Palo Alto Networks SD-WAN Virtual Instant-On Network (vION)

Certificate #5330

Webpage information

Status active
Validation dates 15.06.2026
Sunset date 18-08-2029
Standard FIPS 140-3
Security level 1
Type Software
Embodiment MultiChipStand
Caveat When installed, initialized and configured as specified in section 11.1 of the Security Policy and operated in approved mode
Exceptions
  • Physical security: N/A
  • Non-invasive security: N/A
  • Mitigation of other attacks: N/A
Description The Palo Alto Networks SD-WAN Virtual Instant-On Network (vION) enables the integration of a diverse set of wide area network (WAN) connection types, improves application performance and visibility, enhances security and compliance, and reduces the overall cost and complexity of your WAN.
Vendor Palo Alto Networks, Inc.
References

This certificate's webpage directly references 0 certificates, transitively this expands into 0 certificates.

Security policy

Symmetric Algorithms
AES-128, AES-192, AES-256, AES, AES-, CAST, HMAC
Asymmetric Algorithms
RSA 2048, ECDH, ECDHE, ECDSA, Diffie-Hellman, DSA
Hash functions
SHA-1, SHA1
Schemes
MAC
Protocols
SSH, SSHv2, TLS, TLSv1.2, TLS v1.2, TLS 1.2, IKEv2
Randomness
DRBG, RBG
Elliptic Curves
P-256, P-384, P-521, P-224
Block cipher modes
CTR, GCM

Trusted Execution Environments
PSP, SSC

Security level
Level 1
Certification process
out of scope, fails. Any firmware loaded into the module that is not shown on the module certificate, is out of scope of this validation and requires a separate FIPS 140-3 validation. 4.6 Cryptographic Output Actions

File metadata

Author JustinBettencourt
Creation date D:20260415192834-04'00'
Modification date D:20260415193002-04'00'
Pages 41
Creator Acrobat PDFMaker 25 for Word
Producer Adobe PDF Library 25.1.40

Heuristics

No heuristics are available for this certificate.

References

No references are available for this certificate.

Updates Feed

  • The certificate data changed.
  • The certificate was first processed.

Raw data

{
  "_type": "sec_certs.sample.fips.FIPSCertificate",
  "cert_id": 5330,
  "dgst": "2b1e7392a9141ae5",
  "heuristics": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.Heuristics",
    "algorithms": {
      "_type": "Set",
      "elements": []
    },
    "cpe_matches": null,
    "direct_transitive_cves": null,
    "extracted_versions": {
      "_type": "Set",
      "elements": [
        "-"
      ]
    },
    "indirect_transitive_cves": null,
    "module_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "module_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "policy_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "policy_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "related_cves": null,
    "verified_cpe_matches": null
  },
  "pdf_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.PdfData",
    "keywords": {
      "asymmetric_crypto": {
        "ECC": {
          "ECDH": {
            "ECDH": 1,
            "ECDHE": 57
          },
          "ECDSA": {
            "ECDSA": 35
          }
        },
        "FF": {
          "DH": {
            "Diffie-Hellman": 2
          },
          "DSA": {
            "DSA": 3
          }
        },
        "RSA": {
          "RSA 2048": 2
        }
      },
      "certification_process": {
        "OutOfScope": {
          "fails. Any firmware loaded into the module that is not shown on the module certificate, is out of scope of this validation and requires a separate FIPS 140-3 validation. 4.6 Cryptographic Output Actions": 1,
          "out of scope": 1
        }
      },
      "cipher_mode": {
        "CTR": {
          "CTR": 37
        },
        "GCM": {
          "GCM": 9
        }
      },
      "cplc_data": {},
      "crypto_engine": {},
      "crypto_library": {},
      "crypto_protocol": {
        "IKE": {
          "IKEv2": 3
        },
        "SSH": {
          "SSH": 50,
          "SSHv2": 43
        },
        "TLS": {
          "TLS": {
            "TLS": 69,
            "TLS 1.2": 1,
            "TLS v1.2": 1,
            "TLSv1.2": 60
          }
        }
      },
      "crypto_scheme": {
        "MAC": {
          "MAC": 24
        }
      },
      "device_model": {},
      "ecc_curve": {
        "NIST": {
          "P-224": 8,
          "P-256": 38,
          "P-384": 12,
          "P-521": 8
        }
      },
      "eval_facility": {},
      "fips_cert_id": {
        "Cert": {
          "#1": 1
        }
      },
      "fips_certlike": {
        "Certlike": {
          "# A3566": 1,
          "- PKCS 1": 3,
          "AES-128": 2,
          "AES-128/192/256": 1,
          "AES-192": 2,
          "AES-256": 5,
          "DRBG 256": 2,
          "HMAC- SHA1": 1,
          "HMAC-SHA- 1": 2,
          "HMAC-SHA-1": 4,
          "PKCS 1": 3,
          "RSA 2048": 2,
          "SHA-1": 7,
          "SHA1": 1,
          "SHA2- 256": 4,
          "SHA2- 512": 1,
          "SHA2-256": 21,
          "SHA2-384": 11,
          "SHA2-512": 12
        }
      },
      "fips_security_level": {
        "Level": {
          "Level 1": 3
        }
      },
      "hash_function": {
        "SHA": {
          "SHA1": {
            "SHA-1": 7,
            "SHA1": 1
          }
        }
      },
      "ic_data_group": {},
      "javacard_api_const": {},
      "javacard_packages": {},
      "javacard_version": {},
      "os_name": {},
      "pq_crypto": {},
      "randomness": {
        "PRNG": {
          "DRBG": 85
        },
        "RNG": {
          "RBG": 2
        }
      },
      "side_channel_analysis": {},
      "standard_id": {
        "FIPS": {
          "FIPS 140-3": 9,
          "FIPS 180-4": 6,
          "FIPS 186-4": 9,
          "FIPS 198-1": 6,
          "FIPS186-4": 15
        },
        "NIST": {
          "SP 800-135": 5,
          "SP 800-38A": 5,
          "SP 800-38D": 2,
          "SP 800-56A": 2,
          "SP 800-90A": 2,
          "SP 800-90B": 1
        },
        "PKCS": {
          "PKCS 1": 3
        },
        "RFC": {
          "RFC 5288": 1
        }
      },
      "symmetric_crypto": {
        "AES_competition": {
          "AES": {
            "AES": 10,
            "AES-": 7,
            "AES-128": 2,
            "AES-192": 2,
            "AES-256": 5
          },
          "CAST": {
            "CAST": 75
          }
        },
        "constructions": {
          "MAC": {
            "HMAC": 37
          }
        }
      },
      "tee_name": {
        "AMD": {
          "PSP": 10
        },
        "IBM": {
          "SSC": 3
        }
      },
      "tls_cipher_suite": {},
      "vendor": {},
      "vulnerability": {}
    },
    "policy_metadata": {
      "/Author": "JustinBettencourt",
      "/Comments": "",
      "/Company": "",
      "/CreationDate": "D:20260415192834-04\u002700\u0027",
      "/Creator": "Acrobat PDFMaker 25 for Word",
      "/Keywords": "",
      "/ModDate": "D:20260415193002-04\u002700\u0027",
      "/Producer": "Adobe PDF Library 25.1.40",
      "/SourceModified": "D:20260415232818",
      "/Subject": "",
      "/Title": "",
      "pdf_file_size_bytes": 546168,
      "pdf_hyperlinks": {
        "_type": "Set",
        "elements": [
          "about:blank",
          "http://www.paloaltonetworks.com/",
          "https://docs.paloaltonetworks.com/"
        ]
      },
      "pdf_is_encrypted": false,
      "pdf_number_of_pages": 41
    }
  },
  "state": {
    "_type": "sec_certs.sample.fips.InternalState",
    "module": {
      "_type": "sec_certs.sample.document_state.DocumentState",
      "convert_ok": true,
      "download_ok": true,
      "extract_ok": true,
      "json_hash": null,
      "source_hash": null,
      "txt_hash": null
    },
    "policy": {
      "_type": "sec_certs.sample.document_state.DocumentState",
      "convert_ok": true,
      "download_ok": true,
      "extract_ok": true,
      "json_hash": null,
      "source_hash": "9d105e17bda91d68494aa8097820f65cf98b2cd2dc8de1a653630b757720896e",
      "txt_hash": "34150442735c3abdbf76704120e3a1f5c9d661ba5bc35abc2a56fa9d4f251bd3"
    }
  },
  "web_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.WebData",
    "caveat": "When installed, initialized and configured as specified in section 11.1 of the Security Policy and operated in approved mode",
    "certificate_pdf_url": "https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/certificates/June 2026_080726_0648.pdf",
    "date_sunset": "2029-08-18",
    "description": "The Palo Alto Networks SD-WAN Virtual Instant-On Network (vION) enables the integration of a diverse set of wide area network (WAN) connection types, improves application performance and visibility, enhances security and compliance, and reduces the overall cost and complexity of your WAN.",
    "embodiment": "MultiChipStand",
    "exceptions": [
      "Physical security: N/A",
      "Non-invasive security: N/A",
      "Mitigation of other attacks: N/A"
    ],
    "fw_versions": null,
    "historical_reason": null,
    "hw_versions": null,
    "level": 1,
    "mentioned_certs": {},
    "module_name": "Palo Alto Networks SD-WAN Virtual Instant-On Network (vION)",
    "module_type": "Software",
    "revoked_link": null,
    "revoked_reason": null,
    "standard": "FIPS 140-3",
    "status": "active",
    "sw_versions": null,
    "tested_conf": null,
    "validation_history": [
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2026-06-15",
        "lab": "Gossamer Security Solutions",
        "validation_type": "Initial"
      }
    ],
    "vendor": "Palo Alto Networks, Inc.",
    "vendor_url": "http://www.paloaltonetworks.com"
  }
}