: Prisma SD-WAN Support for FedRAMP Moderate Environment
Focus
Focus

Prisma SD-WAN Support for FedRAMP Moderate Environment

Table of Contents

Prisma SD-WAN Support for FedRAMP Moderate Environment

Learn about the support for FedRAMP moderate environment in Prisma SD-WAN.
Prisma SD-WAN supports new deployments in a FedRAMP Moderate environment. Prisma SD-WAN does not support upgrades from an existing Prisma SD-WAN deployment to a FedRAMP Moderate deployment.
When you purchase Prisma SD-WAN for a FedRAMP Moderate deployment, Prisma SD-WAN requires SKUs that are specific to the FedRAMP environment. Work with your authorized Palo Alto Networks representative or partner to make sure that you purchase the correct SKUs for your FedRAMP Moderate deployment.
Prisma SD-WAN ION device platforms ION-1200-S-5G, ION 3200, and ION-9200 on device software version 6.1.6 are currently available for FedRAMP Moderate deployments.
Prisma SD-WAN uses FIPS-validated encryption and hardened on-premises ION devices as part of the Prisma SASE FedRAMP service offering.
You need to toggle from the non-FIPS to FIPS mode for the supported ION devices from the Prisma SD-WAN web interface (controller). When you enable FIPS mode, all cryptographic security parameters (CSPs), including the CIC certificate, are cleared and the device is rebooted. After reboot, the device comes up in the FIPS approved mode of operation with a new CIC provisioned by the controller and the FIPS functionality enabled on the device.