Check Point VPN-1/FireWall-1

Survey of Check Point Appliances for R70


AERAsec Network Services and Security GmbH


This page is about available appliance families for Check Point R70

This document gives an idea about appliances for Check Point R70. No warranty at all!
Further license information can be found on the corresponding page.
For details and prices please contact Check Point, your local reseller or us.

Since some years Check Point not only provides their software, but the software bundled with hardware. The first appliances were VPN-1 Edge and Safe@. These are not discussed on this page. 

Please be aware that the license is bundled and therefore dependent on the Appliance itself! If an Appliance with bundled Service Blades is bought, the continuous subscription of the integrated services (e.g. IPS, AV) is mandatory. 
Further on, please be aware that licensing in R70 is per Gateway (system) and no longer per Site. So a cluster consisting of two members (NGX R65: 1 Site) requires a management license for two Gateways!

Since the acquisition of the security appliance business of Nokia, there are now six appliance families available: 

- UTM-1 Appliances: Firewall and Management
- IP Appliances: Firewall 
- Power-1 Appliance: Firewall
- IAS Appliances: Firewall
- VSX-1 Appliances: Firewall
- Smart-1 Management Appliances: Management

This page refers to Software Blades of Check Point R70 described here. The knowledge of the official abbreviations is assumed. 

 

UTM-1 Appliances

UTM-1 Appliances always include a Management Server and a Gateway / Firewall. 
Based on the target customers, a UTM-1 Appliance also offers Content Control (Web, Anti Virus, etc.). There are some bundles available, also including a different number of Software Blades. If necessary, further Software Blades or Service Blades can be licensed. 
When the UTM-1 Appliances are going to be centrally managed, please select this option in the first installation steps. When needed, the integrated Management Server can be disabled. There are no licenses for Firewall only, in UTM-1 the Management on the Appliance is always licensed. 
Currently all appliances are delivered with two images: NGX R65 and R70.
Each appliance is for an unlimited number of users. 
All information about throughput is based on Check Point information. 

Name of Appliance
Software Blades included
UTM-1 13x
- Management for 1 Gateway
- 5 Ports
- Compact Desktop
- FW: 400 Mbps, VPN: 100 Mbps
- IPS: 300 Mbps
- 300.000 concurrent sessions
UTM-1 132
UTM-1 136

 

FW, VPN
FW, VPN, IPS, ASPM, URLF, AV

 

UTM-1 27x
- Management for 2 Gateways
- 4 Ports
- 1U rack mountable 
- FW: 400 Mbps, VPN: 100 Mbps
- IPS: 380 Mbps
- 400.000 concurrent sessions
UTM-1 272
UTM-1 276

 

FW, VPN
FW, VPN, IPS, ASPM, URLF, AV

 

UTM-1 57x
- Management for 2 Gateways
- 6 Ports
- 1U rack mountable
- FW: 1.1 Gbps, VPN: 250 Mbps
- IPS: 700 Mbps
- 500.000 concurrent sessions
UTM-1 572
UTM-1 576

 

FW, VPN
FW, VPN, IPS, ASPM, URLF, AV

 

UTM-1 107x
- Management for 2 Gateways
- 6 Ports
- 1U rack mountable
- FW: 1.8 Gbps, VPN: 250 Mbps
- IPS: 900 Mbps
- 1.100.000 concurrent sessions
UTM-1 1073
UTM-1 1076

 

FW, VPN, IPS
FW, VPN, IPS, ASPM, URLF, AV

 

UTM-1 207x
- Management for 2 Gateways
- 8 Ports
- 1U rack mountable
- FW: 2.8 Gbps, VPN: 280 Mbps
- IPS: 1 Gbps
- 1.100.000 concurrent sessions
UTM-1 2073
UTM-1 2076

 

FW, VPN, IPS
FW, VPN, IPS, ASPM, URLF, AV

 

UTM-1 307x
- Management for 2 Gateways
- 10 Ports
- 1U rack mountable
- FW: 4.5 Gbps, VPN: 1.1 Gbps
- IPS: 4 Gbps
- 1.100.000 concurrent sessions
UTM-1 3073
UTM-1 3076

 

FW, VPN, IPS
FW, VPN, IPS, ASPM, URLF, AV

 

back to top

IP Appliances

IP Appliances follow up Nokia appliances. They include the license for one Gateway / Firewall. The number of users is unlimited. A Management is never included. 
These appliances are bundled with Software Blades. If necessary, further Software Blades or Service Blades can be licensed. 
Currently all IP Appliances are delivered with two images: NGX R65 and R70.
All information about throughput is based on Check Point information. 

Name of Appliance
Software Blades included
IP 152
- 4 Ports
- 1 U rack mountable
- FW: 500 Mbps

 

FW, VPN
IP 295
- 6 Ports (up to 8) 
- 1 expansion slot
- 1 U 1/2 rack mountable
- FW: 1.5 Gbps, VPN: 1.0 Gbps
- 1.100.000 concurrent connections 

 

FW, VPN, IPS, ADN, ACCL
IP 395
- 4 Ports (up to 8)
- 2 expansion slots
- 1 U rack mountable
- FW: 3 Gbps, VPN: 677 Mbps
- 1.100.000 concurrent connections

 

FW, VPN, IPS, ADN, ACCL
IP 565
- 4 Ports (up to 12)
- 2 expansion slots
- 1 PCMCIA slot
- 1 U rack mountable
- FW: 6.3 Gbps, 1.7 Gbps
- 1.100.000 concurrent connections

 

FW, VPN, IPS, ADN, ACCL
IP 695
- 4 Ports (up to 16)
- 3 expansion slots
- 1 U rack mountable
- FW: 7.2/11.7 Gbps, VPN: 1.4/3.3 Gbps
- IPS: 4 Gbps
- 1.100.000 concurrent connections 

 

FW, VPN, IPS, ADN, ACCL
IP 1285
- 4 Ports (up to 28)
- 5 expansion slots
- 2 U rack mountable
- FW: 10.3/15.4 Gbps, VPN: 1.9/8.3 Gbps
- IPS: 7 Gbps
- 1.100.000 concurrent connections

 

FW, VPN, IPS, ADN, ACCL
IP 2455
- 4 Ports (up to 32)
- 5 expansion slots
- 2 U rack mountable
- FW: 10.3/29 Gbps, VPN: 1.9/8.3 Gbps
- IPS: 9 Gbps
- 1.100.000 concurrent connections

 

FW, VPN, IPS, ADN, ACCL

back to top

 

Power-1 Appliances

Power-1 Appliances include the license for one Gateway / Firewall. The number of users is unlimited. A Management is never included. 
Based on the target customers, throughput and performance are the key features of these Appliances. There are some bundles available, also including a different number of Software Blades. If necessary, further Software Blades or Service Blades can be licensed. 
Currently the appliances 5075 and 9075 are delivered with two images: NGX R65 and R70. All others are deliverd with R70 only. 
All information about throughput is based on Check Point information. 

Name of Appliance
Software Blades included
Power-1 5075
- 8 Ports (up to 14)
- 1 expansion slot 
- 1 Sync Port
- 1 Management Port 
- 2 U rack mountable
- FW: 9 Gbps, VPN: 2.4 Gbps
- IPS: 7.5 Gbps
- 1.200.000 concurrent connections 

 

FW, VPN, IPS, ADN, ACCL
Power-1 9075
- 8 Ports (up to 18)
- 2 expansion slots 
- 1 Sync Port
- 1 Management Port
- 2 U rack mountable 
- FW: 16 Gbps, VPN: 3.7 Gbps
- IPS: 10 Gbps 
- 1.200.000 concurrent connections

 

FW, VPN, IPS, ADN, ACCL
Power-1 11065
- 8 Ports (up to 18)
- 2 expansion slots 
- 1 Sync Port
- 1 Management Port 
- 2 U rack mountable
- FW: 15 Gbps, VPN: 3.7 Gbps
- IPS: 10 Gbps
   field upgradeable
- 1.200.000 concurrent connections

 

FW, VPN, IPS, ADN, ACCL
Power-1 11075
- 8 Ports (up to 18)
- 2 expansion slots 
- 1 Sync Port
- 1 Management Port 
- 2 U rack mountable
- FW: 20 Gbps, VPN: 4 Gbps
- IPS: 10 Gbps
   field upgradeable
- 1.200.000 concurrent connections

 

FW, VPN, IPS, ADN, ACCL
Power-1 11085
- 8 Ports (up to 18)
- 2 expansion slots 
- 1 Sync Port
- 1 Management Port 
- 2 U rack mountable
- FW: 25 Gbps, VPN: 4.5 Gbps
- IPS: 15 Gbps
- 1.200.000 concurrent connections

 

FW, VPN, IPS, ADN, ACCL

back to top

IAS Appliances

IAS Appliances mean "Integrated Appliance Solutions". They include the license for one Gateway / Firewall. The number of users is unlimited. A Management is not included. There are some bundles available, also including a different number of Software Blades for R70. If necessary, further Software Blades or Service Blades can be licensed. 
IAS Appliances can be used with both supported versions: NGX R65 and R70. 
All information about throughput is based on Check Point information. 

Name of Appliance
Software Blades included
IAS M2
- 4 Ports (up to 10)
- 1 U rack mountable
- FW: 4.5 Gbps, VPN: 1.1 Gbps
- IPS: 4 Gbps
- 1.100.000 concurrent connections

 

IAS M6
- 10 Ports 
- 1 U rack mountable
- FW: 8 Gbps, VPN: 2.4 Gbps
- IPS: 7.1 Gbps
- 1.100.000 concurrent connections

 

IAS M2
- 14 Ports (up to 18)
- 2 U rack mountable
- FW: 12 Gbps, VPN: 3.5 Gbps
- IPS: 8.6 Gbps
- 1.100.000 concurrent connections

 

back to top

 

VSX-1 Appliances

VSX-1 Appliances include the license for a number of Virtual Systems. The number of users is unlimited. A Management is never included. 
Currently all VSX-1 Appliances are delivered with NGX R65. 
All information about throughput is based on Check Point information. 

Name of Appliance
Software Blades included
VSX-1 3070
- 10 Ports
- 1 U rack mountable
- FW: 4.5 Gbps, VPN: 1.1 Gbps
- 1.000.000 concurrent connections
- 5 VS included, up to 10 possible

 

currently NGX R65 only
therefore no Software Blades
VSX-1 9070
- 14 Ports (up to 18)
- 2 U rack mountable
- FW: 13.5 Gbps, VPN: 3.5 Gbps
- 1.100.000 concurrent connections
- 10 VS included, up to 150 possible

 

currently NGX R65 only
therefore no Software Blades
VSX-1 9090
- 28 Ports (up to 36)
- 4 U rack mountable
- FW: 27 Gbps, VPN: 7 Gbps
- 1.800.000 concurrent connections
- 10 VS included, up to 150 possible

 

currently NGX R65 only
therefore no Software Blades

 

back to top

Smart-1  Management Appliances

Smart-1 Appliances are for managing Firewalls. These appliances do not include a Firewall, but the possibility to manage a number of them. 
They are delivered in R70, so managing Gateways in NGX R65 and R70 is possible. Depending on the Appliance, some Software Blades are bundled. Ordering further Software Blades is possible. 

Name of Appliance
Software Blades included
Smart-1 5
- Management of 5 Gateways (ext. to 25 possible) 
- 1x 500 GB HD
- Logs per second: 7.500

 

NPM, EPM, LOGS, PRVS

 

Smart-1 25
- Management of 25 Gateways (ext. to 50 possible) 
- 4x 500 GB HD
- Logs per second: 14.000

 

NPM, EPM, LOGS, MNTR, IPSA, PRVS, UDIR

 

Smart-1 50
- Management of 50 Gateways (ext. to 150 possible) 
- Suitable for Provider-1 MDS for 3, 5 or 10 CMA
- 4x 1 TB HD
- Logs per second: 30.000

 

SmartCenter: 
NPM, EPM, LOGS, MNTR, IPSA, PRVS, UDIR
Provider-1 for 3, 5 or 10 Domains: 
NPM, EPM, LOGS, MNTR, IPSA, PRVS, MPTL, UDIR

 

Smart-1 150
- Management of 150 Gateways (ext. to 150 possible) 
- Suitable for Provider-1 MDS for 3, 5 or 10 CMA
   (ext. to 50 CMA possible)
- 4x 1 TB HD, extensible
- Logs per second: 30.000
Provider-1 for 3, 5 or 10 Domains: 
NPM, EPM, LOGS, MNTR, IPSA, PRVS, MPTL, UDIR

 

back to top

 

 

 


No warranty at all, your Feedback is welcome!
© 2003-2010 AERAsec Network Services and Security GmbH, last change 2009-07-19
back to http://www.vpn-1.de/aerasec