Skip to main content
FIPS 140-2 applies to Aviatrix versions earlier than 9.0. Starting in version 9.0, Aviatrix transitions to FIPS 140-3; see Federal Information Processing Standard (FIPS) 140-3 for the 9.0+ implementation, upgrade requirements, CA rotation, and rollback behavior.
You can install the FIPS 140-2 Module via a Security Patch . After the FIPS 140-2 patch is installed, you can turn it On from the Settings > Configuration > General tab.
Turning On this setting will restart OpenVPN services and cause your VPN clients to disconnect and then reconnect to the gateways.
The FIPS 140-2 approved crypto functions are described in this Security Policy PDF. According to this document, the following algorithms that Aviatrix supports are FIPS 140-2 compliant: SSL VPN encryption algorithm set on the server is AES-256-CBC. For OpenVPN clients running a version 2.3 or lower the negotiated algorithm would be AES-256-CBC. For OpenVPN clients running 2.4 or greater, the negotiated algorithm would be AES-256-GCM due to NCP (Negotiable Crypto Parameters). The SSL VPN authentication algorithm is SHA512.