Check Point 3600 Security Gateway Datasheet
QUANTUM 3600 SECURITY GATEWAY
Top Security Effectiveness
Leader with 99.7% malware block rate in
Miercom NGFW Security Benchmark (2023)
Hyperscale Network Security
On-demand expansion and resilient access
to mission-critical applications
Industry Recognition
Named a Leader for the 23rd time in the
Gartner® Magic Quadrant™ for Network
Firewalls
Unified Management and Ops Efficiency
Increase protection and reduce TCO with a
consolidated security architecture
AI Deep Learning powered threat prevention
to secure branch offices
Check Point Quantum 3600 Next Generation
Firewalls enables enterprises to deploy the
industry’s leading threat prevention capabilities at
all points of their infrastructure, including remote
branch offices.
This enables enterprises to prevent and block even
the most advanced attacks before they can disrupt
business — greatly increasing the efficiency of their
security operations.
PERFORMANCE HIGHLIGHTS
Firewall Next Gen Firewall
| Firewall | Next Gen Firewall | Threat Prevention |
|---|---|---|
| 3.3 Gbps | 1.5 Gbps | 780 Mbps |
SPOTLIGHT
3600 SECURITY GATEWAY
- 5x 10/100/1000 Base-T ports
- Management 10/100/1000 Base-T port
- 2x USB 3.0 ports
- RJ45 console port
- USB Type-C console port
- 2x connectors to external power supply adaptors
AI Deep Learning Threat Prevention
The speed and sophistication of evasive
zero-day DNS and phishing attacks
requires AI Deep Learning to predict and
block malicious behavior without human
intervention. Quantum Firewalls use
Check Point’s threat intelligence cloud
40+ AI/ML engines to block emerging
threats that haven’t been seen before.
ENTERPRISE-GRADE PLATFORM
Best-in-class Security Management
Unified management across networks
and cloud environments increases
operational efficiency and lowers the
complexity of managing your security.
One console can manage all aspects of
security from policy to threat
prevention.
| 1 GbE (copper) | Memory | Redundant Power |
|---|---|---|
| 6 | 8GB | ○ |
IoT Security
Quantum IoT Protect now provides
autonomous threat prevention. Quantum
Firewalls discover IoT assets, feed those
to the IoT Cloud Service to automatically
map IoT devices to profiles and then
apply a zero-trust policy on the firewalls
to prevent IoT threats in 5 minutes.
Integrated SD-WAN
Security protects you when you’re
connected. SD-WAN ensures you’re
always connected, and the connection
offers the best user experience for the
lowest cost. Quantum SD-WAN in
Quantum firewalls keeps you secure and
connected.
SPECIFICATIONS
Performance
| Threat Prevention(1Mbps) | 780 |
|---|---|
| NGFW2(Gbps) | 1.5 |
| IPS(Gbps) | 1.99 |
| Firewall(Gbps) | 3.3 |
RFC 3511, 2544, 2647, 1242 Performance (Lab)
| Firewall 1518B UDP (Gbps) | 4 |
|---|---|
| VPN AES-128(Gbps) | 2.71 |
| Connections/sec | 32,000 |
| Concurrent connections | 2M |
1: Includes Firewall, Application Control, URL Filtering, IPS, Antivirus, Anti-Bot and SandBlast
Additional Features
Highlights
- 1x CPUs, 4 physical cores
- 1x 240 GB SSD storage
- 8 GB memory
- Virtual Systems (maximum) : 5
Content Security
First Time Prevention Capabilities
- CPU-level, OS-level and static file analysis
- File disarm and reconstruction via Threat Extraction
- Maximal file size for Emulation is 100 MB
- Average emulation time for unknown files that require full
sandbox evaluation is under 100 seconds
Dynamic User-based Policy
- Accept, prevent, schedule, and apply traffic-shaping
Data Loss Prevention
- Integrates with Microsoft AD, LDAP, RADIUS, Cisco pxGrid, Terminal Servers and with 3 parties via a Web API
- Use 10,000+ pre-defined or customize your own applications
- Enforce consistent policy for local and remote users on Windows, macOS, Linux, Android and Apple iOS platforms
- Integrated SD-WAN network optimization and resilience
Network Connectivity
- Total physical and virtual (VLAN) interfaces per appliance: 1024/4096 (single gateway/with virtual systems)
- 802.3ad passive and active link aggregation
High Availability
- Active/Active L2, Active/Passive L2 and L3
- Session failover for routing change, device and link failure
- ClusterXL or VRRP
IPv6
- NAT66, NAT64, NAT46
- CoreXL, SecureXL, HA with VRRPv3
Physical Power Requirements
- Single Power Supply rating: 40W
- AC power input: 100 to 240V (50-60Hz)
- Power consumption avg/max: 21W/25W
- Enclosure: Desktop
- Dimensions (WxDxH): 8.3 x 8.3 x 1.65 in. (210 x 210 x 42mm)
- Emissions: FCC, CE, VCCI, RCM/C-Tick
- Safety: UL, CB, CE, TUV GS
- Storage: -20°C to 70°C, humidity 5 to 95%
Certifications
- Factory certificate
ORDERING QUANTUM 3600 SECURITY GATEWAYS
BASE CONFIGURATION
| BASE CONFIGURATION¹ | SKU |
|---|---|
| 3600 Security Gateway Configuration, includes 6x 1GbE copper ports,8 GB RAM,1240 GB SSD,1 external AC power adaptor,SandBlast (SNBT) Security Subscription Package for 1 Year | CPAP-SG3600-SNBT |
| Quantum IoT Network Protection for 1 year for 3600 appliances | CPSB-IOTP-3600-1Y |
| Quantum SD-WAN subscription for 1 year for 3600 appliances | CPSB-SDWAN-3600-1Y |
Includes 2 virtual systems (VS) - one management VS and one production/data VS. These are not additive or counted when adding additional VS licenses.
SPARES AND MISCELLANEOUS
| SPARES AND MISCELLANEOUS | SKU |
|---|---|
| Replacement/Additional Power Supply for 3600 and 3800 Security Gateways | CPAC-PSU-3600/3800 |
| Rack Mount kit for the 1500, 3600 and 3800 Security Gateways | CPAC-1500/3600/3800-RM-DUAL |
All-inclusive Security
| NGFW | NGTP | SNBT(SandBlast) | |
|---|---|---|---|
| Basic access control plus IPS | Prevent known threats | Prevent known and zero-day attacks | |
| Firewall | √ | √ | √ |
| VPN(IPsec) | √ | √ | √ |
| Mobile Access | √ | √ | √ |
| Identity Awareness | √ | √ | √ |
| Application Control | √ | √ | √ |
| Content Awareness | √ | √ | √ |
| IPS | √ | √ | √ |
| URL Filtering | √ | √ | |
| Anti-Bot | √ | √ | |
| Anti-Virus | √ | √ | |
| Anti-Spam | √ | √ | |
| DNS Security | √ | √ | |
| SandBlast Threat Emulation | √ | ||
| SandBlast Threat Extraction | √ | ||
| Zero Phishing | √ | ||
| IoT Network Protection | optional | optional | optional |
| SD-WAN Network Optimization | optional | optional | optional |
The first-year purchase includes the SNBT package. Security subscription renewals, NGFW, NGTP and SNBT are available for subsequent years. Optional security capabilities can be ordered a-la-carte or separately.