NIAP: Compliant Product
NIAP/CCEVS
  NIAP  »»  Product Compliant List  »»  Compliant Product  
Compliant Product - FortiGate/FortiOS 6.4

Certificate Date:  2023.03.09

Validation Report Number:  CCEVS-VR-VID11296-2023

Product Type:    Network Device

Conformance Claim:  Protection Profile Compliant

PP Identifier:    collaborative Protection Profile for Network Devices Version 2.2e
  collaborative Protection Profile Module for Stateful Traffic Filter Firewalls v1.4 + Errata 20200625
  PP-Module for Virtual Private Network (VPN) Gateways Version 1.1

CC Testing Lab:  Lightship Security USA, Inc.


CC Certificate [PDF] Security Target [PDF] Validation Report [PDF]

Assurance Activity [PDF]

Administrative Guide: FortiOS Version 6.4.9 [PDF]

Administrative Guide: FortiOS - VMware ESXi Version 6.4 [PDF]

Administrative Guide: FIPS 140-2 and NDcPP Common Criteria Technote [PDF]

Administrative Guide: FortiOS - Parallel Path Processing Version 6.4.0 [PDF]

Administrative Guide: FortiOS - CLI Reference Version 6.4.9 [PDF]

Administrative Guide: FortiOS - Hardware Acceleration Guide Version 6.4.9 [PDF]

Administrative Guide: NDcPP Common Criteria Logging Addendum [PDF]


Product Description

The TOE is a family of FortiGate next-generation firewall (NGFW) appliances running FortiOS software. The TOE provides high performance, multilayered validated security and granular visibility for end-to-end protection across the entire enterprise.


Evaluated Configuration

The TOE is FortiGate/FortiOS 6.4 Version 6.4 (FIPS-CC-64-6) running on a physical or virtual device.

 

The physical boundary of the TOE includes the FortiGate hardware models and the virtual appliances shown below. The virtual appliances are evaluated as virtual Network Devices (vND), which is case 1 of Section 1.2 of NDcPP v2.2e.

                                         TOE Hardware Models

Model

CPU

Architecture

RAM

Boot

Storage

ASIC

Entropy

CAVP

FG-61E

Fortinet SoC3

ARMv7-A

2 GB

8GB

128GB

CP9Lite

SoC3

A2225 A2269 A2241

FG-61F

Fortinet SoC4

ARMv8

2 GB

8GB

128GB

CP9XLite

SoC4

A2225 A2269 A2242

FWF-61E

Fortinet SoC3

ARMv7-A

2 GB

8GB

128GB

CP9Lite

SoC3

A2225 A2269 A2241

FWF-61F

Fortinet SoC4

ARMv8

2 GB

8GB

128GB

CP9XLite

SoC4

A2225 A2269 A2242

FG-81E

Fortinet SoC3

ARMv7-A

2 GB

8GB

128GB

CP9Lite

SoC3

A2225 A2269 A2241

FG-81E-PoE

Fortinet SoC3

ARMv7-A

2 GB

8GB

128GB

CP9Lite

SoC3

A2225 A2269 A2241

FG-81F

Fortinet SoC4

ARMv8

4 GB

8GB

128GB

CP9XLite

SoC4

A2225 A2269 A2242

FG-81F-2R

Fortinet SoC4

ARMv8

4 GB

8GB

128GB

CP9XLite

SoC4

A2225 A2269 A2242

FG-81F-2R-3G4G-PoE

Fortinet SoC4

ARMv8

4 GB

8GB

128GB

CP9XLite

SoC4

A2225 A2269 A2242

FG-81F-2R-PoE

Fortinet SoC4

ARMv8

4 GB

8GB

128GB

CP9XLite

SoC4

A2225 A2269 A2242

FG-81F-PoE

Fortinet SoC4

ARMv8

4 GB

8GB

128GB

CP9XLite

SoC4

A2225 A2269 A2242

FG-90E

Fortinet SoC3

ARMv7-A

2 GB

8GB

128GB

CP9Lite

SoC3

A2225 A2269 A2241

FG-91E

Fortinet SoC3

ARMv7-A

2 GB

8GB

128GB

CP9Lite

SoC3

A2225 A2269 A2241

FG-101E

Fortinet SoC3

ARMv7-A

4 GB

8GB

480GB

CP9Lite

SoC3

A2225 A2269 A2241

FG-101F

Fortinet SoC4

ARMv8

4 GB

8GB

480GB

CP9XLite

SoC4

A2225 A2269 A2242

FG-201E

Intel Celeron G1820

Haswell

4GB

16GB

480GB

CP9

CP9

A2225 A2269 A2240

FG-201F

Intel Xeon D-1627

Hewitt Lake

8GB

30GB

480GB

CP9

CP9

A2225 A2269 A2240

FG-301E

Intel i5-6500

SkyLake

8GB

16GB

480GB

CP9

CP9

A2225 A2269 A2240

FG-401E

Intel i5-8500

Coffee Lake

8GB

16GB

480GB

CP9

CP9

A2225 A2269 A2240

FG-501E

Intel i7-6700

SkyLake

16GB

16GB

480GB

CP9

CP9

A2225 A2269 A2240

FG-601E

Intel i7-8700

Coffee Lake

16 GB

16GB

480GB

CP9

CP9

A2225 A2269 A2240

FG-1101E

Intel Xeon E-2186G

Coffee Lake

16 GB

16GB

960GB

CP9

CP9

A2225 A2269 A2240

FG-1801F

Intel Xeon W-3223

Cascade Lake

24GB

30GB

2TB

CP9

CP9

A2225 A2269 A2240

FG-1801F-DC

Intel Xeon W-3223

Cascade Lake

24GB

30GB

2TB

CP9

CP9

A2225 A2269 A2240

FG-2000E

Intel Xeon E5-1660v4

Broadwell

32 GB

16GB

480GB

CP9

CP9

A2225 A2269 A2240

FG-2201E

Intel Xeon Gold 6126

SkyLake

24 GB

16GB

2TB

CP9

CP9

A2225 A2269 A2240

FG-2500E

Intel Xeon E5-1650v3

Haswell

32 GB

16GB

480GB

CP9

CP9

A2225 A2269 A2240

FG-2601F

Intel Xeon Gold 6208U

Cascade Lake

48 GB

30 GB

2 TB

CP9

CP9

A2225 A2269 A2240

FG-2601F-DC

Intel Xeon Gold 6208U

Cascade Lake

48 GB

30 GB

2 TB

CP9

CP9

A2225 A2269 A2240

FG-3301E

Intel Xeon Gold 5118

 SkyLake

96 GB

16GB

2TB

CP9

CP9

A2225 A2269 A2240

FG-3401E

Intel Xeon Gold 6130

 SkyLake

96 GB

16GB

2TB

CP9

CP9

A2225 A2269 A2240

FG-3401E-DC

Intel Xeon Gold 6130

 SkyLake

96 GB

16GB

2TB

CP9

CP9

A2225 A2269 A2240

FG-3601E

Intel Xeon Gold 6152

 SkyLake

96 GB

16GB

2TB

CP9

CP9

A2225 A2269 A2240

FG-4201F

Intel Xeon Gold 6248

Cascade Lake

384 GB

30 GB

4 TB

CP9

CP9

A2225 A2269 A2240

FG-4201F-DC

Intel Xeon Gold 6248

Cascade Lake

384 GB

30 GB

4 TB

CP9

CP9

A2225 A2269 A2240

FG-4401F

Intel Xeon Gold 6248

Cascade Lake

384 GB

30 GB

4 TB

CP9

CP9

A2225 A2269 A2240

FG-4401F-DC

Intel Xeon Gold 6248

Cascade Lake

384 GB

30 GB

4 TB

CP9

CP9

A2225 A2269 A2240

FG-5001E1

Intel Xeon E5-2690v4

Broadwell

64GB

16GB

480 GB

CP9

CP9

A2225 A2269 A2240

FG-6300F

Intel Xeon D-1567

Broadwell

192GB

16GB

2 TB

 CP9

Entropy Token

A2225 A2269 A2240

FG-6301F

Intel Xeon D-1567

Broadwell

192GB

16GB

2 TB

 CP9

Entropy Token

A2225 A2269 A2240

FG-6500F

Intel Xeon D-1567

Broadwell

320GB

16GB

2 TB

 CP9

Entropy Token

A2225 A2269 A2240

FG-6501F

Intel Xeon D-1567

Broadwell

320GB

16GB

2 TB

 CP9

Entropy Token

A2225 A2269 A2240

 

                       TOE Virtual Appliance and Related Hardware

Model

License

Hypervisor

CPU*

Entropy

CAVP

FortiGate-VM64

VM01
(1x vCPU core and unlimited RAM)

VMware ESXi 6.7

Intel Xeon
D-1559
(Broadwell)

Intel Xeon
E3-1515MV5
(Skylake)

Intel Xeon
E-2276ME
(Coffee Lake)

 

Token via USB pass-through

A2291 A2298

VM02
(2x vCPU cores and unlimited RAM)

VM04
(4x vCPU cores and unlimited RAM)

VM08
(8x vCPU cores and unlimited RAM)

VM16
(16x vCPU cores and unlimited RAM)

VM32
(32x vCPU cores and unlimited RAM)

VMUL
(Unlimited vCPU cores and RAM)

* Provided with PacStar 451/455

 

 


Security Evaluation Summary

The evaluation was carried out in accordance with the Common Criteria Evaluation and Validation Scheme (CCEVS) process and scheme. The criteria against which FortiGate/FortiOS 6.4 was evaluated are described in the Common Criteria for Information Technology Security Evaluation, Version 3.1 Rev. 5. The product, when configured as identified in the FortiOS 6.4 and FortiGate NGFW Appliances FIPS140-2 and Common Criteria Technote, March 9, 2023 01-649-0773518-20230309, satisfies all of the security functional requirements stated in the FortiGate/FortiOS 6.4 Security Target, Version 1.2, March 2023. The project underwent CCEVS Validator review. The evaluation was completed in March 2023. Results of the evaluation can be found in the Common Criteria Evaluation and Validation Scheme Validation Report (Report Number CCEVS-VR-VID11296-2023) prepared by CCEVS.


Environmental Strengths

The TOE provides the following security functions:

a)          Security Audit. The TOE generates logs for auditable events. These logs can be stored locally in protected storage and/or exported to an external audit server via a secure channel.

b)          Cryptographic Support. The TOE implements a variety of key generation and cryptographic methods to provide protection of data both in transit and at rest within the TOE. In the evaluated configuration, the TOE is in FIPS mode to support the cryptographic functionality. The TOE implements cryptographic protocols such as SSH, TLS, HTTPS, and IPsec.

c)          Residual Data Protection.  The TOE ensures that data cannot be recovered once deallocated.

d)          Stateful Traffic and Packet Filtering. The TOE allows for the configuration and enforcement of stateful packet filtering/firewall rules on all traffic traversing the TOE.

e)          Identification and Authentication. The TOE implements mechanisms to ensure that users are both identified and authenticated before any access to TOE functionality or TSF data is granted. Remote login attempts are limited to an administrator-configured threshold, after which the user must wait for a defined period of time before login attempts can be made. It provides the ability to both assign attributes (user names, passwords and roles) and to authenticate users against these attributes. The TOE also provides X.509 certificate validation for its TLS and IPsec connections.

f)            Security Management. The TOE provides a suite of management functionality, allowing for full configuration of the TOE by an authorized administrator.

g)          Protection of the TSF. The TOE implements a number of protection mechanisms (including authentication requirements, self-tests and trusted update) to ensure the protection of the TOE and all TSF data. The TOE maintains its own time source free from outside interference for the purpose of generating logs and executing time sensitive operations.

h)          TOE Access. The TOE provides session management functions for local and remote administrative sections. Administrative sessions have a defined lifetime for both local and remote sessions, users connecting to the TOE will be presented with a warning and consent banner prior to authentication.

i)            Trusted Path/Channels. The TOE provides secure channels between itself and local/remote administrators and other devices to ensure data security during transit.


Vendor Information


Fortinet, Inc.
Alan Kaye
613-225-9381
akaye@fortinet.com

https://www.fortinet.com/
Site Map              Contact Us              Home