Check Point 6900 Security Gateway Datasheet
QUANTUM 6900 SECURITY GATEWAY
Top Security Effectiveness
Leader with 99.7% malware block rate in Miercom NGFW Security Benchmark (2023)
Unified Management and Ops Efficiency
Increase protection and reduce TCO with a consolidated security architecture
Named a Leader for the 23rd time in the Gartner® Magic Quadrant™ for Network Firewalls Named a Leader in the Forrester Wave™
Industry Recognition
Named a Leader for the 23rd time in the AI Deep Learning powered threat prevention to secure enterprises
Named a Leader in the Forrester Wave™ Enterprise Firewalls Q4 2022 Awarded the Frost & Sullivan Firewall Company of the Year
Check Point Quantum 6900 Next Generation Firewalls enable enterprises to deploy the industry’s leading threat prevention capabilities at all points of their infrastructure, scaling security according to their changing business needs.
This enables enterprises to prevent and block even the most advanced attacks before they can disrupt business — greatly increasing the efficiency of their security operations.
PERFORMANCE HIGHLIGHTS
Firewall Next Gen Firewall
| Firewall | Next Gen Firewall | Threat Prevention |
|---|---|---|
| 37 Gbps | 17 Gbps | 7.4 Gbps |
Performance measured with enterprise testing conditions. Additional performance details on page 3. 1: Includes Firewall, Application Control, and IPS. 2: Includes Firewall, Application Control, URL Filtering, IPS, Antivirus, Anti-Bot and SandBlast Zero-Day Protection.
SPOTLIGHT
6900 SECURITY GATEWAY
- Sync 10/100/1000 Base-T port
- RJ45 console port
- 2x network card expansion slots
- 8x 10/100/1000 Base-T ports
- Management 10/100/1000 Base-T port
- 2x USB 3.0 ports
- Lights-out Management port
- USB Type-C console port
- 2x 480GB SSD RAID1
- Redundant hot-swap power supplies
AI Deep Learning Threat Prevention
The speed and sophistication of evasive zero-day DNS and phishing attacks requires AI Deep Learning to predict and block malicious behavior without human intervention. Quantum firewalls use Check Point’s threat intelligence cloud 40+ AI/ML engines to block emerging threats that haven’t been seen before.
Flexible I/O Options
| NGFW | NGTP | SNBT | |
|---|---|---|---|
| Firewall, VPN, Mobile Access | √ | √ | √ |
| Content Awareness | √ | √ | √ |
| Application Control | √ | √ | √ |
| Intrusion Prevention System | √ | √ | √ |
| URL Filtering | √ | √ | |
| Antivirus and Anti-Bot | √ | √ | |
| DNS Security | √ | √ | |
| Threat Emulation (sandboxing) | √ | ||
| Threat Extraction(CDR) | √ | ||
| Zero Phishing | √ |
Flexible I/O Options
The 6900 includes 10 on-board 1 GbE copper ports. Add additional I/O as you like in the two expansion slots; 8x 1GbE copper, 4x 1GbE fiber, or 4x 10GbE SFP+.
Next Generation Firewall, Next Generation Threat Prevention and SandBlast packages
| 1 GbE(copper) | 1 GbE(fiber) | 10 GbE | 100/40/25GbE | Memory | Redundant Storage | Redundant Power | LOM | |
|---|---|---|---|---|---|---|---|---|
| Base model | 10 | 0 | 0 | 0 | 16GB | ○ | ○ | ○ |
| Plus model | 10 | 0 | 4 | 0 | 32GB | ● | ● | ● |
| Max capacity | 26 | 8 | 8 | 2 | 64GB | ● | ● | ● |
IoT Security
Quantum IoT Protect now provides autonomous threat prevention. Quantum Firewalls discover IoT assets, feed those to the IoT Cloud Service to automatically map IoT devices to profiles and then applies a zero-trust policy on the firewalls to prevent IoT threats in 5 minutes.
Remote Management and Monitoring
Security protects you when you’re connected, and the connection offers the best user experience for the lowest cost.
SPECIFICATIONS
Performance
Enterprise Test Conditions
| Threat Prevention(1Gbps) | 7.4 |
|---|---|
| NGFW(2Gbps) | 17 |
| IPS(Gbps) | 19 |
| Firewall(Gbps) | 37 |
RFC 3511, 2544, 2647, 1242 Performance (Lab)
| Firewall 1518B UDP (Gbps) | 63 |
|---|---|
| VPN AES-128(Gbps) | 9.81 |
| Connections/sec | 230,000 |
| Concurrent connections $ ^{3}$ | 4/8/16M |
1: Includes Firewall, Application Control, URL Filtering, IPS, Antivirus, Anti-Bot and SandBlast Zero-Day Protection with logging enabled. 2: Includes Firewall, Application Control and IPS with logging enabled. 3: Performance measured with default/Plus/maximum memory.
Additional Features
Highlights
• 1x CPUs, 8 physical cores, 16 virtual cores
• 1x 480GB SSD storage (2x in Plus)
• 1 AC or DC power supply (2x in Plus)
• Lights-Out-Management (included in Plus)
• Virtual Systems ( Base/ Plus /max mem): 10/ 20/ 20
Network Expansion Slot Options (2 of 2 slots open)
• 8x 10/100/1000Base-T RJ45 port card, up to 26 ports
• 4x 1000Base-F SFP port card, up to 8 ports
• 4x 10GBase-F SFP+ port card, up to 8 ports
• CPU-level, OS-level and static file analysis
• File disarm and reconstruction via Threat Extraction
• Use 10,000+ pre-defined or customize your own applications
• Accept, prevent, schedule, and apply traffic-shaping
First Time Prevention Capabilities
Data Loss Prevention
• 2x 100/40/25G QSFP28 port double-slot-width card
Content Security (continued)
• End user and data owner incident handling
Dynamic User-based Policy
• Integrates with Microsoft AD, LDAP, RADIUS, Cisco pxGrid, Terminal Servers and with 3rd parties via a Web API • Enforce consistent policy for local and remote users on Windows, macOS, Linux, Android and Apple iOS platforms
Network Connectivity
• Integrated SD-WAN network optimization and resilience
• Total physical and virtual (VLAN) interfaces per appliance: 1024/4096 (single gateway/with virtual systems)
• 802.3ad passive and active link aggregation
• Layer 2 (transparent) and Layer 3 (routing) mode
High Availability
• Active/Active L2, Active/Passive L2 and L3
• ClusterXL or VRRP
IPv6
Unicast and Multicast Routing (see SK98226)
• NAT66, NAT64, NAT46
• OSPFv2 and v3, BGP, RIP
• Static routes, Multicast routes
• Policy-based routing
• PIM- SM, PIM- SSM, PIM- DM, IGMP v2, and v3
Power Requirements
• Single Power Supply rating: 300W
Environmental Conditions
• Operating: 0° to 40°C, humidity 95%
• Power consumption avg/max: 139W/195W
• Maximum thermal output: 665.4 BTU/hr.
• Storage: -20 to 70°C, humidity 95%
• Maximum thermal output: 665.4 BTU/hr.
• Environmental: RoHS, WEEE, REACH, ISO14001
ORDERING QUANTUM 6900 SECURITY GATEWAY S
BASE CONFIGURATION
| BASE CONFIGURATION $ ^{1}$ | SKU |
|---|---|
| 6900 Security Gateway Base configuration, includes 10x 1GbE copper ports, 16 GB RAM, 1 SSD, 1 AC PSU, telescopic rails, SandBlast (SNBT) Security Subscription Package for 1 Year | CPAP-SG6900-SNBT |
| 6900 Security Gateway Plus configuration, includes 10x 1GbE copper ports, 4x 10GbE SFP+ ports, 4x SR transceivers, 32GB RAM, 2x SSD, 2x AC PSU, Lights-out Management, telescopic rails, SandBlast (SNBT) Security Subscription Package for 1 Year | CPAP-SG6900-PLUS-SNBT |
| Quantum IoT Network Protection for 1 year for 6900 appliances | CPSB-IOTP-6900-1Y |
| Quantum IoT Network Protection for 1 year for 6900 PLUS appliances | CPSB-IOTP-6900-PLUS-1Y |
| Quantum SD-WAN subscription for 1 year for 6900 appliances | CPSB-SDWAN-6900-1Y |
| Quantum SD-WAN subscription for 1 year for 6900 PLUS appliances | CPSB-SDWAN-6900-PLUS-1Y |
The Base and Plus packages include 2 virtual systems (VS) - one management VS and one production/data VS. These are not additive or counted when adding additional VS licenses. 1. Renewal NGFW, NGTP and SandBlast (SNBT) packages are available in the online product catalog.
Accessories
INTERFACE CARDS AND TRANSCEIVERS
| INTERFACE CARDS AND TRANSCEIVERS | |
|---|---|
| 8 Port 10/100/1000 Base-T RJ45 interface card | CPAC-8-1C-C |
| 4 Port 1000Base-F SFP interface card; requires additional 1000Base SFP transceivers | CPAC-4-1F-C |
| SFP transceiver module for 1G fiber ports - long range [1000Base-LX] | CPAC-TR-1LX-C |
| SFP transceiver module for 1G fiber ports - short range [1000Base-SX] | CPAC-TR-1SX-C |
| SFP transceiver to 1000 Base-T RJ45(Copper) | CPAC-TR-1T-C |
| 4 Port 10GBase-F SFP+ interface card | CPAC-4-10F-C |
| SFP+ transceiver module for 10G fiber ports - for links up to 40km [10GBASE-ER] | CPAC-TR-10ER-C |
| SFP+ transceiver module for 10G fiber ports - long range up to 10km [10GBASE-LR] | CPAC-TR-10LR-C |
| SFP+ transceiver module for 10G fiber ports - short range [10GBASE-SR] | CPAC-TR-10SR-C |
| SFP+ transceiver 100BASE-T RJ45(Copper) - for links up to 30m over CAT6a/CAT7 | CPAC-TR-10T-C |
| 10G SFP+ Direct Attach Copper(DAC) cable, 3 meters | CPAC-DAC-10G-3M |
| 2 Port 10/25/40/100G QSFP28 Dual Width interface card | CPAC-2-40/100F-C |
| QSFP28 transceiver module for 100G fiber ports - short range [100GBase-SR4] | CPAC-TR-100SR |
| QSFP28 transceiver module for 100G fiber ports - long range [100GBase-LR4] | CPAC-TR-100LR |
| 100G SWDM4, LC connector, 75m/5M3 fiber | CPAC-TR-100WDM4 |
| 100G CWDM4, LC connector, 2Km/single mode fiber | CPAC-TR-100CWDM4 |
| QSFP+ transceiver module for 40G fiber ports - short range [40GBase-SR] | CPAC-TR-405R-QSFP-300m |
| QSFP+ transceiver module for 40G fiber ports - long range [40GBase-LR] | CPAC-TR-40LR-QSFP-10Km |
| Bi-directional QSFP transceiver for 40G fiber ports - short range [40GBase-SR-BD] | CPAC-TR-405R-QSFP-BIDI |
| QSFP28 to SFP28 Adapter-10G/25G fiber adaptor | CPAC-TR-QSFP28-SFP28 |
| SFP28 transceiver module for 25G fiber ports with QSFP28 adaptor - short range [25GBase-SR] | CPAC-TR-255R-ADP |
| SFP28 transceiver module for 25G fiber ports with QSFP28 adaptor - long range [25GBase-LR] | CPAC-TR-25LR-ADP |
| SFP+ transceiver module for 10G fiber with QSFP28 adaptor - for links up to 40km [10GBASE-ER] | CPAC-TR-10ER-ADP |
| SFP+ transceiver module for 10G fiber with QSFP28 adaptor - long range up to 10km [10GBASE-LR] | CPAC-TR-10LR-ADP |
| SFP+ transceiver module for 100 fiber with QSFP28 adaptor - short range [10GBase-SR] | CPAC-TR-10SR-ADP |
| SFP+ transceiver 10GBASE-T RJ45(Copper)与QSFP28 adaptor - for links up to 30m over CAT6a/CAT7 | CPAC-TR-10T-ADP |
| 100G Direct Attach Copper cable(QSFP28), 3 meters | CPAC-DAC-100G-3M |
| 40G Direct Attach Copper cable(QSFP28), 3 meters | CPAC-DAC-40G-3M |
| 25G Direct Attach Copper cable(QSFP28), 3 meters | CPAC-DAC-25G-3M |
| 10G Direct Attach Copper cable,(10BASE-CU) 3 meters | CPAC-DAC-10G-3M |
ORDERING QUANTUM 00 69 ( Continued)
BYPASS (FAIL-OPEN) NETWORK INTERFACE CARDS
| BYPASS(FAIL-OPEN) NETWORK INTERFACE CARDS | SKU |
|---|---|
| 4 Port 1GE copper Bypass (Fail-Open) Network interface card (10/100/1000Base-T) | CPAC-4-1C-BP-C |
| 2 Port 10GE Short-range Fiber Bypass (Fail-Open) Network interface card (10GBase-SR) | CPAC-2-10FSR-BP-C |
MEMORY
| MEMORY | SKU |
|---|---|
| Memory upgrade kit from 16GB to 32GB for 6900 appliances | CPAC-RAM16GB-6900 |
| Memory upgrade kit from 16GB to 64GB for 6900 appliances | CPAC-RAM48GB-6900 |
| Memory upgrade kit from 32GB to 64GB for 6900 appliances | CPAC-RAM32GB-6900 |
SPARES AND MISCELLANEOUS
| SPARES AND MISCELLANEOUS | SKU |
|---|---|
| Additional/Replacement AC Power Supply for 6900 appliances | CPAC-PSU-6600/6900 |
| Additional/Replacement DC Power Supply for 6600, 6700, 6900 appliances | CPAC-PSU-DC-6600/6700/6900 |
| 480GB SSD for 6900 Security Gateways | CPAC-SSD-480G-6900 |
| Lights Out Management module | CPAC-NLOM-C |
| Slide rails for 6000 and 7000 Security Appliances (22'-32') | CPAC-RAILS-6000/7000 |
| Telescopic slide rails for 6000 and 7000 Security Appliances (24'-36') | CPAC-RAILS-EXT-60007000 |
All-inclusive Security
| NGFW | NGTP | SNBT(SandBlast) | |
|---|---|---|---|
| Basic access control plus IPS | Prevent known threats | Prevent known and zero-day attacks | |
| Firewall | √ | √ | √ |
| VPN (IPsec) | √ | √ | √ |
| Mobile Access | √ | √ | √ |
| Identity Awareness | √ | √ | √ |
| Application Control | √ | √ | √ |
| Content Awareness | √ | √ | √ |
| IPS | √ | √ | √ |
| URL Filtering | √ | √ | |
| Anti-Bot | √ | √ | |
| Anti-Virus | √ | √ | |
| Anti-Spam | √ | √ | |
| DNS Security | √ | √ | |
| SandBlast Threat Emulation | √ | ||
| SandBlast Threat Extraction | √ | ||
| Zero Phishing | √ | ||
| IoT Network Protection | optional | optional | optional |
| SD-WAN Network Optimization | optional | optional | optional |
The first-year purchase includes the SNBT package. Security subscription renewals, NGFW, NGTP and SNBT are available for subsequent years. Optional security capabilities can be ordered a-la-carte or separately.