSC Sp800- 56Ar3 (A4446)KDF SSH (A4446)
SSH RSA Private KeyUsed for SSH session authenticati onModulus 2048 and 3072 bits - 112- 128 bitsPrivate Key - CSPRSA KeyGen (SSHv2, TLSv1.2, IKEv2)RSA SigGen (FIPS186-4) (A4446)
SSH RSA Public KeyUsed for SSH sessions aiuthenticati onModulus 2048 and 3072 bits - 112- 128 bitsPublic Key - PSPRSA KeyGen (SSHv2, TLSv1.2, IKEv2)
SSH ECDSA Private KeyUsed for SSH session authenticati onCurves: 256, 384, 521 bits - 128 to 256 bitsPrivate Key - CSPECDSA KeyGen (SSHv2, TLSv1.2 and IKEv2)ECDSA SigGen (FIPS186-4) (A4446)
SSH ECDSA Public KeyUsed for SSH sessions aiuthenticati onCurves: 256, 384, 521 bits - 128 to 256 bitsPublic Key - PSPECDSA KeyGen (FIPS186- 4) (A4446)
Page 50
NameDescriptionSize - StrengthType - CategoryGenerat ed ByEstablish ed ByUsed By
SSH Session Encryption KeyUsed for SSH Session confidentialit y protection128-256 bits - 128-256 bitsSession Key - CSPKAS-ECC (SSHv2) KAS-FFC (SSHv2)Block Cipher (SSHv2)
SSH Session Authenticati on KeyUsed for SSH Session integrity protection160-256 bits - 160-256 bitsSession Key - CSPKAS-ECC (IKEv2) KAS-FFC (IKEv2)MAC (SSHv2)
TLS DH Private KeyUsed to Derive TLS DH Shared Secretffdhe204 8, ffdhe307 2, ffdhe409 6 - 112- 152 bitsPrivate Key - CSPKAS- FFC- KeyGen (TLSv1.2 )KAS-FFC- SSC Sp800- 56Ar3 (A4446)
TLS DH Public KeyUsed to Derive TLS DH Shared Secretffdhe204 8, ffdhe307 2, ffdhe409 6 - 112- 152 bitsPublic Key - PSPKAS-FFC- KeyGen (TLSv1.2)
TLS Peer DH Public KeyUsed to derive TLS DH Shared Secretffdhe204 8, ffdhe307 2, ffdhe409 6 - 112- 152 bitsPublic Key - PSPKAS-FFC- SSC Sp800- 56Ar3 (A4446)
TLS DH Shared SecretUsed to Derive TLS Session Encryption Key and TLS Session Authenticati on Keyffdhe204 8, ffdhe307 2, ffdhe409 6 - 112- 152 bitsShared Secret - CSPKAS-FFC- SSC Sp800- 56Ar3 (A4446)TLS v1.2 KDF RFC7627 (A4446)
TLS ECDH Private KeyUsed to Derive TLS ECDH Shared SecretCurves P-256, P- 384, and P-521 - 128-256 bitsPrivate Key - CSPKAS- ECC- KeyGen (TLSv1.2 )KAS-ECC- SSC Sp800- 56Ar3 (A4446)
Page 51
NameDescriptionSize - StrengthType - CategoryGenerat ed ByEstablish ed ByUsed By
TLS ECDH Public KeyUsed to Derive TS ECDH Shared SecretCurves P-256, P- 384, and P-521 - 128-256 bitsPublic Key - PSPKAS-ECC- KeyGen (TLSv1.2)
TLS Peer ECDH Public KeyUsed to derive IKE ECDH Shared SecretCurves: P-256, P- 384, P- 521 - 128-256 bitsPublic Key - PSPKAS-ECC- SSC Sp800- 56Ar3 (A4446)
TLS ECDH Shared SecretUsed to Derive TLS Session Encryption Key and TLS Session Authenticati on KeyCurves p-256, P- 384, P- 521 - 128-256 bitsShared Secret - CSPKAS-ECC- SSC Sp800- 56Ar3 (A4446)TLS v1.2 KDF RFC7627 (A4446)
TLS ECDSA Private KeyUsed to support CO and Admin HTTPS interfacesCurves P-256, P- 384, P- 521 - 128-256 bitsPrivate Key - CSPECDSA KeyGen (SSHv2, TLSv1.2 and IKEv2)ECDSA SigGen (FIPS186-4) (A4446)
TLS ECDSA Public KeyUsed to support CO and User HTTPS InterfacesCurves P-256, P- 384, P- 521 - 128-256 bitsPublic Key - PSPECDSA KeyGen (SSHv2, TLSv1.2 and IKEv2)
TLS RSA Private KeyUsed to support CO and Admin HTTPS InterfacesModulus 2048 and 3072 bits - 112- 128 bitsPrivate Key - CSPRSA KeyGen (SSHv2, TLSv1.2, IKEv2)RSA SigGen (FIPS186-4) (A4446)
TLS RSA Public KeyUsed to support CO and User HTTPS interfacesModulus 2048 and 3072 bits - 112- 128 bitsPublic Key - PSPRSA KeyGen (SSHv2, TLSv1.2, IKEv2)
TLS Master SecretUsed to protect HTTPS Session.384 bits - 384 bitsMaster Secret - CSPTLS v1.2 KDF RFC7627 (A4446)
Page 52
NameDescription Pre-master secretSize - StrengthType - CategoryGenerat ed ByEstablish ed ByUsed By
TLS Session Encryption KeyUsed to protect HTTPS Session. TLS Master secret128-256 bits - 128-256 bitsSession Key - CSPKAS-ECC (TLSv1.2) KAS-FFC (TLSv1.2)Block Cipher (TLSv1.2)
TLS Session Authenticati on KeyUsed to protect HTTPS Session. TLS master secret160-384 bits - 160-384 bitsSession Key - CSPKAS-ECC (TLSv1.2) KAS-FFC (TLSv1.2)MAC (TLSv1.2)
IPSec/IKE DH Private KeyUsed to derive IPSec/IKE DH Shared SecretMODP- 2048, MODP- 3072, MODP- 4096 - 112-152 bitsPrivate Key - CSPKAS- FFC- KeyGen (IKEv2)KAS-FFC- SSC Sp800- 56Ar3 (A4446)
IPSec/IKE DH Public KeyUsed to derive IPSec/IKE DH Shared SecretMODP- 2048, MODP- 3072, MODP- 4096 - 112-152 bitsPublic Key - PSPKAS-FFC- KeyGen (IKEv2)
IPSec/IKE Peer DH Public KeyUsed to derive IPSec/IKE DH Shared SecretMODP- 2048, MODP- 3072, MODP- 4096 - 112-152 bitsPublic Key - PSPKAS-FFC- SSC Sp800- 56Ar3 (A4446)
IPSec/IKE DH Shared SecretUsed to derive IPSec/IKE Session Encryption Keys, IPSec/IKE Authenticati on KeysMODP- 2048, MODP- 3072, MODP- 4096 - 112-152 bitsShared Secret - CSPKAS-FFC- SSC Sp800- 56Ar3 (A4446)KDF IKEv2 (A4446)
Page 53
NameDescriptionSize - StrengthType - CategoryGenerat ed ByEstablish ed ByUsed By
IPSec/IKE ECDH Private KeyUsed to derive IPSec/IKE ECDH Shared SecretsCurves P-256, P- 384, P- 521 - 128-256 bitsPrivate Key - CSPKAS- ECC- KeyGen (IKEv2)KAS-ECC- SSC Sp800- 56Ar3 (A4446)
IPSec/IKE ECDH Public KeyUsed to derive IPSec/IKE ECDH Shared SecretsCurves P-256, P- 384, P- 521 - 128-256 bitsPublic Key - PSPKAS-ECC- KeyGen (IKEv2)
IPSec/IKE Peer ECDH Public KeyUsed to derive IPSec/IKE ECDH Shared SecretsCurves P-256, P- 384, P- 521 - 128-256 bitsPublic Key - PSPKAS-ECC- SSC Sp800- 56Ar3 (A4446)
IPSec/IKE ECDH Shared SecretUsed to derive IPSec/IKE ECDH Shared SecretsCurves P-256, P- 384, P- 521 - 128-256 bitsShared Secret - CSPKAS-ECC- SSC Sp800- 56Ar3 (A4446)KDF IKEv2 (A4446)
IPSec/IKE ECDSA Private KeyUsed for IPSec/IKE peer authenticati onCurves P-256, P- 384, P- 521 - 128-256 bitsPrivate Key - CSPECDSA KeyGen (SSHv2, TLSv1.2 and IKEv2)ECDSA SigGen (FIPS186-4) (A4446)
IPSec/IKE ECDSA Public KeyUsed for IPSec/IKE peer authenticati onCurves P-256, P- 384, P- 521 - 128-256 bitsPublic Key - PSPECDSA KeyGen (SSHv2, TLSv1.2 and IKEv2)
IPSec/IKE RSA Private KeyUsed for IPSec/IKE peer authenticati onModulus 2048 or 3072 - 112 or 128 bitsPrivate Key - CSPRSA KeyGen (SSHv2, TLSv1.2, IKEv2)RSA SigGen (FIPS186-4) (A4446)
IPSec/IKE RSA Public KeyUsed for IPSec/IKE peer authenticati onModulus 2048 or 3072 - 112 or 128 bitsPublic Key - PSPRSA KeyGen (SSHv2, TLSv1.2, IKEv2)
Page 54
NameDescriptionSize - StrengthType - CategoryGenerat ed ByEstablish ed ByUsed By
IPSec/IKE Pre-shared SecretUsed for IPSec/IKE peer authenticati on16-32 bytes character s - 16-32 bytes character sshared secret - CSP
SKEYSEEDKeying material used to derive the IPSec/IKE Session Encryption Key and IPSec/IKE Authenticati on Key160 bits - 160 bitsKeying Material - CSPKDF IKEv2 (A4446)
IPSec/IKE Session Encryption KeyUsed to secure IPSec/IKEv2 session confidentialit y128-256 bits - 128-256 bitsSession Key - CSPKAS-ECC (IKEv2) KAS-FFC (IKEv2)Block Cipher (IPSec/IKE)
IPSec/IKE Authenticati on KeyUsed to secure IPSec/IKEv2 session integrity160-512 bits - 160-512 bitsSession Key - CSPKAS-ECC (IKEv2) KAS-FFC (IKEv2)MAC (IPSec/IKEv 2)
SNMPv3 Shared SecretUsed for SNMPv3 user authenticati on8-32 character s - N/AAuthenticati on Secret - CSP
SNMPv3 Encryption KeyUsed to protect SNMPv3 traffic confidentialit y128 bits - 128 bitsEncryption Key - CSPKDF SNMP (A4446)Block Cipher (SNMPv3)
SNMPv3 Authenticati on KeyUsed to secure SNMPv3 traffic integrity160-384 bits - 160-384 bitsAuthenticati on Key - CSPKDF SNMP (A4446)MAC (SNMPv3)

s y y Table 18: SSP Table 1 © 2021-2025 Cisco Systems, Inc.

Page 55
NameInput - OutputStorageStorage DurationZeroizatio nRelated SSPs
DRBG Entropy InputDRAM:Plainte xtUntil RebootZeroizatio n Command Session terminatio n RebootDRBG Seed:Used With DRBG Internal State (V, Key):Used With DRBG Internal State (V, C):Used With
DRBG SeedDRAM:Plainte xtUntil RebootZeroizatio n Command Session terminatio n RebootDRBG Entropy Input:Used With DRBG Internal State (V, Key):Used With DRBG Internal State (V, C):Used With
DRBG Internal State (V, Key)DRAM:Plainte xtUntil RebootZeroizatio n Command Session terminatio n RebootDRBG Entropy Input:Used With DRBG Seed:Used With
DRBG Internal State (V, C)DRAM:Plainte xtUntil RebootZeroizatio n Command Session terminatio n RebootDRBG Entropy Input:Used With DRBG Seed:Used With
User PasswordPassword/Sec ret Input via TLS encrypted by GCM Password/Sec ret Input via TLS encrypted by AES and HMAC Password/Sec ret Input via SSHv2 encrypted by GCM Password/Sec ret Input via SSHv2Flash:Encrypt edZeroizatio n Command
Page 56
NameInput - Output encrypted by AES and HMACStorageStorage DurationZeroizatio nRelated SSPs
Crypto Officer PasswordPassword/Sec ret Input via TLS encrypted by GCM Password/Sec ret Input via TLS encrypted by AES and HMAC Password/Sec ret Input via SSHv2 encrypted by GCM Password/Sec ret Input via SSHv2 encrypted by AES and HMACFlash:Encrypt edZeroizatio n Command
RADIUS SecretPassword/Sec ret Input via TLS encrypted by GCM Password/Sec ret Input via TLS encrypted by AES and HMAC Password/Sec ret Input via SSHv2 encrypted by GCM Password/Sec ret Input via SSHv2 encrypted by AES and HMACFlash:Encrypt edZeroizatio n Command
TACACS+ SecretPassword/Sec ret Input via TLS encrypted by GCM Password/SecFlash:Encrypt edZeroizatio n Command
Page 57
NameInput - Output ret Input via TLS encrypted by AES and HMAC Password/Sec ret Input via SSHv2 encrypted by GCM Password/Sec ret Input via SSHv2 encrypted by AES and HMACStorageStorage DurationZeroizatio nRelated SSPs
Firmware Load Test KeyFlash:Plaintex tN/A
SSH DH Private KeyDRAM:Plainte xtWhile SSH tunnel is onZeroizatio n Command Session terminatio n RebootSSH DH Public Key:Paired With SSH Peer DH Public Key:Used With
SSH DH Public KeyModule Public Key OutputDRAM:Plainte xtWhile SSH tunnel is onZeroizatio n Command Session terminatio n RebootSSH DH Private Key:Paired With
SSH Peer DH Public KeyPeer Public Key InputDRAM:Plainte xtWhile SSH tunnel is onZeroizatio n Command Session terminatio n RebootSSH DH Private Key:Used With
SSH DH Shared SecretDRAM:Plainte xtWhile SSH tunnel is onZeroizatio n Command Session terminatio n RebootSSH DH Private Key:Derived From SSH DH Public Key:Derived From
Page 58
NameInput - OutputStorageStorage DurationZeroizatio nRelated SSPs
SSH ECDH Private KeyDRAM:Plainte xtWhile SSH tunnel is onZeroizatio n Command Session terminatio n RebootSSH ECDH Public Key:Paired With SSH Peer ECDH Public Key:Used With
SSH ECDH Public KeyModule Public Key OutputDRAM:Plainte xtWhile SSH tunnel is onZeroizatio n Command Session terminatio n RebootSSH ECDH Private Key:Paired With
SSH Peer ECDH Public KeyPeer Public Key InputDRAM:Plainte xtWhile SSH tunnel is onZeroizatio n Command Session terminatio n RebootSSH ECDH Private Key:Used With
SSH ECDH Shared SecretDRAM:Plainte xtWhile SSH tunnel is onZeroizatio n Command Session terminatio n RebootSSH ECDH Private Key:Derived From SSH ECDH Public Key:Derived From
SSH RSA Private KeyFlash:Plaintex tZeroizatio n CommandSSH RSA Public Key:Paired With
SSH RSA Public KeyModule Public Key OutputFlash:Plaintex tZeroizatio n CommandSSH RSA Private Key:Paired With
SSH ECDSA Private KeyFlash:Plaintex tZeroizatio n CommandSSH ECDSA Public Key:Paired With
SSH ECDSA Public KeyModule Public Key OutputFlash:Plaintex tZeroizatio n CommandSSH ECDSA Private Key:Paired With
SSH Session Encryption KeyDRAM:Plainte xtWhile SSH tunnel is onZeroizatio n Command Session terminatio n RebootSSH Session Authentication Key:Used With
Page 59
NameInput - OutputStorageStorage DurationZeroizatio nRelated SSPs
SSH Session Authenticati on KeyDRAM:Plainte xtWhile SSH tunnel is onZeroizatio n Command Session terminatio n RebootSSH Session Encryption Key:Used With
TLS DH Private KeyDRAM:Plainte xtWhile TLS tunnel is onZeroizatio n Command Session terminatio n RebootTLS DH Public Key:Paired With TLS Peer DH Public Key:Used With
TLS DH Public KeyModule Public Key OutputDRAM:Plainte xtWhile TLS tunnel is onZeroizatio n Command Session terminatio n RebootTLS DH Private Key:Paired With
TLS Peer DH Public KeyPeer Public Key InputDRAM:Plainte xtwhile TLS tunnel is onZeroizatio n Command Session terminatio n RebootTLS DH Private Key:Used With
TLS DH Shared SecretDRAM:Plainte xtWhile TLS tunnel is onZeroizatio n Command Session terminatio n RebootTLS ECDH Private Key:Derived From TLS Peer ECDH Public Key:Derived From
TLS ECDH Private KeyDRAM:Plainte xtWhile TLS tunnel is onZeroizatio n Command Session terminatio n RebootTLS ECDH Public Key:Paired With TLS Peer ECDH Public Key:Used With
TLS ECDH Public KeyModule Public Key OutputDRAM:Plainte xtWhile TLS tunnel is onZeroizatio n Command Session terminatioTLS ECDH Private Key:Paired With
Page 60
NameInput - OutputStorageStorage DurationZeroizatio nRelated SSPs
n Reboot
TLS Peer ECDH Public KeyPeer Public Key InputDRAM:Plainte xtwhile TLS tunnel is onZeroizatio n Command Session terminatio n RebootTLS ECDH Private Key:Used With
TLS ECDH Shared SecretDRAM:Plainte xtWhile TLS tunnel is onZeroizatio n Command Session terminatio n RebootTLS ECDH Private Key:Derived From TLS Peer ECDH Public Key:Derived From
TLS ECDSA Private KeyFlash:Plaintex tZeroizatio n CommandTLS ECDSA Public Key:Paired With
TLS ECDSA Public KeyModule Public Key OutputFlash:Plaintex tZeroizatio n CommandTLS ECDSA Private Key:Paired With
TLS RSA Private KeyFlash:Plaintex tZeroizatio n CommandTLS RSA Public Key:Paired With
TLS RSA Public KeyModule Public Key OutputFlash:Plaintex tZeroizatio n CommandTLS RSA Private Key:Paired With
TLS Master SecretDRAM:Plainte xtWhile TLS tunnel is onZeroizatio n Command Session terminatio n RebootTLS ECDH Shared Secret:Derived From
TLS Session Encryption KeyDRAM:Plainte xtWhile TLS tunnel is onZeroizatio n Command Session terminatio n RebootTLS Session Authentication Key:Used With
TLS Session Authenticati on KeyDRAM:Plainte xtWhile TLS tunnel is onZeroizatio n Command Session terminatioTLS Session Encryption Key:Used With
Page 61
NameInput - OutputStorageStorage DurationZeroizatio nRelated SSPs
n Reboot
IPSec/IKE DH Private KeyDRAM:Plainte xtWhile IPSec/IKE v2 tunnel is onZeroizatio n Command Session terminatio n RebootIPSec/IKE DH Public Key:Paired With IPSec/IKE Peer DH Public Key:Used With
IPSec/IKE DH Public KeyModule Public Key OutputDRAM:Plainte xtWhile IPSec/IKE v2 tunnel is onZeroizatio n Command Session terminatio n RebootIPSec/IKE DH Private Key:Paired With
IPSec/IKE Peer DH Public KeyPeer Public Key InputDRAM:Plainte xtwhile IPSec/IKE tunnel is onZeroizatio n Command Session terminatio n RebootIPsec/IKE DH Private Key:Used With
IPSec/IKE DH Shared SecretDRAM:Plainte xtWhile IPSec/IKE v2 tunnel is onZeroizatio n Command Session terminatio n RebootSKEYSEED:Used With
IPSec/IKE ECDH Private KeyDRAM:Plainte xtWhile IPSec/IKE v2 tunnel is onZeroizatio n Command Session terminatio n RebootIPSec/IKE ECDH Public Key:Paired With IPSec/IKE Peer ECDH Public Key:Used With
IPSec/IKE ECDH Public KeyModule Public Key OutputDRAM:Plainte xtWhile IPSec/IKE v2 tunnel is onZeroizatio n Command Session terminatio n RebootIPSec/IKE ECDH Private Key:Paired With
IPSec/IKE Peer ECDH Public KeyPeer Public Key InputDRAM:Plainte xtWhile IPSec/IKE v2 tunnel is onZeroizatio n Command SessionIPSec/IKE ECDH Private Key:Used With
Page 62
NameInput - OutputStorageStorage DurationZeroizatio nRelated SSPs
terminatio n Reboot
IPSec/IKE ECDH Shared SecretDRAM:Plainte xtWhile IPSec/IKE v2 tunnel is onZeroizatio n Command Session terminatio n RebootSKEYSEED:Used With
IPSec/IKE ECDSA Private KeyFlash:Plaintex tZeroizatio n CommandIPSec/IKE ECDSA Public Key:Paired With
IPSec/IKE ECDSA Public KeyModule Public Key OutputFlash:Plaintex tZeroizatio n CommandIPSec/IKE ECDSA Private Key:Paired With
IPSec/IKE RSA Private KeyFlash:Plaintex tZeroizatio n CommandIPSec/IKE RSA Public Key:Paired With
IPSec/IKE RSA Public KeyModule Public Key OutputFlash:Plaintex tZeroizatio n CommandIPSec/IKE RSA Private Key:Paired With
IPSec/IKE Pre-shared SecretPassword/Sec ret Input via SSHv2 encrypted by GCM Password/Sec ret Input via SSHv2 encrypted by AES and HMAC Password/Sec ret Input via TLS encrypted by GCM Password/Sec ret Input via TLS encrypted by AES and HMACFlash:Encrypt edWhile IPSec/IKE v2 tunnel is onZeroizatio n CommandSKEYSEED:Deriv ed to
SKEYSEEDDRAM:Plainte xtWhile IPSec/IKE v2 tunnel is onZeroizatio n Command Session terminatioIPSec/IKE DH Shared Secret:Derived From IPSec/IKE ECDH Shared
Page 63
NameInput - OutputStorageStorage DurationZeroizatio nRelated SSPs
n RebootSecret:Derived From IPSec/IKE Pre- shared Secret:Derived From
IPSec/IKE Session Encryption KeyDRAM:Plainte xtWhile IPSec/IKE v2 tunnel is onZeroizatio n Command Session terminatio n RebootIPSec/IKE DH Shared Secret:Derived From IPSec/IKE ECDH Shared Secret:Derived From
IPSec/IKE Authenticati on KeyDRAM:Plainte xtWhile IPSec/IKE v2 tunnel is onZeroizatio n Command Session terminatio n RebootIPSec/IKE DH Shared Secret:Derived From IPSec/IKE ECDH Shared Secret:Derived From
SNMPv3 Shared SecretPassword/Sec ret Input via TLS encrypted by GCM Password/Sec ret Input via TLS encrypted by AES and HMAC Password/Sec ret Input via SSHv2 encrypted by GCM Password/Sec ret Input via SSHv2 encrypted by AES and HMACFlash:Encrypt edWhile SNMPv3 tunnel is onZeroizatio n CommandSNMPv3 Encryption Key:Derive To SNMPv3 Authentication Key:Derive To
SNMPv3 Encryption KeyDRAM:Plainte xtWhile SNMPv3 tunnel is onZeroizatio n Command Session terminatioSNMPv3 Shared Secret:Derived From
Page 64
NameInput - OutputStorageStorage DurationZeroizatio nRelated SSPs
n Reboot
SNMPv3 Authenticati on KeyDRAM:Plainte xtWhile SNMPv3 tunnel is onZeroizatio n Command Session terminatio n RebootSNMPv3 Shared Secret:Derived From SNMPv3 Encryption Key:Used With
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetails
RSA SigVer (FIPS186-4) (A4446)RSA SigVer 2048 bits with SHA2-512KATSW/FW IntegrityModule is in normal stateRSA SigVer
Pre-Operational Bypass TestN/AN/ABypassModule is in normal stateN/A
9.5 Transitions

SHA-1 The module includes an implementation of SHA-1 for hashing and digital signature verification. This implementation will be non-Approved for all uses starting January 1, 2031. At this time, the user should move to SHA2, which is available in this module. 186-4/186-5 As of February 5, 2024, the CMVP does not accept module submissions that implement DSA or RSA X9.31 in the approved mode, other than for signature verification which is approved for legacy use. This module does not implement DSA or RSA X9.31 for signature generation and therefore is unaffected by the current transition from 186-4 to 186-5. As detailed in section 2.7, the CAVP testing performed on the 186-4 algorithms is mathematically similar to the testing performed on the 186-5 algorithms and therefore this module claims compliance with 186-5. This means that no timeline exists in which any of the implemented algorithms will transition from approved to non-approved.”

10 Self-Tests
10.1 Pre-Operational Self-Tests

Table 20: Pre-Operational Self-Tests The module performs the following self-tests, including the pre-operational self-tests and Conditional self-tests. Prior to the module providing any data output via the data output interface, the module performs and passes the pre-operational self-tests. Following the successful pre-operational self-tests, the module executes the Conditional Cryptographic Algorithm Self-tests (CASTs). If anyone of the self-tests fails, the module transitions into an © 2021-2025 Cisco Systems, Inc.

Page 65
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
AES-CBC Encrypt KAT (A4446)256 bitsKATCASTModule is in normal stateEncryptPower Up
AES-CBC Decrypt KAT (A4446)256 bitsKATCASTModule is in normal stateDecryptPower Up
AES-GCM Authenticated Encrypt KAT (A4446)256 bitsKATCASTModule is in normal stateAuthenticated EncryptPower Up
AES-GCM Authenticated Decrypt KAT (A4446)256 bitsKATCASTModule is in normal stateAuthenticated DecryptPower Up
Counter DRBG Instantiate KAT (A4446)AES-128KATCASTModule is in normal stateInstantiate KATPower Up
Counter DRBG Generate KAT (A4446)AES-128KATCASTModule is in normal stateGenerate KATPower Up
Counter DRBG Reseed KAT (A4446)AES-128KATCASTModule is in normal stateReseed KATPower Up
ECDSA SigGen (FIPS186-4) KAT (A4446)P-256 curve with SHA2-256KATCASTModule is in normal stateECDSA SigGen KATPower Up
ECDSA SigVer (FIPS186-4) KAT (A4446)P-256 curve with SHA2-256KATCASTModule is in normal stateECDSA SigVer KATPower Up
HMAC-SHA-1 KAT (A4446)SHA-1KATCASTModule is in normal stateHMAC-SHA-1Power Up

error state and outputs the error message via the module’s status output interface. While the module is in the error state, all data through the data output interface and all cryptographic operations are disabled. The error state can only be cleared by reloading the module. All self-tests must be completed successfully before the module transitions to the operational state.

10.2 Conditional Self-Tests
Page 66
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
HMAC-SHA2- 256 KAT (A4446)SHA2-256KATCASTModule is in normal stateHMAC-SHA2- 256Power Up
HMAC-SHA2- 384 KAT (A4446)SHA2-384KATCASTModule is in normal stateHMAC-SHA2- 384Power Up
HMAC-SHA2- 512 KAT (A4446)SHA2-512KATCASTModule is in normal stateHMAC-SHA2- 512Power Up
KAS-ECC- SSC Sp800- 56Ar3 KAT (A4446)P-256 CurveKATCASTModule is in normal statePrimitive Z KATPower Up
KAS-FFC- SSC Sp800- 56Ar3 KAT (A4446)MODP- 2048KATCASTModule is in normal statePrimitive Z KATPower Up
RSA SigGen (FIPS186-4) KAT (A4446)2048 bit modulus with SHA2- 256KATCASTModule is in normal stateRSA SigGen KATPower Up
RSA SigVer (FIPS186-4) KAT (A4446)2048 bit modulus with SHA2- 256KATCASTModule is in normal stateRSA SigVer KATPower Up
KDF IKEv2 KAT (A4446)N/AKATCASTModule is in normal stateN/APower Up
KDF SNMP KAT (A4446)N/AKATCASTModule is in normal stateN/APower Up
KDF SSH KAT (A4446)N/AKATCASTModule is in normal stateN/APower Up
TLS v1.2 KDF RFC7627 KAT (A4446)N/AKATCASTModule is in normal stateN/APower Up
SHA-1 KAT (A4446)N/AKATCASTModule is in normal stateN/APower Up
AES-CBC Encrypt KAT (C1026)128 bitsKATCASTModule is in normal stateEncrypt KATPower Up
AES-CBC Decrypt KAT (C1026)128 bitsKATCASTModule is in normal stateDecrypt KATPower Up
Page 67
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
AES-GCM Authenticated Encrypt KAT (C1026)128 bitsKATCASTModule is in normal stateEncrypt KATPower Up
AES-GCM Authenticated Decrypt KAT (C1026)128 bitsKATCASTModule is in normal stateDecrypt KATPower Up
Hash DRBG Instantiate KAT (C1026)SHA2-512KATCASTModule is in normal stateInstantiate KATPower Up
Hash DRBG Generate KAT (C1026)SHA2-512KATCASTModule is in normal stateGenerate KATPower Up
Hash DRBG Reseed KAT (C1026)SHA2-512KATCASTModule is in normal stateReseed KATPower Up
HMAC-SHA-1 KAT (C1026)SHA-1KATCASTModule is in normal stateHMAC-SHA-1Power Up
HMAC-SHA2- 256 KAT (C1026)SHA2-256KATCASTModule is in normal stateHMAC-SHA2- 256Power Up
HMAC-SHA2- 384 KAT (C1026)SHA2-384KATCASTModule is in normal stateHMAC-SHA2- 384Power Up
HMAC-SHA2- 512 KAT (C1026)SHA2-512KATCASTModule is in normal stateHMAC-SHA2- 512Power Up
SHA-1 KAT (C1026)N/AKATCASTModule is in normal stateN/APower Up
ECDSA KeyGen (FIPS186-4) PCT (A4446)Curve P- 256 with SHA2-256PCTPCTModule is in normal stateECDSAPerforms all required pair-wise consistency tests on the newly generated key pairs before the first operational use.
RSA KeyGen (FIPS186-4) PCT (A4446)2048 bit ModulusPCTPCTModule is in normal stateRSAPerforms all required pair-wise consistency
Page 68
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions tests on the newly generated key pairs before the first operational use.
KAS-ECC- SSC Sp800- 56Ar3 PCT (A4446)Curve P- 256 with SHA2-256PCTPCTModule is in normal stateN/APerforms all required pair-wise consistency tests on the newly generated key pairs before the first operational use.
KAS-FFC- SSC Sp800- 56Ar3 PCT (A4446)MODP- 2048PCTPCTModule is in normal stateN/APerforms all required pair-wise consistency tests on the newly generated key pairs before the first operational use.
Firmware Load TestHMAC- SHA2-512KATSW/FW LoadModule is in normal stateN/AWhen firmware has been uploaded to the module
Conditional BypassN/AN/ABypassModule is in normal stateN/APerforms conditional bypass test before first operational use of bypass service
Entropy 90B Start-up RepetitionRepetition Count TestRCTCASTModule is in normal stateDesigned to quickly detect catastrophicPower Up
Page 69
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
Count Test (RCT)failures that cause the noise source to become "stuck" on a single output value for a long period of time
Entropy 90B Start-up Adaptive Proportion Test (APT)Adaptive Proportion TestAPTCASTModule is in normal stateDesigned to detect a large loss of entropy that might occur as a result of some physical failure or environmental change affecting the noise sourcePower Up
Entropy 90B Continuous Repetition Count Test (RCT)Repetition Count TestRCTCASTModule is in normal stateDesigned to quickly detect catastrophic failures that cause the noise source to become "stuck" on a single output value for a long period of timeEntropy data is generated from the Entropy Source - Continuous
Entropy 90B Continuous Adaptive Proportion Test (APT)Adaptive Proportion TestAPTCASTModule is in normal stateDesigned to detect a large loss of entropy that might occur as a result of some physical failure or environmental change affecting the noise sourceEntropy data is generated from the Entropy Source - Continuous

Table 21: Conditional Self-Tests The module performs on-demand self-tests initiated by the operator, by powering off and powering the module back on. The full suite of self-tests is then executed. The same procedure may be employed by the operator to perform periodic self-tests. © 2021-2025 Cisco Systems, Inc.

Page 70
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
RSA SigVer (FIPS186-4) (A4446)KATSW/FW IntegrityRecommend 60 DaysReboot
Pre-Operational Bypass TestN/ABypassRecommend 60 DaysReboot
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
AES-CBC Encrypt KAT (A4446)KATCASTRecommend 60 DaysReboot
AES-CBC Decrypt KAT (A4446)KATCASTRecommend 60 DaysReboot
AES-GCM Authenticated Encrypt KAT (A4446)KATCASTRecommend 60 DaysReboot
AES-GCM Authenticated Decrypt KAT (A4446)KATCASTRecommend 60 DaysReboot
Counter DRBG Instantiate KAT (A4446)KATCASTRecommend 60 DaysReboot
Counter DRBG Generate KAT (A4446)KATCASTRecommend 60 DaysReboot
Counter DRBG Reseed KAT (A4446)KATCASTRecommend 60 DaysReboot
ECDSA SigGen (FIPS186-4) KAT (A4446)KATCASTRecommend 60 DaysReboot
ECDSA SigVer (FIPS186-4) KAT (A4446)KATCASTRecommend 60 DaysReboot
HMAC-SHA-1 KAT (A4446)KATCASTRecommend 60 DaysReboot
HMAC-SHA2- 256 KAT (A4446)KATCASTRecommend 60 DaysReboot
10.3 Periodic Self-Test Information

Table 22: Pre-Operational Periodic Information © 2021-2025 Cisco Systems, Inc.

Page 71
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
HMAC-SHA2- 384 KAT (A4446)KATCASTRecommend 60 DaysReboot
HMAC-SHA2- 512 KAT (A4446)KATCASTRecommend 60 DaysReboot
KAS-ECC-SSC Sp800-56Ar3 KAT (A4446)KATCASTRecommend 60 DaysReboot
KAS-FFC-SSC Sp800-56Ar3 KAT (A4446)KATCASTRecommend 60 DaysReboot
RSA SigGen (FIPS186-4) KAT (A4446)KATCASTRecommend 60 DaysReboot
RSA SigVer (FIPS186-4) KAT (A4446)KATCASTRecommend 60 DaysReboot
KDF IKEv2 KAT (A4446)KATCASTRecommend 60 DaysReboot
KDF SNMP KAT (A4446)KATCASTRecommend 60 DaysReboot
KDF SSH KAT (A4446)KATCASTRecommend 60 DaysReboot
TLS v1.2 KDF RFC7627 KAT (A4446)KATCASTRecommend 60 DaysReboot
SHA-1 KAT (A4446)KATCASTRecommend 60 DaysReboot
AES-CBC Encrypt KAT (C1026)KATCASTRecommend 60 DaysReboot
AES-CBC Decrypt KAT (C1026)KATCASTRecommend 60 DaysReboot
AES-GCM Authenticated Encrypt KAT (C1026)KATCASTRecommend 60 DaysReboot
AES-GCM Authenticated Decrypt KAT (C1026)KATCASTRecommend 60 DaysReboot
Hash DRBG Instantiate KAT (C1026)KATCASTRecommend 60 DaysReboot
Page 72
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
Hash DRBG Generate KAT (C1026)KATCASTRecommend 60 DaysReboot
Hash DRBG Reseed KAT (C1026)KATCASTRecommend 60 DaysReboot
HMAC-SHA-1 KAT (C1026)KATCASTRecommend 60 DaysReboot
HMAC-SHA2- 256 KAT (C1026)KATCASTRecommend 60 DaysReboot
HMAC-SHA2- 384 KAT (C1026)KATCASTRecommend 60 DaysReboot
HMAC-SHA2- 512 KAT (C1026)KATCASTRecommend 60 DaysReboot
SHA-1 KAT (C1026)KATCASTRecommend 60 DaysReboot
ECDSA KeyGen (FIPS186-4) PCT (A4446)PCTPCTRecommend 60 DaysReboot
RSA KeyGen (FIPS186-4) PCT (A4446)PCTPCTRecommend 60 DaysReboot
KAS-ECC-SSC Sp800-56Ar3 PCT (A4446)PCTPCTRecommend 60 DaysReboot
KAS-FFC-SSC Sp800-56Ar3 PCT (A4446)PCTPCTRecommend 60 DaysReboot
Firmware Load TestKATSW/FW LoadN/AN/A
Conditional BypassN/ABypassN/AN/A
Entropy 90B Start-up Repetition Count Test (RCT)RCTCASTN/AN/A
Entropy 90B Start-up Adaptive Proportion Test (APT)APTCASTN/AN/A
Entropy 90B Continuous Repetition Count Test (RCT)RCTCASTN/AN/A
Page 73
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
Entropy 90B Continuous Adaptive Proportion Test (APT)APTCASTN/A
NameDescriptionConditionsRecovery MethodIndicator
Error StateIf self-test tests fail, the module is put into an error stateSelf-test failureReboot the moduleSystem Halt

Table 23: Conditional Periodic Information

10.4 Error States

Table 24: Error States If any of the above-mentioned self-tests fail, the module reports the error and enters the Error state. In the Error State, no cryptographic services are provided, and data output is prohibited. The only method to recover from the error state is to reboot the module and perform the selftests, including the pre-operational firmware integrity test and the conditional CASTs. The module will only enter into the operational state after successfully passing the pre-operational firmware integrity test and the conditional CASTs.

11 Life-Cycle Assurance
11.1 Installation, Initialization, and Startup Procedures

The validated module firmware was installed onto the respective test platforms listed in Table 2 above. The Crypto Officer must configure and enforce the following initialization steps: Step 1: The Crypto Officer must install opacity shields as described in section 7 above. Step 2: The Crypto Officer must apply tamper evidence labels as described in section 7 above. Step 3: The Crypto Officer must securely store any unused tamper evidence labels. Note: Each module has a Type A USB 2.0 port, but it is considered to be disabled once the Crypto Officer has applied the TEL #7. Step 4: Crypto Officer performs the following configurations: ciscoasa# configure terminal Note, the Crypto Officer needs to connect the platform to cisco.com to obtain the license for ASA from Cisco. ciscoasa(config)# license smart register idtoken [token data] ciscoasa(config)#license smart © 2021-2025 Cisco Systems, Inc.

Page 74

ciscoasa(config-smart-lic)# show license all Smart Licensing Status ====================== Smart Licensing is ENABLED -ORStep

  1. Crypto officer shall perform zeroization operation if the module was previously used before the approved mode configuration. ciscoasa(config-smart-lic)# show license summary Smart Licensing is ENABLED Registration: Step 6: Enable “Approved Mode” to allow the module to startup the cryptographic module, such as run power-on self-tests and bypass test by using the following command: ciscoasa(config)# fips enable Note: Startup operational mode will not take effect until you save configuration and reboot the device Rebooting the device will force new self-test Step 7: Crypto Officer can verify the version installed and running ciscoasa(config)# show version Step 8: Crypto Officer will need to configure ASA ciscoasa> en ciscoasa# conf t ciscoasa(config)# Step 9: Assign users a Privilege Level of
  2. Step 10: Configure IP address for unit and all distant endpoints. Step 11: Define RADIUS and TACACS+ shared secret keys that are at least 8 characters long and secure traffic between the security module and the RADIUS/TACACS+ server via secure (IPSec, TLS) tunnel. Note: Perform this step only if RADIUS/TACAS+ is configured, otherwise skip over and proceed to next step. Step 12: Configure the security module so that any remote connections via Telnet are secured through IPSec connection by using the following commands crypto map interface access-list protocol esp encryption protocol esp integrity If IPSec secure connection is not configured, after running two internal independent actions defined in section 4.6 above, the module would enter the Bypass state. © 2021-2025 Cisco Systems, Inc.
Page 75

Step 13: Configure the security module so that any remote connections via Telnet are secured through IPSec. Step 14: Configure the security module so that only approved algorithms are used for IPsec tunnels. Step 15: Configure the security module so that error messages can only be viewed by Crypto Officer. Step 16: Disable the TFTP server. Step 17: Disable HTTP for performing system management in approved mode of operation. HTTPS with TLS should always be used for Web-based management. Step 18: Ensure that installed digital certificates are signed using approved algorithms. Step 19: Save the configuration. Step 20: Reboot the module.

11.2 Administrator Guidance

Specific Administrator guidance can be found on various Cisco guidance documents: https://www.cisco.com/c/en/us/td/docs/security/secure-firewall/threat-defense/use-case/multiinstance-sec-fw/multi-instance-sec-fw.html, https://www.cisco.com/c/en/us/td/docs/security/asa/special/cluster-sec-fw/secure-firewallcluster.html, https://www.cisco.com/c/en/us/td/docs/security/asa/asa923/asdm723/general/asdm-723general-config.html

11.3 Non-Administrator Guidance

Specific Non-Administrator guidance can be found in the Cisco Secure Firewall 4200 Datasheet: https://www.cisco.com/c/en/us/products/collateral/security/firewalls/secure-firewall-4200-ds.html

12 Mitigation of Other Attacks

N/A for this module. © 2021-2025 Cisco Systems, Inc.