Check Point 5600 Security Gateway Datasheet
5600 SECURITY GATEWAY
Check Point’s 5600 Next Generation Firewall offers a fully integrated, unified solution tuned to deliver
maximum security against 5th generation threats without compromising performance. The 5600
Security Gateway provides the most advanced threat prevention security for demanding enterprise
networks.
The Most Advanced
Threat Prevention
Equipped with our SandBlast
technology, protecting against
unknown threats and zero-day attacks
Full Security
Uncompromising Performance
Highly optimized with up to 2.78 Gbps of
threat prevention throughput
Designed to Secure
Encrypted Traffic
Powerful platforms for inspection
of SSL traffic
PERFORMANCE HIGHLIGHTS
| Gen II Security Firewall | Gen III Security NGFW¹ | Gen V Security Threat Prevention+SandBlast² |
|---|---|---|
| 20.4 Gbps | 5.1 Gbps | 2.78 Gbps |
Performance measured with enterprise testing conditions. Additional performance details on page 4. 1: Includes Firewall, Application Control,
and IPS. 2: Includes Firewall, Application Control, URL Filtering, IPS, Antivirus, Anti-Bot and SandBlast Zero-Day Protection.
5600
Enterprise-grade security, performance and reliability
The Check Point 5600 Next Generation Security Gateway combines the most comprehensive
security protections to safeguard your mid-size enterprise.
The 5600 is a 1U Next Generation Security Gateway with one I/O expansion slot for higher port
capacity, redundant fans, redundant AC or DC power supply options, a 1TB (HDD) or 240GB (SSD)
disk, and optional Lights-Out Management (LOM) for remote management. This powerful Next
Generation Security Gateway is optimized to deliver real-world threat prevention to secure your
critical assets and environments.
Key Features & Benefits
Advanced Threat Prevention ….… 1 time prevention of known and zero-day threats
Uncompromising Performance .… Achieve up to 2.78 Gbps of threat prevention throughput
Secure Encrypted Traffic ………... Consolidate SSL inspection into one integrated security platform
SPOTLIGHT
5600 SECURITY GATEWAY
1 Sync 10/100/1000Base-T RJ45 port
2 RJ45/micro USB console port
3 One network card expansion slot
4 8x 10/100/1000Base-T RJ45 ports
5 Management 10/100/1000Base-T RJ45 port
6 2x USB ports for ISO installation
7 Lights-Out Management port
Prevent Known and Zero-day Threats
Zero-day protection offering network
security with evasion-resistant malware
detection and complete protection from
the most advanced attacks, ensuring
quick delivery of safe content to users.
All-inclusive Security Solutions
Check Point 5600 Next Generation
Security Gateway offers a complete and
consolidated security solution available
in two complete packages:
- v Threat Prevention
- v Threat Prevention + SandBlast
Inclusive High Performance Package
Purchase the affordable High
Performance Package (HPP) and get a
base system plus one 4x 1Gb SFP
interface card, transceivers, redundant
AC or DC power supplies, Lights-Out-
Management and 16 GB of memory for
high connection capacity.
Remote Management and Monitoring
A Lights-Out-Management (LOM) card
provides out-of-band remote
management to remotely diagnose,
start, restart and manage the appliance
from a remote location. Also use the
LOM web interface to remotely install
an OS image from an ISO file.
ENTERPRISE-GRADE PLATFORM
| 1GbE(copper) | 1GbE(fiber) | 10GbE | Memory | RedundantPower | LOM | ||
|---|---|---|---|---|---|---|---|
| 5600 | Base | 10 | 0 | 0 | 8GB | ○ | ○ |
| 5600 | HPP | 10 | 4 | 0 | 16GB | ● | ● |
| 5600 | Maximums | 18 | 4 | 4 | 32GB | ● | ● |
WELCOME TO THE FUTURE OF CYBER SECURITY
Performance
Enterprise Testing Conditions
- 2.78 Gbps of Threat Prevention¹
- 5.1 Gbps of NGFW
- 5.5 Gbps IPS
- 20.4 Gbps of firewall throughput
Ideal Testing Conditions
- 23 Gbps of UDP 1518 byte packet firewall throughput
- 6.5 Gbps of AES-128 VPN throughput
- 185,000 connections per second, 64 byte response³
- 3.2/6.4/12.8M concurrent connections, 64 byte response³
1: Includes Firewall, Application Control, URL Filtering, IPS, Antivirus, Anti-Bot and SandBlast
Zero-Day Protection. 2: Includes Firewall, Application Control and IPS. 3: Performance
measured with default/HPP/maximum memory with R80.10.
Additional Features
Highlights
- 1x CPUs, 4x physical cores (total)
- 1x 1TB HDD or 240GB SSD storage
- 1 AC or DC power supply (2 redundant PSU option)
- 8, 16 and 32 GB memory options
- Lights-Out-Management card is optional
- Virtual Systems (base/HPP/max mem): 10/20/20
Network Expansion Slot Options (1 of 1 slots open)
- 8x 10/100/1000Base-T RJ45 port card, up to 18 ports
- 4x 1000Base-F SFP port card, up to 4 ports
- 4x 10GBase-F SFP+ port card, up to 4 ports
Fail-Open/Bypass Network Options
- 4x 10/100/1000Base-T RJ45 port card
- 2x 10GBase-F SFP+ port card
Content Security
First Time Prevention Capabilities
- CPU-level, OS-level and static file analysis
- File disarm and reconstruction via Threat Extraction
- Average emulation time for unknown files that require full
sandbox evaluation is under 100 seconds - Maximal file size for Emulation is 100 MB
- Emulation OS Support: Windows XP, 7, 8.1, 10
Applications
- Use 8,000+ pre-defined or customize your own applications
- Accept, prevent, schedule, and apply traffic-shaping
Data Loss Prevention
- Classify 700+ pre-defined data types
- End user and data owner incident handling
Content Security (continued)
- Integrates with Microsoft AD, LDAP, RADIUS, Cisco pxGrid,
Terminal Servers and with 3rd
parties via a Web API
Dynamic User-based Policy
$$ 3^{\mathrm{r d}} $$
- Enforce consistent policy for local and remote users on
Windows, macOS, Linux, Android and Apple iOS platforms
Network
Network Connectivity
- Total physical and virtual (VLAN) interfaces per appliance:
1024/4096 (single gateway/with virtual systems) - 802.3ad passive and active link aggregation
- Layer 2 (transparent) and Layer 3 (routing) mode
High Availability
- Active/Active L2, Active/Passive L2 and L3
- Session failover for routing change, device and link failure
- ClusterXL or VRRP
IPv6
- NAT66, NAT64, NAT46
- CoreXL, SecureXL, HA with VRRPv3
Unicast and Multicast Routing (see SK98226)
- OSPFv2 and v3, BGP, RIP
- Static routes, Multicast routes
- Policy-based routing
- PIM-SM, PIM-SSM, PIM-DM, IGMP v2, and v3
Physical
Power Requirements
Power Requirements Fail-Open/Bypass Network Options
- Single Power Supply rating: 275W
- AC power input: 90 to 264V (47-63Hz)
- Power consumption max: 87.2W
- Maximum thermal output: 297.5 BTU/hr.
Dimensions
- Enclosure: 1RU
- Dimensions (WxDxH): 17.2x20x1.73 in.(437.9x508x44mm)
- Weight: 17.53 lbs. (7.95 kg)
Environmental Conditions
- Operating: 0° to 40°C, humidity 5% to 95%
$$ 0^{ ext{°}} $$
$$ 40^{ ext{°}} ext{C}. $$ - Storage: –20° to 70°C, humidity 5% to 95% at 60°C
$$ 60^{ ext{°}} ext{C} $$
$$ 70^{ ext{°}} ext{C}. $$
Certifications
- Safety: UL, CB, CE, TUV GS
- Emissions: FCC, CE, VCCI, RCM/C-Tick 1
- Environmental: RoHS, WEEE, REACH¹, ISO14001
ORDERING 5600 SECURITY GATEWAYS
| BASE CONFIGURATION1 | SKU |
|---|---|
| 5600 Next Generation Security Gateway Base Configuration, includes 10x1GbE copper ports, 8GB RAM, 1 HDD, 1 AC Power Unit, Next Generation Threat Prevention (NGTP) Security Subscription Package for 1 Year | CPAP-SG5600-NGTP |
| 5600 SandBlast Next Generation Security Gateway Base Configuration, includes 10x1GbE copper ports, 8GB RAM, 1 HDD, 1 AC Power Unit, SandBlast (NGTX) Security Subscription Package for 1 Year | CPAP-SG5600-NGTX |
| HPP CONFIGURATION1 | SKU |
| 5600 Next Generation Security Gateway with High Performance Package, includes10x1GbE copper ports,4x1Gb SFP ports,4 SR transceivers,16 GB RAM,1 HDD,2 AC Power Units,Lights Out Management(LOM),Next Generation Threat Prevention(NGTP)Security Subscription Package for1Year | CPAP-SG5600-NGTP-HPP |
| 5600 Next Generation Security Gateway with High Performance Package,includes10x1GbE copper ports,4x1Gb SFP ports,4 SR transceivers,16 GB RAM,1 HDD,2 AC Power Units,Lights Out Management(LOM),Next Generation Threat Extraction(SandBlast)Security Subscription Package for1Year | CPAP-SG5600-NGTX-HPP |
1 2 and 3 year and Virtual Systems packages also available in the online product catalog
Accessories
INTERFACE CARDS AND TRANSCEIVERS
| INTERFACE CARDS AND TRANSCUVERS | |
|---|---|
| 8 Port 10/100/1000 Base-T RJ45 interface card | CPAC-8-1C-B |
| 4 Port 1000Base-F SFP interface card; requires additional 1000Base SFP transceivers | CPAC-4-1F-B |
| SFP transceiver module for 1G fiber ports - long range (1000Base-LX) | CPAC-TR-1LX-B |
| SFP transceiver module for 1G fiber ports - short range (1000Base-SX) | CPAC-TR-1SX-B |
| SFP transceiver to 1000 Base-T RJ45(Copper) | CPAC-TR-1T-B |
| 4 Port 10GBase-F SFP+ interface card | CPAC-4-10F-B |
| SFP+ transceiver module for 10G fiber ports - long range(10GBase-LR) | CPAC-TR-10LR-B |
| SFP+ transceiver module for 10G fiber ports - short range(10GBase-SR) | CPAC-TR-10SR-B |
| 4 Port 1GE copper Bypass(Fail-Open) network interface card(10/100/1000 Base-T) | CPAC-4-1C-BP-B |
| 2 Port 10GE short-range Fiber Bypass(Fail-Open) network interface card(10GBase-SR) | CPAC-2-10-FSR-BP-B |
| MEMORY | SKU |
| Memory upgrade kit from 8GB to 16GB for 5600 appliance | CPAC-RAM8GB-5000 |
| Memory upgrade kit from 8GB to 32GB for 5600 appliance | CPAC-RAM24GB-5000 |
| Memory upgrade kit from 16GB to 32GB for 5600 appliance | CPAC-RAM16GB-5000 |
| SPARES AND MISCELLANEOUS | SKU |
| Additional/Replacement AC Power Supply for 5600 and 5800 appliances | CPAC-PSU-5600/5800 |
| Additional/Replacement DC power supply unit for 5600 and 5800 | CPAC-PSU-DC-5600/5800 |
| Lights Out Management module | CPAC-LOM-B |
| Slide rails for 5000 Appliances(22"-32") | CPAC-RAILS-5000 |
| Extended slide rails for 5000 Appliances(24"-36") | CPAC-RAILS-EXT-5000 |
Note: for returns of existing security gateways via the RMA process, a 500GB HDD is available
5600 SECURITY GATEWAY
1 Redundant AC or DC power supplies 2 Cooling fans