Check Point 26000 Security Gateway Datasheet
QUANTUM 26000 SECURITY GATEWAY
AI ML powered Threat Prevention
Protect networks and users from zero-days, phishing, DNS, and ransomware attacks.
Industry Recognition
Named a Leader for the Gartner Magic Quadrant Firewalls.
23rd time in the NT for Network.
Unified Management and Ops Efficiency
Increase protection and reduce TCO with a consolidated security architecture.
AI Deep Learning powered threat prevention to secure enterprise data centers.
Named a Leader in the For Enterprise Firewalls Q4 20. Awarded the Frost & Sullivan Company of the Year.
Check Point Quantum 26000
Next Generation Firewalls enable enterprises to deploy the industry's leading threat prevention capabilities at all points of their infrastructure, scaling security according to their changing business needs. This enables enterprises to prevent and block even the most advanced attacks before they can disrupt business, greatly increasing the efficiency of their security operations.
PERFORMANCE HIGHLIGHTS
| Firewall | Next Gen Firewall | Threat Prevention |
|---|---|---|
| 106.2 Gbps | 40.5 Gbps | 24 Gbps |
| Performance measured with enterprise testing conditions. Additional performance details on page 3.1: Includes Firewall, Application Control, and IPS. 2: Includes Firewall, Application Control, URL Filtering, IPS, Antivirus, Anti-Bot, and SandBlast Zero-Day Protection. |
SPOTLIGHT
26000 SECURITY GATEWAY
- RJ45 and USB Type-C console ports
- Lights-out Management port
- 2x USB 3.0 ports
- Sync 10/100/1000 Base-T port
- Management 10/100/1000 Base-T port
- ESD grounding point
- 2x 480GB SSD RAID1
- Eight network card expansion slots
- 3x redundant power supplies (back view not shown)
- 4x field replaceable fans (back view not shown)
The speed and sophistication of evasive zero-day DNS and phishing attacks require AI Deep Learning to predict and block malicious behavior without human intervention. Quantum Firewalls use Check Point's threat intelligence cloud 40+ AI/ML engines to block emerging threats that haven't been seen before.
AI Deep Learning Threat Prevention
If you're ready to move from 10 to 25, 40 or 100 GbE, so is the 26000 Next Generation Security Gateway. The 26000 Security Gateway lets you connect your 10 GbE server uplinks to your core network.
| NGFW | NGTP | SNBT | |
|---|---|---|---|
| Firewall, VPN, Mobile Access | √ | √ | √ |
| Content Awareness | √ | √ | √ |
| Application Control | √ | √ | √ |
| Intrusion Prevention System | √ | √ | √ |
| URL Filtering | √ | √ | |
| Antivirus and Anti-Bot | √ | √ | |
| DNS Security | √ | √ | |
| Threat Emulation (sandboxing) | √ | ||
| Threat Extraction (CDR) | √ | ||
| Zero Phishing | √ |
Next Generation Firewall, Next Generation Threat Prevention and SandBlast packages
| 1GbE copper | 1GbE fiber | 10GbE | 100/40/25*GbE | Memory | Redundant Power | Redundant Storage | LOM | |
|---|---|---|---|---|---|---|---|---|
| Base model | 10 | 0 | 0 | 0 | 48GB | ● | ○ | ○ |
| Plus model | 10 | 0 | 12 | 0 | 96GB | ● | ● | ● |
| Max capacity | 66 | 32 | 32 | 8 | 128GB | ● | ● | ● |
Optional Accessories
- Integrated SD-WAN
- IoT Security
Quantum IoT Protect now provides autonomous threat prevention. Quantum Firewalls discover IoT assets, feed those to the IoT Cloud Service to automatically map IoT devices to profiles, and then apply a zero-trust policy on the firewalls to prevent IoT threats in 5 minutes.
Remote Management and Monitoring: A Lights-Out-Management (LOM) card provides out-of-band management to remotely diagnose, start, restart, and manage the appliance from a remote location.
SPECIFICATIONS
Enterprise Test Conditions
| Threat Prevention1(Gbps) | 24 |
|---|---|
| NGFW2(Gbps) | 40.5 |
| IPS(Gbps) | 43 |
| Firewall(Gbps) | 106.2 |
RFC 3511, 2544, 2647, 1242 Performance (Lab)
| Firewall 1518B UDP (Gbps) | 316.5 |
|---|---|
| VPN AES-128 (Gbps) | 40.1 |
| Connections/sec | 550,000 |
| Concurrent connections2 | 10/20/32M3 |
- Includes Firewall, Application Control, URL Filtering, IPS, Antivirus, Anti-Bot, and SandBlast Zero-Day Protection with logging enabled.
- Includes Firewall, Application Control, and IPS with logging enabled.
- Performance measured with Base/Plus/maximum memory.
Additional Features
- 2x CPUs, 36 physical cores, 72 virtual cores (total)
- 1x 1TB HDD or 480GB SSD, (2x SSD in Plus)
- 3x AC power supplies (DC option)
- Lights-Out-Management card (optional in Base package)
- 8x 10/100/1000Base-T RJ45 port card, up to 66 ports
- Virtual Systems (base/ PLUS /max mem): 125/250/250
- 4x 10GBase-F SFP+ port card, up to 32 ports
- 4x 1000Base-F SFP port card, up to 32 ports
Content Security
- 2x 100/40/25G QSFP28 port double- slot- width card, up to 8 ports
- Use 10,000+ pre-defined or customize your own applications
- Accept, prevent, schedule, and apply traffic-shaping
First Time Prevention Capabilities
- File disarm and reconstruction via Threat Extraction
- Maximal file size for Emulation is 100 MB
- Classify 700+ pre-defined data types
- End user and data owner incident handling
Dynamic User-based Policy
- Enforce consistent policy for local and remote users on Windows, macOS, Linux, Android, and Apple iOS platforms
Network Connectivity
- Integrated SD-WAN network optimization and resilience
- Total physical and virtual (VLAN) interfaces per appliance: 1024/4096 (single gateway/with virtual systems)
- 802.3ad passive and active link aggregation
- Layer 2 (transparent) and Layer 3 (routing) mode
High Availability
- Active/Active L2, Active/Passive L2 and L3
- Session failover for routing change, device and link failure
- ClusterXL or VRRP
IPv6 Unicast and Multicast Routing
- CoreXL, SecureXL, HA with VRRPv3
- NAT66, NAT64, NAT46
- OSPFv2 and v3, BGP, RIP
- Static routes, Multicast routes
Physical Specifications
- Single Power Supply rating AC: 850W, DC: 1300W
- Power input: 100 to 240V (47-63Hz), 40~-72VDC
- Weight: 46.3 lbs. (21 kg)
- Safety: UL, CB, CE, TUV GS
Environmental Conditions
- Power input: 100 to 240V (47-63Hz), 40~-72VDC
- Power consumption avg/max: 330/589W
- Storage: −20∞ to 70∞C, humidity 5% to 95% at 60∞C
- Environmental: RoHS, WEEE, REACH1, ISO14001
ORDERING QUANTUM 26000 SECURITY GATEWAY
SECURITY APPLIANCE
| SECURITY APPLIANCE1 | SKU |
|---|---|
| 26000 Base configuration:10x1GbE copper ports,48GB RAM,1x1TB HDD,3xAC PSUs,telescopic rails,SandBlast(SNBT)Subscription Package for 1 Year | CPAP-SG26000-SNBT |
| 26000 Plus configuration:10x1GbE copper ports,12x10GbE SFP+ports,12xSR transceivers,96GB RAM,2x480GBSSD,3xACPSUs,LOM,telescopic rails,5VS,SandBlast(SNBT)for1Year | CPAP-SG26000-PLUS-SNBT |
| Quantum IoT Network Protection for 1 year for 26000 appliances | CPSB-IOTP-26000-1Y |
| Quantum IoT Network Protection for 1 year for 26000 PLUS appliances | CPSB-IOTP-26000-PLUS-1Y |
| Quantum SD-WAN subscription for 1 year for 26000 appliances | CPSB-SDWAN-26000-1Y |
| Quantum SD-WAN subscription for 1 year for 26000 PLUS appliances | CPSB-SDWAN-26000-PLUS-1Y |
The Base package includes 2 virtual systems (VS) - one management VS and one production/data VS. These are not additive or counted when adding additional VS licenses. Plus includes 5 VS licenses which are additive when adding additional VS licenses.
Accessories
| INTERFACE CARDS AND TRANSCEIVERS | SKU |
|---|---|
| 8 Port 10/100/1000 Base-T RJ45 interface card | CPAC-8-1C-C |
| 4 Port 1000Base-F SFP interface card; requires additional 1000Base SFP transceivers | CPAC-4-1F-C |
| SFP transceiver module for 1G fiber ports - long range [1000Base-LX] | CPAC-TR-1LX-C |
| SFP transceiver module for 1G fiber ports - short range [1000Base-SX] | CPAC-TR-15X-C |
| SFP transceiver to 1000 Base-T RJ45(Copper) | CPAC-TR-1T-C |
| 4 Port 10GBase-F SFP+ interface card | CPAC-4-10F-C |
| SFP+ transceiver module for 10G fiber ports - for links up to 40km(10GBASE-ER) | CPAC-TR-10ER-C |
| SFP+ transceiver module for 10G fiber ports - long range up to 10km(10GBase-LR) | CPAC-TR-10LR-C |
| SFP+ transceiver module for 10G fiber ports - short range [100GBase-SR] | CPAC-TR-10SR-C |
| SFP+ transceiver 10GBASE-T RJ45(Copper) - for links up to 30m over CAT6a/CAT7 | CPAC-TR-10T-C |
| 10G Direct Attach Copper(DAC) Cable, [10BASE-CU]3 meters | CPAC-DAC-10G-3M |
| 2 Port 10/25/40/100G QSFP28 Dual Width interface card* | CPAC-2-40/100F-C |
| QSFP28 transceiver module for 100G fiber ports - short range(100GBase-SR4) | CPAC-TR-100SR |
| QSFP28 transceiver module for 100G fiber ports - long range(100GBase-LR4) | CPAC-TR-100LR |
| 100G SWDM4, LC connector, 75m/0M3 fiber | CPAC-TR-100SWDM4 |
| 100G CWDM4, LC connector, 2Km/ single mode fiber | CPAC-TR-100CWDM4 |
| QSFP+ transceiver module for 40G fiber ports - short range(40GBase-SR) | CPAC-TR-40SR-QSFP-300m |
| QSFP+ transceiver module for 40G fiber ports - long range(40GBase-LR) | CPAC-TR-40LR-QSFP-10Km |
| Bi-directional QSFP transceiver for 40G fiber ports - short range(40GBase-SR-BD) | CPAC-TR-40SR-QSFP-BIDI |
| QSFP28 to SFP28 Adapter - 10G/25G fiber adaptor | CPAC-TR-QSFP28-5FP28 |
| SFP28 transceiver module for 25G fiber ports with QSFP28 adaptor - short range(25GBase-SR) | CPAC-TR-25SR-ADP |
| SFP28 transceiver module for 25G fiber ports with QSFP28 adaptor - long range(25GBase-LR) | CPAC-TR-25LR-ADP |
| SFP+ transceiver module for 10G fiber with QSFP28 adaptor - for links up to 40km(10GBASE-ER) | CPAC-TR-10ER-ADP |
| SFP+ transceiver module for 10G fiber with QSFP28 adaptor - long range up to 10km(10GBASE-LR) | CPAC-TR-10LR-ADP |
| SFP+ transceiver module for 100G fiber with QSFP28 adaptor - short range(10GBase-SR) | CPAC-TR-10SR-ADP |
| SFP+ transceiver 10GBASE-T RJ45(Copper) with QSFP28 adaptor - for links up to 30m over CAT6a/CAT7 | CPAC-TR-10T-ADP |
| 100G Direct Attach Copper cable(QSFP28), 3 meters | CPAC-DAC-100G-3M |
| 40G Direct Attach Copper cable(QSFP28), 3 meters | CPAC-DAC-40G-3M |
| 25G Direct Attach Copper cable(QSFP28), 3 meters | CPAC-DAC-25G-3M |
| 10G Direct Attach Copper cable,(10BASE-CU) 3 meters | CPAC-DAC-10G-3M |
- CPAC-2-40/100F-C 25G transceivers will be supported in a future Jumbo Hot Fix
ORDERING QUANTUM 26000 (continued)
FAIL-OPEN NETWORK INTERFACE CARDS
| 4 Port 1GE copper Bypass(Fail-Open) Network interface card(10/100/1000 Base-T) | CPAC-4-1C-BP-C |
|---|---|
| 2 Port 10GE Short-range Fiber Bypass(Fail-Open) Network interface card(10GBase-SR) | CPAC-2-10FSR-BP-C |
MEMORY
| MEMORY | SKU |
|---|---|
| Memory upgrade kit from 48GB to 96GB for 26000 Security Gateways | CPAC-RAM48GB-26000 |
| Memory upgrade kit from 96GB to 128GB for 26000 Security Gateways | CPAC-RAM32GB-26000 |
| Memory upgrade kit from 48GB to 128GB for 26000 Security Gateways | CPAC-RAM80GB-26000 |
SPARES AND MISCELLANEOUS
| SPARES AND MISCELLANEOUS | SKU |
|---|---|
| 1TB HDD for 16000/26000 Security Gateways | CPAC-HDD-1T-C |
| 480GB SSD for 16000/26000 Security Gateways | CPAC-SSD-480G-C |
| AC power supply for 16600HS, 26000, 28000, 28600HS Security Gateways | CPAC-PSU-AC-26000/28000 |
| Dual DC power supplies for 16000 and 26000 Security Gateways | CPAC-PSU-DC-Dual-16000/26000/28000 |
| DC power supply for 16000 and 26000 Security Gateways | CPAC-PSU-DC-16000/26000 |
| Replacement Lights-Out Management Module | CPAC-NLOM-C |
| Replacement Fan | CPAC-FAN-26000/28000 |
| Slide rails for 26000 Security Gateways (22"-32") | CPAC-RAIL-L |
| Extended slide rails for 26000 Security Gateways (24"-36") | CPAC-RAIL-EXT-L |
All-inclusive Security
| NGFW | NGTP | SNBT (SandBlast) | |
|---|---|---|---|
| Basic access control plus IPS | √ | √ | √ |
| VPN (IPsec) | √ | √ | √ |
| Mobile Access | √ | √ | √ |
| Identity Awareness | √ | √ | √ |
| Application Control | √ | √ | √ |
| Content Awareness | √ | √ | √ |
| IPS | √ | √ | √ |
| URL Filtering | √ | √ | |
| Anti-Bot | √ | √ | |
| Anti-Virus | √ | √ | |
| Anti-Spam | √ | √ | |
| DNS Security | √ | √ | |
| SandBlast Threat Emulation | √ | ||
| SandBlast Threat Extraction | √ | ||
| Zero Phishing | √ | ||
| IoT Network Protection | optional | optional | optional |
| SD-WAN Network Optimization | optional | optional | optional |
The first-year purchase includes the SNBT package. Security subscription renewals, NGFW, NGTP, and SNBT are available for subsequent years. Optional security capabilities can be ordered a-la-carte or separately.