Does Azure VPN Gateway support FIPS 140-2

Anand Franklin 21 Reputation points
2020-07-14T12:36:58.31+00:00

Hello there,

We have a requirement to establish a Site-to-Site VPN Tunnel, and would like to know whether Azure VPN Gateway is FIPS 140-2 compliant?

Thank you, Anand

Azure VPN Gateway
Azure VPN Gateway
An Azure service that enables the connection of on-premises networks to Azure through site-to-site virtual private networks.
1,450 questions
0 comments No comments
{count} votes

Accepted answer
  1. GitaraniSharma-MSFT 49,386 Reputation points Microsoft Employee
    2020-07-15T08:18:09.17+00:00

    Hello @AnandFranklin-3216 ,

    Azure is built with a combination of hardware, commercially available operating systems (Linux and Windows), and Azure-specific version of Windows. Through the Microsoft Security Development Lifecycle (SDL), all Azure services use FIPS 140-2 approved algorithms for data security because the operating system uses FIPS 140-2 approved algorithms while operating at a hyper scale cloud.

    You can use the industry-standard IPsec protocol to encrypt traffic between your corporate VPN gateway and Azure as well as between the VMs located on your Virtual Network. In accordance with the Public Key Infrastructure Operational Security Standard, which is a component of the Microsoft Security Policy, Microsoft leverages the cryptographic capabilities included in the Windows operating system for certificates and authentication mechanisms, which includes the use of cryptographic modules that meet the U.S. government's Federal Information Processing Standards (FIPS) 140-2 standard.

    Please refer : https://learn.microsoft.com/en-us/microsoft-365/compliance/offering-fips-140-2?view=o365-worldwide
    https://learn.microsoft.com/en-us/microsoft-365/compliance/office-365-encryption-in-the-microsoft-cloud-overview?view=o365-worldwide

    Hope this helps!

    Kindly let us know if the above helps or you need further assistance on this issue.


    Please don’t forget to "Accept the answer" wherever the information provided helps you, this can be beneficial to other community members.

    0 comments No comments

2 additional answers

Sort by: Most helpful
  1. Leon Laude 85,721 Reputation points
    2020-07-14T14:30:14.657+00:00

    Hi,

    Something here might help:

    Federal Information Processing Standard (FIPS) Publication 140-2
    https://learn.microsoft.com/en-us/microsoft-365/compliance/offering-fips-140-2?view=o365-worldwide

    Best regards,
    Leon

    0 comments No comments

  2. Anand Franklin 21 Reputation points
    2020-07-15T13:44:30.237+00:00

    Hello Gitarani,

    The provided information is adequate and it answers my question.

    Thank you, Anand