FIPS Approved Ciphers and Algorithms
Focus
Focus
Prisma SD-WAN

FIPS Approved Ciphers and Algorithms

Table of Contents

FIPS Approved Ciphers and Algorithms

FIPS supports certain ciphers and algorithms.
Where Can I Use This?What Do I Need?
  • Prisma SD-WAN
  • Prisma SD-WAN license
FIPS and FIPS-CC modes supports the following ciphers and algorithms:
SNMP
  • SNMPv3
  • Security Level: ---auth, ---private
  • Auth Type: ---sha
  • Encryption Type: ---aes
Cipher suites for TLS connection between ION Device and Controller
  • TLS_ECDHE_RSA-AES256-GCM-SHA384
  • TLS_ECDHE_RSA-AES256-CBC-SHA384
  • TLS_ECDHE_RSA-AES128-GCM-SHA256
  • TLS_ECDHE_RSA-AES128-CBC-SHA256
IPSec - IKE and ESP Group
Key ExchangeDH GroupEncryptionHash
IKE Group
IKEv2
ECP-256(Group 19)
ECP-384(Group 20)
MODP-2048(Group 14)
AES-128-CBC
AES-192-CBC
AES-256-CBC
SHA-1
SHA-256
SHA-512
ESP Group
IKEv2
ECP-256(Group 19)
ECP-384(Group 20)
MODP-2048(Group 14)
AES-128-CBC
AES-192-CBC
AES-256-CBC
AES-128-GCM
AES-256-GCM
SHA-1
SHA-256
SHA-512
Open SSH
Kex_algorithms
Ecdh-sha2-nistp256
Ecdh-sha2-nistp384
Ecdh-sha2-nistp521
Diffie-hellman-group14-sha1
Diffie-hellman-group14-sha256
Diffie-hellman-group16-sha512
diffie-hellman-group18-sha512
Server_host_key_algorithms
rsa-sha2-512
rsa-sha2-256
Ssh-rsa
ecdsa-sha2-nistp256
Encryption_algorithms
aes128-ctr
aes192-ctr
aes256-ctr
Mac_algorithms
hmac-sha2-256-etm@openssh.com
hmac-sha2-512-etm@openssh.com hmac-sha1-etm@openssh.com
hmac-sha2-256
Hmac-sha2-512
hmac-sha1