44000 - 64000 Security System Datasheet
CHECK POINT
SECURITY SYSTEMS
Scalable performance, advanced security
Product Benefits
• Scalable platform that grows with your business
• High port density with 10, 40 and 100 GBE fiber ports
• Full redundancy (N+N) eliminates down-time
• Advanced protection against known and unknown threats
• Designed for ease of management and fast deployment
Product Features
• Scalable security solution
• Raw firewall performance up to 395 Gbps in the 44000 and 880 Gbps in the 64000
• Enterprise Threat Prevention performance up to 90 Gbps in the 44000 and 180 Gbps in the 64000
• High port density with up to 64x100GbE, 12x400GbE or 4x100GbE ports
• Intra/Dual-Chassis redundancy
• Carrier grade, NEBS certified, ATCA compliant chassis
• Full range of customizable protection capabilities from Firewall, IPS, to SandBlast Threat Emulation
INSIGHTS
Large data centers have uncompromising needs for performance, uptime and scalability. High end security gateway solutions must perform network access control within the unique requirements of these environments—ultra-high throughput, connection capacity, session and logging rate—while supporting the latest networking standards like IPv6. Additionally, with the increase in sophisticated attacks, security layers to protect against both known and unknown threats have become essential for organizations. In addition to their vast performance and security needs, data center environments are characterized by rigid requirements for high reliability of its various systems. All of these requirements drive the need for redundant, serviceable and highly available components and systems.
SOLUTION
The Check Point 44000 and 64000 Security Systems are built for these demanding environments and are based on proven technologies used by Fortune 100 companies and telecommunication vendors all over the world. The Check Point Firewall, IPS, Application Control and Identity Awareness technologies have been awarded the highest 3rd-party certifications possible including NATO Information Product Catalog; US Government penetration testing; Department of Defense Information Systems Agency, ISO-ICE 15408 and more.
The ATCA compliant, carrier grade design offers unsurpassed scalability, availability and serviceability with high performance and high port density. Redundant Security Switch Modules (SSM) provide switching fabric, physical interface, and routing functions. Redundant Chassis Management Modules (CMM) continuously check and monitor the health of the chassis including fans, power supplies and Security Gateway Modules (SGM). For optimal reliability, Check Point ClusterXL Load Sharing distributes the load between Security Gateway Modules in one chassis and ClusterXL High Availability operates between chassis. Check Point SynCXL provides for highly efficient synchronization of system and security information between components in order to ensure high system performance. Deploy two chassis in high availability mode to eliminate down-time.
These two platforms improve security, protect business continuity and reduce operational costs in complex, mission critical security environments such as data centers, Managed Service Providers and telecommunication companies. By adding more SGMs customers get more security and performance. Because SGMs are hot-swappable, customers can add SGMs, boosting performance to new or existing 44000 and 64000 systems even when those systems are in production.
44000 and 64000
- Chassis Management Modules (CMM)
- Security Gateway Modules (SGM)
- Security Switch Modules (SSM)
- Power Supplies
- Fan Trays
64000 SECURITY SYSTEM
The Check Point 64000 Security System is the industry’s fastest security system, achieving up to 180 Gbps of Enterprise Threat Prevention throughput in a single firewall instance. Even more, the ability to support 110.4 million concurrent connections and 4.92 million sessions per second brings unparalleled performance to multi-transaction environments.
This ATCA compliant, scalable system contains up to 12 Security Gateway Modules (SGM) and 2 Security Switch Modules (SSM). The SSMs distribute the load evenly across the 1.2 Tpps chassis backplane fabric to the SGMs ensuring near linear scalability as SGMs are added to the chassis.
The 64000 Security System has been designed from the ground up to support the unique service requirements of Telco’s and data centers. This includes system level redundancy and chassis level redundancy of the components that comprise the 64000 such as power-supplies, fans and the various hardware modules.
44000 SECURITY SYSTEM
The Check Point 44000 Security System is a compact 6U ATCA compliant chassis that can contain up to 6 Security Gateway Modules (SGM) and up to 2 Security Switch Modules (SSM). The 44000 chassis distributes the load evenly among the SGMs ensuring near linear scalability up to 395 Gbps of firewall throughput as SGMs are added to the chassis.
The 44000 Security System delivers up to 90 Gbps of Enterprise Threat Prevention performance with 6 SGMs. The shared design, components, and the flexibility to add additional security controls facilitates future expansion and growth of the network infrastructure, providing excellent investment protection.
NEBS CERTIFIED
The 64000 meets Network Equipment Building Systems (NEBS) Level 3 certification requirements for products used in telecommunications networks.
VIRTUAL SYSTEMS
Check Point Virtual Systems (VS) enable organizations to create virtualized security gateways to consolidate infrastructure and segment the network while reducing costs and offering customized per-Virtual System Software Blade security. The solution supports seamless performance scale-up by adding more Virtual Systems and hardware blades, with traffic evenly balanced across the entire chassis.
| Gateway Mode | VS Mode |
|---|---|
| Firewall | supported |
| IPsec VPN | supported |
| Identity Awareness | supported |
| IPS | supported |
| Application Control | supported |
| URL Filtering | supported |
| Antivirus | supported |
| Anti-Bot | supported |
| SandBlast Threat Emulation | supported |
| DLP | not supported |
| Mobile Access | not supported |
EASE OF MANAGEMENT
Our renowned security management software centrally manages the 44000 and 64000 from anywhere in the network. With our intuitive configuration wizard, the first SGM can be deployed in less than 30 minutes and additional SGMs can be added seamlessly.
INTEGRATED SECURITY ARCHITECTURE
Each 44000 and 64000 Security System is packaged with Firewall, IPsec VPN, Identity Awareness, Advanced Networking, and Acceleration and Clustering. Customize your protection by enabling additional advanced threat prevention features such as IPS and SandBlast Threat Emulation to block zero-day attacks and unknown threats. This lowers total cost of ownership and meets any need, today and in the future.
PERFORMANCE
| 44000 | 64000 | |
|---|---|---|
| Threat Prevention Throughput (Gbps)¹ | up to 90 | up to 180 |
| NGFW Throughput (Gbps)² | up to 204 | up to 408 |
| Firewall Throughput (Gbps) | up to 335 | up to 800 |
| Firewall Throughput, 1518 byte UDP (Gbps) | up to 395 | up to 880 |
| Connections Per Second (M) | up to 2.46 | up to 4.92 |
| Concurrent Sessions (M) | up to 55.2 | up to 110.4 |
| Security Gateway Modules | SGM400 (DefaultMax) | 1/6 |
| Maximum Virtual Systems | 250 | 250 |
1: Includes Firewall, Application Control, URL Filtering, IPS, Antivirus, Anti-Bot and SandBlast Zero-Day Protection with R80SP.20.
2: Includes Firewall, Application Control and IPS with R80SP.20.
HARDWARE
| 44000 | 64000 | |
|---|---|---|
| Physical Enclosure | 6U | 18U |
| Dimensions Standard (WxDxH) | 17.5 x 15 x 10.5 in. | 17.7 X 15.2 x 26.43 in. |
| Dimensions Metric (WxDxH) | 445 x 383 x 267 mm | 449 x 385.6 x 696.7 mm |
| Weight (chassis without SGMs) | 20 kg (44 lbs.) | 57.4 kg (128.6 lbs.) |
| Weight (fully populated) | 40 kg (88.2 lbs.) | 99.8 kg (220.1 lbs.) |
| Power Supplies | 4 | 4 (up to 9 SGMs), 6 (10-12 SGMs) |
| Input Voltage | 85-240VAC | 200-240VAC |
| Frequency | 47-63 Hz | 47-63Hz |
| Single Power Supply Rating | 1200W @ 110V, 1584W @ 220V | 2496W @ 208V/230V |
| Maximum Power Consumption | 2500W | 5600W |
| Thermal Output | 8,530 BTU/hour | 19,108 BTU/hour |
| Operating Temperature | 23° to 122°F / -5° to 50°C, 5%-90% (non-condensing) | 23° to 122°F / -5° to 50°C, 5%-90% (non-condensing) |
| Storage Temperature | -40° to 158°F / -40° to 70°C, 5%-95% (non-condensing) | -40° to 158°F / -40° to 70°C, 5%-95% (non-condensing) |
| Safety Certification | UL/EN/IEC60950-1 Certified with all country deviations | UL/EN/IEC60950-1 Certified with all country deviations |
| Emissions | FCC part 15 Class A | FCC part 15 Class A |
| Environmental | RoHS, WEEE | RoHS, WEEE |
| NEBS Certified | ✕ | ✓ |
NETWORK
| Maximum Port Capacity (2 Security Switch Modules) |
|---|
| 100G QSFP28 |
| 40G QSFP+ |
| 10GBase-F SFP+ |
Transceivers
Network and Synchronization
- QSFP28 transceiver for 100GE ports (SR/MR/LR)
- QSFP transceiver for 40GE ports (SR/LR)
- QSFP splitter for 40 GBE ports
- SFP+ (100GE) fiber transceiver for SFP+ ports (SR/LR)
- SFP fiber transceiver for 1GGE SFP ports (SXLX)
- Twisted pair transceiver for 1GGE SFP ports
Management and Log
- SFP+ (100GE) fiber transceiver for SFP+ ports (SR/LR)
- Fiber transceiver for 1GGE SFP ports (SXLX)
- Twisted pair transceiver for 1GGE SFP ports (SXLX)
The above are the maximum port capacities for a 2x SSM configuration. The SSM port configuration can be configured in multiple ways. Please refer to the latest 60000/40000 Administration Guide for an available port configuration that matches your environment.
ORDERING INFORMATION
Chassis SKU
64000 Security System with AC power, includes chassis, 2xCMM, fans and 4 AC power supplies CPAP-CHASSIS-64000
64000 Security System with DC power, includes chassis, 2xCMM, fans and 4 AC power supplies CPAP-CHASSIS-64000-DC
44000 Security System with AC power, includes chassis, 2xCMM, fans, and 4 AC power supplies CPAP-CHASSIS-44000
Security Gateway Modules
Security Gateway Module SGM400 for 44000 and 64000 CPAP-SGM400
Security Switch Modules
Switch Module SSM440 for 64000 Security Platform with up to 40 GBE CPAP-SSM440
Security Switch Module SSM440 for 64000 Security Platform with up to 100 GBE CPAP-SSM440-100G
100 GBE upgrade license for a single SSM440 CPSB-100G-SINGLE-UPG
Security Service Extension¹ SKU
Next Generation SandBlast Zero-day Protection package for 1 year; includes Application Control, URL Filtering, IPS, Antivirus, Anti-Bot Threat Emulation CPAB-NGTX-64000-1Y
Next Generation Threat Prevention Package for 1 year; includes Application Control, URL Filtering, IPS, Antivirus, Anti-Bot CPBS-NGTX-64000-1Y
Next Generation Firewall Package for 1 year; includes Application Control and IPS CPBS-NGWF-64000-1Y
Next Generation SandBlast Zero-day Protection package for 1 year; includes Application Control, URL Filtering, IPS, Antivirus, Anti-Bot Threat Emulation CPBS-NGTX-44000-1Y
Next Generation Threat Prevention Package for 1 year; includes Application Control, URL Filtering, IPS, Antivirus, Anti-Bot CPBS-NGTX-44000-1Y
Next Generation Firewall Package for 1 year; includes Application Control and IPS CPBS-NGWF-44000-1Y
Mobile Access for unlimited concurrent connections CPSB-MOB-U
¹ Two and three year SKUS are also available. See the online Product Catalog