General Overview
Form Factor and Series Options
NetScaler Location |
FIPS Options |
Validated |
Public Cloud/On-Prem |
VPX FIPS |
Level 1 validated. Cert. #4098 |
On-Prem |
MPX 8900 FIPS |
Level 2 validated. Cert #4043 |
On-Prem |
MPX 15000-50G FIPS |
Level 2 validated. Cert #4043 |
NetScaler Location |
FIPS Options |
Compliant |
Azure Public Cloud |
VPX with Azure key vault integration |
Level 2 / Level 3 compliant |
On-Prem |
MPX/SDX 14000 FIPS (Level 3 compliant) |
Level 3 compliant |
On-Prem |
MPX/SDX with External HSM (Thales & nCipher) |
Level 2/ Level 3 compliant |
The following table lists the available options for FIPS 140-3 appliances:
NetScaler Location |
FIPS Options |
Validated |
Public Cloud/On-Prem |
VPX FIPS |
Module InProcess: MIP |
On-Prem |
MPX 8900 FIPS |
Module InProcess: MIP |
On-Prem |
MPX 9100 FIPS |
Module InProcess: MIP |
On-Prem |
MPX 15000-50G FIPS |
Module InProcess: MIP |
● Instead of only being able to offer FIPS ADC Appliances in hardware form, the purpose-built firmware is now also packaged and licensed as a virtual appliance and this offers customers much more flexibility in how they deploy ADC’s.
● There is no longer a dependency on a third-party company to provide the add-on hardware or the firmware that it runs. This ensures better availability of components.
● By architecting and developing all of the software in-house, NetScaler is able to overcome performance limitations that existed due to the communication with the add-on hardware components. The end result for customers is being able to deploy FIPS appliances that perform better.
● The most significant benefit may be that NetScaler customers are now able to deploy FIPS Validated appliances as opposed to FIPS Compliant appliances.
FIPS Encryption / Ciphers
Features and Functions
Upgrading NetScaler Firmware
One of the most important aspects of running a NetScaler ADC is ensuring that you keep the firmware up-to-date with a compatible version. The information in this section is intended to help you understand which firmwares are compatible with the particular NetScaler FIPS appliance that you have so that you can select an appropriate firmware when upgrades are necessary.
NetScaler Models: VPX FIPS, MPX8900 FIPS, MPX15000-50G FIPS | |
Firmware Type |
Compatible Firmware |
FIPS |
12.1 FIPS or 13.1 FIPS1 |
| |
NetScaler Models: MPX9100 FIPS | |
Firmware Type |
Compatible Firmware |
FIPS |
13.1 FIPS1 |
| |
NetScaler Models: MPX14000 FIPS | |
Firmware Type |
Compatible Firmware |
General (non-FIPS) Firmware |
12.1 (EOL 5/30/2023), 13.0, 13.1, or 14.1 |
| |
NetScaler Models: SDX14000 FIPS, including VPX instances2 | |
Firmware Type |
Compatible Firmware |
General (non-FIPS) Firmware |
12.1 (EOL 5/30/2023), 13.0, 13.1, or 14.1 |
Additional Notes on compatibility:
MPX Hardware-Software Compatibility Matrix: https://docs.netscaler.com/en-us/citrix-hardware-platforms/mpx/mpx-hardware-software-compatibility-matrix.html
SDX Hardware-Software Compatibility Matrix:https://docs.netscaler.com/en-us/citrix-hardware-platforms/sdx/sdx-hardware-software-compatibility-matrix.html
Notes on Using the SDX Single Bundle Upgrade (including minimum 12.1 version requirements to upgrade to 13.0 and beyond): https://docs.netscaler.com/en-us/sdx/current-release/single-bundle-upgrade.html
If you happen to need to upgrade from a firmware version no longer under support (12.1 or older), NetScaler Support and NetScaler Consulting Services are available to assist.
Firmware Information and Differences
Pooled Licensing
● Upgrade a perpetual license in NetScaler VPX to NetScaler pooled capacity
● Upgrading a perpetual license in NetScaler MPX to NetScaler pooled capacity
VPX FIPS
SDX FIPS (14000 Family of Appliances)
Performance
Cloud
If you do not see this message, please refer to https://docs.netscaler.com/en-us/citrix-adc/12-1/ssl/citrix-adc-vpx-fips-appliances.html#troubleshooting.
1 13.1 FIPS is currently only viable for testing purposes and should not be used in production environments
2 SDX14000 FIPS appliances are ONLY compatible with non-FIPS firmware, including VPX instances