Check Point DDoS Protector Datasheet

DDoS Protector

DDoS Protection and Attack Mitigation

! !

Maintain Business Continuity

Even When Under Attack

Features

Benefits

DDoS Attacks Are On The Rise

In today’s info-security threat landscape, denial-of-service and distributed denial-of-service (DoS/DDoS) attacks are a major cause of network downtime. Whether executed by hacktivists to draw attention to a cause, fraudsters trying to illegally obtain data or funds, or a result of geopolitical events, DDoS attacks are a destructive cyber weapon. Governments, utilities, financial services, and commercial institutions face daily attacks.

Preparing for “common” DDoS attacks is no longer enough. Thanks to the growing array of online marketplaces, it is now possible for hackers to wreak havoc with virtually no knowledge of computer programming or networks. Attack tools and services are easy to access, making the pool of possible assaults larger than ever.

With Burst attacks and Advanced Persistent DDoS campaigns, hackers launch multivector, blended campaigns with high-volume network vectors with more sophisticated application-layer attacks. In addition, recent IoT threats spawned the largest DDoS attack in history, propelling the industry into the 1Tbps DDoS era.

With these new threats, it is critical to ensure your DDoS mitigation solution can protect your organization and customers from today and tomorrow’s sophisticated attacks.

Integrated On-Prem and Cloud DDoS Protection

DDoS Protector is part of Check Point’s Attack Mitigation Solution and is an award-winning, real-time, perimeter attack mitigation device that secures organizations against emerging network and application threats. DDoS Protector protects the infrastructure against network and application downtime (or slow time), application vulnerability exploitation, malware spread, network anomalies, information theft, and other types of attacks.

With DDoS Protector, Check Point’s attack mitigation solution offers protection with the shortest mitigation time and broadest attack coverage. Check Point provides a hybrid solution combining on-premise and cloud-based mitigation tools in a single integrated solution, designed to optimally block multiple attack vectors occurring in parallel.

!

Why DDoS Protector?

DDoS Protector includes a comprehensive set of four essential security modules – anti-DDoS, network behavioral analysis (NBA), intrusion prevention system (IPS), and SSL-attack protection - to fully protect the application infrastructure against known and emerging network security attacks. It employs multiple detection and mitigation modules, including adaptive behavioral analysis, challenge response technologies, and signature detection.

Compared to standalone solutions, the synergy of multiple security modules on a single, hardware-accelerated platform enables effective protection against attackers who seek to systematically compromise business assets while providing unified reporting, forensics, and compliance.

DDoS Protector consists of adaptive, behavioral-based real-time signature technology that detects and mitigates emerging network attacks, zero-day, DoS/DDoS, application misuse attacks, network scanning, and malware spread. It eliminates the need for human intervention and does not block legitimate user traffic.

! ! ! ! ! ! ! ! !

DP6 DP20 DP60 DP110 DP200 DP220 DP400 DP-800
Bandwidth(Gbps) 0.2 to 5 2 to 12 10 to 40 40 80 120 160 to 200 380
Mitigation(Gbps) 6 20 60 110 200 220 400 800
PPS(M) 7.2 27.5 27.5 50 292 142 292 1,119
Enclosure 1U 2U 2U 2U 2U 2U 2U 2U
SSL Option √ √ √ √ × √ × ×

!

The DDoS Protector appliances offer versatile connectivity and mitigation capacities, adhering to enterprise and service provider deployments. Bandwidth mitigation capacities range from 6, all the way up to 400 Gbps. Protection can be further augmented with our Cloud DDoS Protector Services.

!

Deployment Modes

DDoS Protector can be deployed inline, out-of-path (OoP), or in a scrubbing center to provide the highest mitigation accuracy within the shortest time. Each deployment mode offers the same performance as an inline device.

With DDoS Protector deployed either inline or out-of-path as well as in a scrubbing center, the devices are able to communicate with each other in real-time to collect automatic updates of normal traffic baselines, detect behavioral patterns, and obtain attack footprints. This constant real-time flow of Defense Messaging enables DDoS Protector to provide accurate and instant mitigation without the need to learn this information when an attack occurs.

Deploying DDoS Protector devices out-of-path or in a scrubbing center is the most scalable and flexible solution as it is based on the maximum attack mitigation capacity needed, without being limited by the actual network physical topology.

Integrated, Hybrid Solution

In addition to the security modules integrated in DDoS Protector, Check Point’s Attack Mitigation Solution (AMS) includes an SSL decryption/encryption engine, a WebApp Protector module, and Hybrid Cloud DDoS Protector Service that works in sync with the on-premises solution. With no performance impact or risk, Check Point’s AMS ensures business continuity even when under attack.

The solution is enhanced with a central Security Information Event Management (SIEM) to provide unified situational awareness to our Emergency Response Team (ERT). Unique messaging assures that each component provides information about traffic baselines and real-time signatures to the others, so that all system components have full visibility into all information.

Cloud DDoS Protector Services

Check Point’s DDoS Protector Cloud Service can be delivered in On-demand, Always-on, or in a Hybrid configuration, and can be custom-tailored to suit any customer need, network topology, or threat profile.

Choosing the Right Solution
Hybrid On-demand Always-on
On premises inline or out-of-path devices backed by cloud-based scrubbing capacity. Real-time protection and minimal latency. Recommended security best practice. Best suited for data center protection. No added latency. Traffic diverted only upon attack detection. Allows lowest-cost, cloud-only simple deployment. Best suited for latency-sensitive applications and organizations that are infrequently attacked. Always-available, real-time, cloud-based DDoS protection. Provides immediate protection but with small added latency. Best suited for applications hosted on the cloud and for organizations that constantly come under attack.

!

Global Coverage, Massive Capacity

Check Point’s DDoS Protector Cloud Service is backed by a worldwide network of 16 global scrubbing centers, with 8 Tbps of mitigation capacity (and growing). Check Point’s scrubbing centers are globally connected in full mesh mode, using Anycast-based routing. This ensures that DDoS attacks are mitigated closest to their point of origin and provides truly global DDoS mitigation capable of absorbing even the largest volumetric attacks.

Check Point DDoS Protector Cloud Service Features

Our cloud-based service includes the same features you get in the on-premises solution. This includes behavioral-based detection using advanced, patented machine-learning algorithms to protect against known and unknown threats, zero-day protection against network and application layer DDoS attacks such as Burst attacks, DNS attacks, and others. Our unique protection against SSL-based attacks does not add latency or require customers to provide full SSL certificates. Our extensive compliance options and certification are unparalleled by any rival and include industry-specific certifications such as PCI and HIPAA, as well as cloud security standards such as ISO 27001, ISO 27017, ISO 27018, ISO 27032, and others.

Expert Support

The Emergency Response Team (ERT) is a group of security experts that provides 24x7 support and mitigation services for.

Absolute Vision is a unified management and monitoring system. It provides advanced element management capabilities through a unique plug-and-play device support mechanism, including initial device setup, ongoing maintenance, SSL certificate management, real-time reporting, capacity utilization measurement, forensics, task scheduling, and more. It provides automation of monitoring and maintenance processes across all the devices it manages and includes a central repository of vital device information for IT managers to easily find hardware platform details, upgrade and software version management, and installed licenses. As a result, continuous service delivery through the entire device’s operational life cycle is ensured. A REST API is available for SIEM integrations.

DDoS Protector Specifications

Enterprise Grade Ultra High End
Appliances 6 20 60 110 200,400-160 220 400-200,800-380
Programmable Mitigation Performance
Max Mitigation Capacity/Throughput(Gbps) 6 20 60 110 200/400 220 400
Max Attack Concurrent Sessions Unlimited
Max DDoS Flood Attack Prevention Rate(PPS) 7.2M 27.5M 27.5M 50M 292M 142M 1,119M
SSL/TLS CPS(RSA 2K) 20K 95K 95K 150K - 150K -
Latency <60 micro seconds
Blocking Performance
Max DDoS Blocking Throughput(Gbps) 240 240 800 760 800 3,400
Max DDoS Blocking(PPS) 357M 357M 1.19B 827B 1.19B 2.7B
Operation Mode
Network Operation Transparent L2 Forwarding/IP Forwarding
Deployment Modes In-line;SPAN Port Monitoring;Copy Port Monitoring;Out-of-path mitigation(scrubbing center solution)
Tunneling Protocol VLAN Tagging,L2TP,MPLS,GRE,GTP,IPinIP
IPv6 Yes
Jumbo Frame - Supported
Block Actions Drop packet,reset(source,destination,both),suspend(source IP address,source port,destination IP address,destination port or any combination),challenge-response for TCP,HTTP and DNS suspicious traffic
Inspection Ports
10/100/1000 Copper 6 - - - - - -
1/10 GbE SFP+ 2 24 24 20 20
10/25 GbE SFP28 24 24
40 GbE QSFP+ - - - 4 to 8 4 4 to 8 4
100 GbE QSFP28 - -- - 0 to 4 4 0 to 4 4
400 GbE
Management Ports
10/100/1000 Copper 2
RJ45 Console Port √
High Availability
FailOpen(F0)/FailClose(FC)² F0/FC;Copper portsFC;SFP+ports: FC;SFP+ports FC;SFP+,SFP28,QSFP+ports
Dual Hot Swap Power Supply √
  1. External fiber fail-open switch is available at additional cost.

DDoS Protector Specifications (continued)

Enterprise Grade Ultra High End
6 20 60 110 200,400-160 220 400-200,800-380
Physical
Enclosure 1U 2U 2U 2U 2U 2U 2U
Standard(WxDxH) 17.2x16x1.7in. 17.2x18.9x3.5in. 19x21.6x3.5in. 16.7x23.6x3.5in. 19x21.6x3.5in.
Metric(WxDxH) 436x406x44mm 436X480X88mm 482x550x87mm 424x600x88mm 482x550x87mm
Weight 6.5Kg(14lbs.) 13.2kg(29lbs.) 14.5kg(31.9lbs) 18.7kg(41.2lbs.) 14.5kg(31.9lbs.)
Power
Dual,Hot-Swappable PSUs Optional Included Included Included Included Included Included
Power Input AC100120V,AC200240V@47~63Hz,DC:-36--72V(400-200,800-380 models DC:-41--72V)
Power Consumption 140W 320W 550W 890W 550W 970W
Heat Dissipation 480BTU/h 1088BTU/h 1880BTU/h 2930BTU/h 1880BTU/h 3300BTU/h
Environment Conditions
Operating Environment 32°to104°F/0°to40°C,5~95% Humidity(non-condensing)
Certifications
Safety cTUVus,EN/IEC60950-1(CB),CCC,IEC60950-1,GB4943,CNS14336
Emissions UL/TUV,FCC(USA),IC(Canada),CE(Europe),UKCA(UK),RCM(Australia/NZ),VCCI(Japan),KCC(Korea),EAC(Russia),CCC(China),BSMI(Taiwan),Anatel(Brazil),NOM(Mexico)
Environment Compliant(EU directive 2011/65/EU, 2015/863/EU)

Ordering DDoS Protection

  1. SSL option available for the DDoS Protector 6, 20, 60, 110 and 220. GBICs must be purchased separately.
DDoS APPLIANCE1 SKU
DDoS Protector 6-5 Appliance providing 6Gbps attack mitigation and 5 Gbps legitimate throughput CPAP-DP6-5-SME
DDoS Protector 6-3 Appliance providing 6Gbps attack mitigation and 3 Gbps legitimate throughput CPAP-DP6-3-SME
DDoS Protector 6-2 Appliance providing 6Gbps attack mitigation and 2 Gbps legitimate throughput CPAP-DP6-2-SME
DDoS Protector 6-1 Appliance providing 6Gbps attack mitigation and 1 Gbps legitimate throughput CPAP-DP6-1-SME
DDoS Protector 6-05 Appliance providing 6Gbps attack mitigation and 500 Mbps legitimate throughput CPAP-DP6-05-SME
DDoS Protector 6-02 Appliance providing 6Gbps attack mitigation and 200 Mbps legitimate throughput CPAP-DP6-02-SME
DDoS Protector 20-12 Appliance providing 20Gbps attack mitigation and 12 Gbps legitimate throughput CPAP-DP20-12-SME
DDoS Protector 20-8 Appliance providing 20Gbps attack mitigation and 8 Gbps legitimate throughput CPAP-DP20-8-SME
DDoS Protector 20-4 Appliance providing 20Gbps attack mitigation and 4 Gbps legitimate throughput CPAP-DP20-4-SME
DDoS Protector 20-2 Appliance providing 20Gbps attack mitigation and 2 Gbps legitimate throughput CPAP-DP20-2-SME
DDoS Protector 60-40 Appliance providing 60Gbps attack mitigation and 40 Gbps legitimate throughput CPAP-DP60-40-SME
DDoS Protector 60-20 Appliance providing 60Gbps attack mitigation and 20 Gbps legitimate throughput CPAP-DP60-20-SME
DDoS Protector 60-10 Appliance providing 60Gbps attack mitigation and 10 Gbps legitimate throughput CPAP-DP60-10-SME
DDoS Protector 110-40S Appliance providing 110Gbps attack mitigation and 40Gbps legit throughput CPAP-DP110-40S-SME
DDoS Protector 200-80 Appliance providing 200Gbps attack mitigation and 80 Gbps legitimate throughput CPAP-DP200-80-SME
DDoS Protector 220-120S Appliance providing 220Gbps attack mitigation and 120Gbps legit throughput CPAP-DP220-120S-SME
DDoS Protector 400-160 Appliance providing 400Gbps attack mitigation and 160 Gbps legit throughput CPAP-DP400-160-SME

Hybrid Cloud, DDoS Services

HYBRID CLOUD DDoS SERVICE¹ SKU
Hybrid Cloud DDoS Protection Service Up to Legitimate 12,8,4,2,10.5,0.2,or0.1Gbps for 1 year CPSB-DPL-xxGB-1Y
UPDATE SERVICE¹
DDoS Behavioral Protection and IPS Updates for DDoS Protector 6-3, 6-2, 6-1, 6-05, 6-02 CPSB-DP6-xx-SUS-1Y
DDoS Behavioral Protection and IPS Updates for DDoS Protector 20-12, 20-8, 20-4 CPSB-DP20-xx-SUS-1Y
DDoS Behavioral Protection and IPS Updates for DDoS Protector 60-40 CPSB-DP60-xx-SUS-1Y
DDoS Behavioral Protection and IPS Updates for DDoS Protector 110-40S(SSL) CPSB-DP110-40S-SUS-1Y
DDoS Behavioral Protection and IPS Updates for DDoS Protector 200-80 CPSB-DP200-80-SUS-1Y
DDoS Behavioral Protection and IPS Updates for DDoS Protector 220-120S(SSL) CPSB-DP220-120S-SUS-1Y
DDoS Behavioral Protection and IPS Updates for DDoS Protector 400-160 CPSB-DP400-160-SUS-1Y
ACTIVE ATTACKERS FEED SERVICE¹
Active Attackers Feed Subscription for DDoS Protector 6-5, 6-3, 6-2, 6-1, 6-05, 6-02 CPSB-DP6-xx-AAF-1Y
Active Attackers Feed Subscription for DDoS Protector 20-12, 20-8, 20-4, 20-2 CPSB-DP20-xx-AAF-1Y
Active Attackers Feed Subscription for DDoS Protector 60-40, 60-20, 60-10 CPSB-DP60-xx-AAF-1Y
Active Attackers Feed Subscription for DDoS Protector 110-40S(SSL) CPSB-DP110-40S-AAF-1Y
Active Attackers Feed Subscription for DDoS Protector 200-80 CPSB-DP200-80-AAF-1Y
Active Attackers Feed Subscription for DDoS Protector 220-120S(SSL) CPSB-DP220-120S-AAF-1Y
Active Attackers Feed Subscription for DDoS Protector 400-160 CPSB-DP400-160-AAF-1Y

Emergency Response Team DDoS Service1

ERT Gold Protection Package(ERT Under Attack,SUS & Active Attackers Feed) for DDoS Protector 6-5, 6-3, 6-2, 6-1, 6-05, 6-02 DDoS Behavioral Protection and IPS CPSB-ERT-G-DP6-xx-1Y
ERT Gold Protection Package(ERT Under Attack,SUS & Active Attackers Feed) for DDoS Protector 20-12, 20-8, 20-4, 20-2 DDoS Behavioral Protection and IPS CPSB-ERT-G-DP20-xx-SSL-1Y
ERT Gold Protection Package(ERT Under Attack,SUS & Active Attackers Feed) for DDoS Protector 60-40, 60-20, 60-10 DDoS Behavioral Protection and IPS CPSB-ERT-G-DP60-xx-SSL-1Y
ERT Gold Protection Package(ERT Under Attack,SUS & Active Attackers Feed) for DDoS Protector 110-40S(SSL) DDoS Behavioral Protection and IPS CPSB-DP110-40S-ERT-G-1Y
ERT Gold Protection Package(ERT Under Attack,SUS & Active Attackers Feed) for DDoS Protector 200-80 DDoS Behavioral Protection and IPS CPSB-ERT-G-DP200-80-1Y
ERT Gold Protection Package(ERT Under Attack,SUS & Active Attackers Feed) for DDoS Protector 220-120S(SSL) DDoS Behavioral Protection and IPS CPSB-ERT-G-DP220-120S-ERT-G-1Y
ERT Gold Protection Package(ERT Under Attack,SUS & Active Attackers Feed) for DDoS Protector 400-160 DDoS Behavioral Protection and IPS CPSB-ERT-G-DP400-160-1Y

On-demand, Always-on DDoS Protection

ON-DEMAND CLOUD DDoS SERVICE
On-Demand Cloud DDoS Protection Service for 1 year Up to Legitimate 12, 8, 4, 2, 1 Gbps or 500, 200, 100, 50, 20, 10 Mbps CP-CG-DP-OND-12GB-1Y
ALWAYS-ON CLOUD DDoS SERVICE
Always-On Cloud DDoS Protection Service for 1 year Up to Legitimate 12, 8, 4, 2, 1 Gbps or 500, 200, 100, 20, 10 Mbps CP-CG-DP-AON-12GB-1Y
1 Additional annual diversions and protected networks available in the online product catalog
  1. SSL option available DDoS Protector 6, 20, 60, 110, and 220

Ordering DDoS Protection (continued)

Vision Management

DDoS Vision Management Appliances

DDoS Vision Management Appliances SKU
DDoS Management VL2 Appliance for management of 2 DDoS Protector physical devices for 1 year CPAP-DP-VMA-VL2
DDoS Management VA2 Virtual Appliance for management of 2 DDoS Protector physical devices for 1 year CPSM-DP-VM-VA2-1Y
MANAGEMENT UPGRADE AND ADD-ONS
DDoS Management upgrade to manage unlimited DDoS Protector physical devices for 1 year CPSB-DPV-RTU-MAXV-Add-1Y
Vision Management Right to Use (RTU), 200 virtual instances - 1 Year CPSB-DPV-RTU-200V-Add-1Y
Vision Management Right to Use (RTU), 60 virtual instances - 1 Year CPSB-DPV-RTU-60V-Add-1Y
APSolute Vision Analytics (AMS), Total 6 Gbps attack capacity - 1 Year CPSB-AMS-6GBPS-1Y
APSolute Vision Analytics (AMS), Total 20 Gbps attack capacity - 1 Year CPSB-AMS-20GBPS-1Y
APSolute Vision Analytics (AMS), Total 60 Gbps attack capacity - 1 Year CPSB-AMS-60GBPS-1Y
APSolute Vision Analytics (AMS), Total 400 Gbps attack capacity - 1 Year CPSB-AMS-400GBPS-1Y
APSolute Vision Reporter(AVR), Total 6 Gbps attack capacity - 1 Year CPSB-AVR-6GBPS-1Y
APSolute Vision Reporter(AVR), Total 20 Gbps attack capacity - 1 Year CPSB-AVR-20GBPS-1Y
APSolute Vision Reporter(AVR), Total 60 Gbps attack capacity - 1 Year CPSB-AVR-60GBPS-1Y
APSolute Vision Reporter(AVR), Total 400 Gbps attack capacity - 1 Year CPSB-AVR-400GBPS-1Y