Appliance Comparison Chart

Similar documents
Appliance Comparison Chart

Appliance Comparison Chart

CHECK POINT NEXT GENERATION SECURITY GATEWAY FOR THE DATACENTER

SECURITY FOR SMALL BUSINESSES

Check Point Appliance

Appliance Comparison Chart

Check Point Appliance

Check Point 4800 Appliance

Check Point Appliance

CHECK POINT APPLIANCES

Check Point 4400 Appliance

Check Point Appliance

Check Point Appliance

CHECK POINT AND SECURITY SYSTEMS

SD-WAN. Model Specifications: SteelHead SD Series. Specification Sheet

Flexible and scalable five enterprise-grade Smart-1 dedicated management appliances. Full Threat Visibility

Check Point 1100 Appliances Frequently Asked Questions

Next Generation Firewalls For Your Network Security

*1. Firewall throughput measured with App-ID and User-ID features enabled utilizing 64KB HTTP transactions. 2.

*Performance and capacities are measured under ideal testing conditions using PAN-OS.0. Additionally, for VM

*1. Firewall throughput measured with App-ID and User-ID features enabled utilizing 64KB HTTP transactions. 2.

*1. Firewall throughput measured with App-ID and User-ID features enabled utilizing 64KB HTTP transactions. 2.

Datasheet. 10G 16-Port Managed Aggregation Switch. Model: US-16-XG. Non-Blocking Throughput Switching. Maximum Performance and Low Latency

Datasheet. 10G 16-Port Managed Aggregation Switch. Model: US-16-XG. Non-Blocking Throughput Switching. Maximum Performance and Low Latency

*1. Firewall throughput measured with App-ID and User-ID features enabled utilizing 64KB HTTP transactions. 2.

Aruba 7000 Series Mobility Controller Data Sheet

Check Point DDoS Protector Introduction

*1. Firewall throughput measured with App-ID and User-ID features enabled utilizing 64KB HTTP transactions. 2.

Alcatel-Lucent OmniAccess 4x50 Series Mobility Controllers Service Multi-tenant Network Management

*1. Firewall throughput measured with App-ID and User-ID features enabled utilizing 64KB HTTP transactions. 2.

*1. Firewall throughput measured with App-ID and User-ID features enabled utilizing 64KB HTTP transactions. 2.

*1. Firewall throughput measured with App-ID and User-ID features enabled utilizing 64KB HTTP transactions. 2.

ARUBA 7000 SERIES MOBILITY CONTROLLER

*1. Firewall throughput measured with App-ID and User-ID features enabled utilizing 64KB HTTP transactions. 2.

*Performance and capacities are measured under ideal testing conditions using PAN-OS 8.0. Additionally, for VM

*1. Firewall throughput measured with App-ID and User-ID features enabled utilizing 64KB HTTP transactions. 2.

ARUBA 7000 SERIES MOBILITY CONTROLLER

*1. Firewall throughput measured with App-ID and User-ID features enabled utilizing 64KB HTTP transactions. 2.

STEELHEAD PRODUCT FAMILY SPEC SHEET

SteelHead Product Family

SECURE 6. Secure64 Appliances Purpose-built DNS appliances for the most demanding environments DNS APPLIANCES DATA SHEET. Appliance Descriptions

STEELHEAD PRODUCT FAMILY SPEC SHEET

ASA5525-FPWR-K9 Datasheet. Overview. Check its price: Click Here. Quick Specs

SteelHead Product Family

ABSOLUTE REAL-TIME PROTECTION SERIES

Corrigendum 3. Tender Number: 10/ dated

McAfee Network Security Platform

QuickSpecs. Models HP TippingPoint S8010F Next Generation Firewall Appliance

Feature. *1. Firewall throughput measured with App-ID and User-ID features enabled utilizing 64KB HTTP transactions. 2.

SteelHead Product Family

Cisco Firepower 9300 Security Appliance

Sophos SG Series. The All-New Desktop Appliances. Unleash the full potential of your network

Infoblox Trinzic DDI Appliances. Trinzic Appliances Deliver Actionable Network Intelligence. A Scalable Family of Hardware and Software Appliances

JURUMANI MERAKI CLOUD MANAGED SECURITY & SD-WAN

McAfee Network Security Platform

ARUBA 7000 SERIES MOBILITY CONTROLLER

Sophos SG Series Appliances

McAfee Network Security Platform 9.1

NetScaler SD-WAN features

Infoblox Trinzic DDI Appliances. Trinzic Appliances Deliver Actionable Network Intelligence. A Scalable Family of Hardware and Software Appliances

SEVONE DATA APPLIANCE FOR EUE

Meraki Z-Series Cloud Managed Teleworker Gateway

Meraki MX Cloud Managed Security & SD-WAN

Sophos SG Series Appliances

STEELHEAD PRODUCT FAMILY SPEC SHEET

Sophos XG Firewall. Unrivalled performance, security and control

Cisco Next Generation Firewall and IPS. Dragan Novakovic Security Consulting Systems Engineer

Datasheet. Managed Gigabit Switches with SFP. Models: US-24, US-48. Non-Blocking Throughput Switching Performance. Gigabit Ethernet RJ45 Ports

Datasheet. 8-Port 10G SFP+ Router. Model: ER-8-XG. 80 Gbps Aggregate Throughput. 10G Ethernet SFP+ Ports. Hot-Swappable Modular Power Supplies

Meraki MX Family Cloud Managed Security Appliances

ARUBA 7000 SERIES CLOUD SERVICES CONTROLLER

VeloCloud SD-WAN Subscription

Meraki MX Family Cloud Managed Security Appliances

Check Point Virtual Systems & Identity Awareness

DATA SHEET MODEL AXC1000 HIGHLIGHTS OVERVIEW. Redefining Enterprise Wireless Management

Imperva SecureSphere Appliances

Max sessions (IPv4 or IPv6) 500, , ,000

DATA SHEET. Cloud-Managed Mid-Enterprise SD-WAN Router with Gigabit PoE+ Ethernet

MX Cloud Managed Security Appliance Series

Gigabit SSL VPN Security Router

Fregata. DDoS Mitigation Solution. Technical Specifications & Datasheet 1G-5G

Meraki MX CLOUD MANAGED SECURITY & SD-WAN

Driving Network Visibility

Datasheet. Managed PoE+ Gigabit Switches with SFP. Models: US-8-150W, US W, US W, US W, US W, US W

SMALL BUSINESS. Model 20/30/50 30 LTE One 210/ BPL-210 BPL-310

ISG-600 Cloud Gateway

Datasheet. Managed PoE+ Gigabit Switches with SFP. Models: US W, US W, US W, US W

Sophos XG Firewall. Unrivalled simplicity, security and insight

McAfee Network Security Platform 9.2

THUNDER ADC APPLIANCE SPECIFICATIONS

HUAWEI USG6650/6660/6670/6680 Next-Generation Firewalls ---High-Performance Security for Small Data Centers and Large or Medium-sized Enterprises

MX Cloud Managed Security Appliance Series

Cisco ASA with FirePOWER Services

Datasheet. Managed PoE+ Gigabit Switches with SFP. Models: US-8-150W, US W, US W, US W, US W, US W

Seqrite TERMINATOR (UTM) Unified Threat Management Solution.

Sophos XG Firewall. Unrivalled Security, Simplicity and Insight

Datasheet. Gigabit Routers with SFP. Models: ER-4, ER-6P. Sophisticated Routing Features. Next-Generation Price/Performance Value

Security-hardened Appliances for Network Infrastructure Identification

McAfee Network Security Platform 8.1

Surat Smart City Development Ltd. Surat Municipal Corporation 1

Transcription:

Security Gateway Appliances 300 300 500 500 5400 5600 5800 5900 Branch Office Small Enterprise Mid-Size Enterprise Real-World Production Conditions Security 60 50 340 45 600 950 750 400 Firewall (Gbps).. 4. 5.3 0 7.5 6 IPS Throughput (Gbps) 350 Mbps 460 Mbps 730 Mbps 80 Mbps.08.9 3.05 4.36 NGFW Throughput (Gbps) 0 Mbps 60 Mbps 450 Mbps 50 Mbps 690 Mbps.8.84 Threat Prevention (Gbps) 30 Mbps 60 Mbps 50 Mbps 90 Mbps 395 Mbps 645 Mbps.035.65 Ideal Testing Conditions Firewall Throughput (Gbps) 4 4 4.5 6 5 35 5 Connections Per Second (K) 40 48 0 5 50 85 85 85 Concurrent Sessions (M) 3 3. 3. 3./6.4 3./6.4 3./.8 3./.8 3./.8 3./.8 VPN Throughput (Gbps).7.5.6.88.6 6.5 0 0. IPS Throughput (Gbps)..44.45 3 3.9 7.8 0 3.5 NGFW Throughput (Gbps) 850 Mbps.5..7 3.4 5.8 8..4 Threat Prevention (Gbps) 45 Mbps 740 Mbps.34.645.745 3.385 4.95 6.75 0/00/000Base-T (Base/Max) 6/6 6/6 6/4 6/4 0/8 0/8 0/6 0/6 000Base-F SFP (Base/Max) NA NA 0/4 0/4 0/4 0/4 0/8 0/8 0GBase-F SFP+ (Base/Max) NA NA NA NA NA 0/4 0/8 0/8 40GB QSFP (Base/Max) NA NA NA NA NA NA 0/4 0/4 Expansion Slot NA NA Fail-Over NIC Option NA NA Yes Yes Yes Yes Yes Yes Additional Features CPUs/physical cores/virtual cores (total) /4/4 /4/4 // // // /4/4 /4/8 /8/6 Storage x 30GB HDD or 40GB SSD x 500GB HDD or 40GB SSD + HDD or SSD Memory Options (GB) 8 8 8, 6 8, 6 8, 6, 3 8, 6, 3 8, 6, 3 8,6, 3 LOM Card NA NA Optional Optional Optional Optional Included Included Virtual Systems Max (base/hpp/max memory) 0 0 0/0/0 0/0/0 0/0/0 0/0/0 0/0/0 0/0/0 Enclosure Desktop Desktop U U U U U U Weight.3kg (.9 lbs).3kg (.9 lbs) 6.kg (3.7 lbs) 6.kg (3.7 lbs) 6.37kg (4 lbs) 7.95kg (7.53 lbs) 8.37kg (8.45 lbs) 0kg (.05 lbs) Hot-Swappable Supplies NA NA NA NA NA Optional Optional Optional DC NA NA Optional Optional Optional Optional Optional Optional Input 0-40VAC, 47-63 Hz Single Supply Rating 40W 40W 50W 50W 50W 75W 75W 500W Consumption (Max) 9.5W 9.5W 6.9W 6.9W 76.5W 87.W 0W 65W Includes Firewall, Application Control and IPS Software Blades. Includes Firewall, Application Control, URL Filtering, IPS, Antivirus, Anti-Bot, SandBlast Software Blades. 3 Performance measured with default/maximum memory. October 4, 07 07 Check Point Software Technologies Ltd. All rights reserved.

Security Gateway Appliances continued 5400 5600 3500 3800 Large Enterprise Data Center Grade Real-World Production Conditions Security 600 3850 5500 6300 Firewall (Gbps) 30 30 34 43 IPS Throughput (Gbps) 4.5 8 0 NGFW Throughput (Gbps) 3 5. 6.3 7. Threat Prevention (Gbps).695 3 3.955 4.5 Ideal Testing Conditions Performance Firewall Throughput (Gbps) 58 76 6 8 Connections Per Second (K) 85 85 00 00 Concurrent Sessions (M) 3 3./5.6 6.4/5.6 6.4/5..8/5. VPN Throughput (Gbps) 0.8 5.8 6 6 IPS Throughput (Gbps) 4 8 30 NGFW Throughput (Gbps).5 7 0 7 Threat Prevention (Gbps) 7 3. 7 8.6 0/00/000Base-T (Base/Max) 0/6 0/6 0/4 0/4 000Base-F SFP (Base/Max) 0/ 0/ 0/0 0/0 0GBase-F SFP+ (Base/Max) / / /0 /0 40G QSFP+ (Base/Max) 0/4 0/4 0/4 0/4 00/5G QSFP8 (Base/Max) 0/4 0/4 0/4 0/4 Expansion Slot 3 3 5 5 Fail-Open/Bypass NIC Option Yes Yes Yes Yes Additional Features CPUs/physical cores/virtual cores (total) /8/6 /6/3 /0/40 /4/48 Storage x TB HDD or 480GB SSD RAID x TB HDD or 480GB SSD RAID x TB HDD or 480GB SSD RAID x TB HDD or 480 GB SSD RAID Memory Options (GB) 8, 4, 64 6, 3, 64 6, 64, 8 3, 64, 8 LOM Card Included Included Included Included LCD Display Graphic LCD Graphic LCD Graphic LCD Graphic LCD Virtual Systems Max (base/hpp/max memory) 0/40/40 60/80/5 60/5/5 5/50/50 Enclosure U U U U Weight 4.3kg (3.5 lbs) 4.3kg (3.5 lbs) 5.8kg (34.8 lbs) 5.8 kg (34.8 lbs.) Hot-Swappable Supplies AC or DC AC or DC AC or DC AC or DC Input 0-40VAC (47-63Hz); -40.5VDC/4A -48VDC/9.A, -60VDC/6.0A Single Supply Rating AC(550W), DC(800W) AC(550W), DC(800W) 800W 800W Consumption (Max) 63W 97W 383W 399W Includes Firewall, Application Control and IPS Software Blades. Includes Firewall, Application Control, URL Filtering, IPS, Antivirus, Anti-Bot, SandBlast Software Blades. 3 Performance measured with default/maximum memory. October 4, 07 07 Check Point Software Technologies Ltd. All rights reserved. 3

Security Systems Real-World Production Conditions 44000 64000 Data Center, Telco, Carrier Grade Security Up to 33000 Up to 66000 Firewall (Gbps) Up to 40 Up to 539 Firewall and IPS (Gbps) Up to 7 Up to 4 NGFW (Gbps) Up to 9.6 Up to 59. Threat Prevention (Gbps) Up to Up to 4 Ideal Testing Conditions Firewall Throughput (Gbps) Up to 377 Up to 880 VPN Throughput (Gbps) Up to 6.7 Up to 33 IPS Recommended Profile (Gbps) Up to 6 Up to 5 NGFW (Gbps) Up to 64 Up to 8 Connections Per Second (M) Up to 4.5 Up to 9 Concurrent Sessions (M) Up to 4 Up to 8 0GBase-F SFP+ (Max Ports) 64 64 40G QSFP+ (Max Ports) 00G QSFP8 (Max Ports) 4 4 Expansion Slot 7 4 Virtual Systems Max VS Supported 50 50 Enclosure 6U 6U Weight Max: 40 kg (88. lbs.) Max: 99.8 kg (0. lbs.) Hot-Swappable Supplies 4 AC 4 AC (up to 9 SGMs), 6 AC (0- SGMs) or DC Input See data sheet Single Supply Rating 00W@0V; 584W@0V AC: (496W @ 08V/30V), DC: (-48V to -60V 5A) Consumption (Max) 500W 5600W Assumes maximum production throughput with real-world traffic blend, a typical rule-base size, NAT and logging enabled and the most secure threat prevention protection October 4, 07 07 Check Point Software Technologies Ltd. All rights reserved. 4

Small Branch Office Security Appliances 430 450 470 490 Real-World Production Conditions Security 75 4 94 33 Firewall (Mbps) 900 00 600 800 IPS Throughput (Mbps) 75 5 85 375 NGFW Throughput (Mbps) 00 0 40 30 Threat Prevention (Mbps) 90 50 75 0 Ideal Testing Conditions Firewall Throughput (Gbps).5 3. 4 IPS Throughput (Mbps) 35 575 700 800 NGFW Throughput (Mbps) 300 490 65 800 Threat Prevention (Mbps) 5 400 500 550 VPN Throughput (Mbps) 75 500 500 000 Connections Per Second (K) 0 7 30 40 Concurrent Sessions (K) 500 500 500 500 Wireless Option 80. b/g/n/ac, single band.4 or 5GHz 80. b/g/n/ac, dual band.4 and 5GHz ADSL/ADSL+ (Annex A or B) - - over Ethernet (PoE) - Optional 0/00/000Base-T Ports 8 8 000Base-F Ports 0 Additional Features Security Architecture Embedded GAiA Embedded GAiA 3G, 4G Modem Support Yes Yes SD Card Slot Micro SDHC slot Micro SDHC slot Web-based Management Available Available Central Management Model Enterprise Security Management Enterprise Security Management Enclosure Desktop Desktop Weight.3kg (.8 lbs).6kg (3.6 lbs) Input 00/40VAC, 50-60Hz 00/40VAC, 50-60Hz Single Supply Rating V/3.33A 40W desktop adaptor V/5.4A 65W desktop adaptor Consumption (Max) 5W (non-wi-fi), 30W (Wi-Fi option) 55W (non-wi-fi), 60W (Wi-Fi option) Includes Firewall, Application Control and IPS Software Blades Includes Firewall, Application Control, URL Filtering, IPS, Antivirus, Anti-Bot, SandBlast Software Blades. October 4, 07 07 Check Point Software Technologies Ltd. All rights reserved. 5

Rugged Appliances 00R Real-World Production Conditions Security 49 Firewall (Mbps) 700 Firewall and IPS (Mbps) 60 Ideal Testing Conditions Firewall Throughput (Gbps) VPN Throughput (Mbps) 450 Connections Per Second (K) 0 Concurrent Sessions (K) 400 0/00/000Base-T (Max) 6 000Base-F (Max) Additional Features 3G/4G Yes Serial Console Port Yes Mount Options DIN rail Central Management Model Enterprise Security Management Certifications Industrial IEC 6850-3, IEEE 63 Maritime IEC-60945 B, IACS-E0 Operating Environment Temperature -40 to67 F / -40 to 75 C Humidity 0%-90% (non-condensing) Enclosure Desktop Weight. kg (.65 lbs.) AC 00-40V, 50 60 Hz DC V-7V, -48V DC Consumption (Max) 5W Also see the [Siemens RUGGEDCOM APE (Application Processing Engine) Line Module] Test clause IEC-60945-8., IACS-E0- were not performed October 4, 07 07 Check Point Software Technologies Ltd. All rights reserved. 6

DDoS Protector 506 006 006 44 84 4 040 040 3040 4040 Grade Enterprise Datacenter Carrier Performance Capacity (Gbps) 0.5 4 8 4 0 0 30 40 Throughput (Gbps) 0.5 4 8 0 0 30 40 Max Concurrent Sessions (M) 4 4 4 6 6 6 6 Max DoS Flood Attack Prevention Rate (M)(pps) Latency Real-time Signatures Inspection Ports 0 0 0 5 5 5 5 < 60 micro seconds Detect and protect against attacks in less than 8 seconds 0/00/000 Copper Ethernet 4 4 4 8 8 8 - - - - GbE Fiber (SFP) 4 4 4 - - - - 0GbE Fiber (XFP) - - - 4 4 4 - - - - /0 GbE (SFP+) - - - - - - 0 0 0 0 40 GbE (QSFP+) - - - - - - 4 4 4 4 Management Ports 0/00/000 Copper RS-3 Console Operation Mode Operation Deployment Modes Tunneling protocols support IPv6 Policy Action Block Actions High Availability Fail-open / Fail-close Clustering Transparent L Forwarding In-line; span port monitoring; copy port monitoring; local out-of-path; out-of-path mitigation (scrubbing center solution) VLAN Tagging, LTP, MPLS, GRE, GTP Support IPv6 networks and block IPv6 attacks Block and Report; Report Only Drop packet, reset (source, destination, both), suspend (source, source port, destination, destination port or any combination); Challenge-Response for HTTP and DNS attacks Internal fail-open/fail-close for copper ports; internal fail-close for SFP ports; optional fail-open for SFP ports 3 Internal fail-open/fail-close for copper ports; internal fail-close for SFP and XFP ports; optional fail-open for SFP and XFP ports 4 Active-Passive Cluster Enclosure U U Dual Supply Optional Yes - Hot Swappable Actual performance figures may change per network configuration, traffic type, etc. Throughput is measured with behavioral and signature protections using the ecommerce protection profile 3 External fiber fail-open switch with SFP ports is available at additional cost 4 External fiber fail-open switches with SFP or XFP ports are available at additional cost Internal fail-close for SFP+ and QSFP+ ports; optional fail-open for SFP+ and QSFP+ ports 4 Consumption (Max) 77W 476W 634W October 4, 07 07 Check Point Software Technologies Ltd. All rights reserved. 7

Virtual Systems Appliances 500 500 500 500 5400 5400 5600 5600 5800 Performance Firewall Throughput (Gbps) 4.5 6. 6.0 8.8 39.6 5 45 35 63 VPN Throughput (Gbps).6.9.9 3.4. 3.9 6.5.7 0 8 Concurrent Sessions (M) 6.4 7.7 6.4 7.7.8 5.4.8 5.4.8 5.4 5900 5900 5400 5400 5600 5600 3500 3500 3800 Performance Firewall Throughput (Gbps) 5 93.6 58 04.4 76 36.8 6 08.8 8 30.4 VPN Throughput (Gbps) 0. 8.4 0.8 9.4 5.8 8.4 6 46.8 6 46.8 Concurrent Sessions (M).8 5.4 5.6 30.7 5.6 30.7 5. 6.4 5. 6.4 With memory upgrade and GAiA OS 5800 3800 Public and Private Cloud Virtual Appliances VMware vsphere 5/5./5.5/6.0 VMware NSX Manager 6./6./6.3 Cisco APIC./.3/.0/./. KVM Microsoft Hyper-V Amazon AWS Microsoft Azure Google Cloud Platform vsec VE (Virtual Edition) vsec for NSX Security Management Multi-Domain Security Management OpenStack October 4, 07 07 Check Point Software Technologies Ltd. All rights reserved. 8

Software Blades Appliance Comparison Chart NGFW NGTP NGTX 3000 5000 5000 3000 400 00R Security Gateway Software Blades Firewall Identity Awareness IPsec VPN Advanced ing & Clustering Mobile Access IPS Application Control URL Filtering Antivirus Anti-Spam Anti-Bot SandBlast Threat Emulation SandBlast Threat Extraction DLP Security Management Software Blades Policy Management Logging & Status Mobile Access Sofware Blade: The 3000, 5000, 5000, 3000 and 00R include 5 users in the default package and this can be extended using the Mobile Access packages The 430/450 and 470/490 include Mobile Access for 00 and 00 users respectively Optional Security Management Software Blades available: SmartWorkflow, Monitoring, Management Portal, User Directory, SmartProvisioning, SmartEvent, Endpoint Policy Management, Compliance The 400 NGTX package includes Threat Emulation. Threat Extraction is not currently supported on this appliance. The NGFW package is available as a renewal package. = Included October 4, 07 07 Check Point Software Technologies Ltd. All rights reserved. 9