QUANTUM FORCE 3950 SECURITY GATEWAY Check Point ACCESSORIES GUIDE
Quantum Force 3950
Security Gateway
Top Security Effectiveness
YOU DESERVE THE BEST SECURITY
Check Point has been ranked #1 for the third consecutive year, achieving a 99.9% malware block rate, 99.7% phishing prevention and 98% high and critical exploit prevention in the Miercom Hybrid Mesh Firewall Benchmark 2025.
GigaOm Radar for Enterprise Firewalls 2025
Named a Leader by Top Analyst Firms Forrester Wave $ ^{\mathrm {T M}} $ for Enterprise Firewalls 2024.
Quantum Force 3950 Performance Highlights
| Firewall | Next Gen Firewall | Threat Prevention |
|---|---|---|
| 20 Gbps | 16.2 Gbps | 5.5 Gbps |
Productivity Loss and Cyber Risks in Branch Offices
Today's branch offices are on the frontline, directly interacting with customers and the public. They directly connect the public cloud and internet which expose them to cyber threats. This often makes branch offices a weak link in enterprise network security.
As employees return to the office, they experience downgraded network performance compared to their high-speed home internet. Suddenly, the same bandwidth-hungry SaaS and enterprise apps become frustrating to use at the office due to lag, choppiness, and freeze ups.
Miercom Enterprise & Hybrid Mesh Firewall Benchmark 2025
Industry-Leading Security
- Next Generation Firewall
- Application and Web Filtering
- Sandboxing
- Intrusion Prevention
- Zero-phishing (no agent required)
- SD-WAN
- Antivirus and Anti-Bot
- HTTPS Inspection (Layer 1-7)
- Advanced DNS Security
Frontline Defense for the Branch
Secure, Blazing Fast SaaS Apps
The 3950 delivers 4x higher threat prevention throughput compared to previous models. This ensures secure, blazing fast network performance for SaaS productivity apps like Zoom, Teams, Salesforce, etc.
High Performance HTTPS Inspection
While commonly used for good, HTTPS web traffic can also hide illegal user activity and malicious traffic. Enterprises need the ability to inspect a broad range of encrypted TLS 1.3 and HTTPS channels while also excluding inspection of sensitive regulated industry traffic, such as Health Care and Financial. Check Point makes it easy to fine-tune HTTPS security using customizable dynamic security policies.
Quantum Force 3950 Specifications
| Performance | |
|---|---|
| Enterprise Test Conditions1 | |
| Threat Prevention2 [Gbps] | 5.5 |
| Next Generation Firewall3 [Gbps] | 16.2 |
| IPS Throughput [Gbps] | 20 |
| Firewall Throughput [Gbps] | 20 |
| RFC 3511,2544,2647,1242 Performance (Lab) | |
| Firewall 1518 bytes UDP [Gbps] | 20 |
| Firewall Latency (μSec) | 13 |
| VPN AES-GCM 1452B [Gbps] | 17.5 |
| Connections/Sec | 130,000 |
| Concurrent Connections (M) | 7.2 |
| TLS Inspection Performance | |
| Threat Prevention1,2 [Gbps] | 1.75 |
| Threat Prevention2 web mix4 [Gbps] | 1.1 |
| IPS web mix4 [Gbps] | 1.4 |
Additional Features:
- 1 CPU, 8 Physical Cores
- 32 GB RAM
- 480 GB SSD NVME M.2
- 2x External AC-DC power adapters
- Desktop (Rack Mount installation - optional)
Network Connectivity
- Optimized for SD-WAN, network efficiency and resilience
- Total physical and virtual (VLAN) interfaces per appliance: 1024/4096 (single gateway/with virtual systems)
- 802.3ad passive and active link aggregation
- Layer 2 (transparent) and Layer 3 (routing) mode
- Active/Active L2, Active/Passive L2 and L3 High Availability
Power Requirements
- Session failover for routing change, device and link failure
- Power consumption avg/max: 46W/54W
- Dual External AC-DC Adaptors
- Power input: 100 to 240VAC (50-60Hz)
- Maximum thermal output avg/max: 160.73 BTU/hr /191.07 BTU/hr
Dimensions
- Dimensions (WxDxH): 8.27 x 8.26 x 1.67 in. (210 x 209.9 x 42.5mm)
- Weight: 2.17 lbs / 0.988 kg
- Box Dimensions: 10.43 in (L) x 9.45 in (W) x 4.33 in (H) (26.5 cm (L) x 24 cm (W) x 11 cm (H))
Environmental Conditions
- Operating: 32°F - 104°F (0ºC - 40ºC), humidity 5% to 95%
- Storage: -4°F - 158°F (-20° - 70°C), humidity 5% to 95%
- MTBF: 234086 hrs @ 25°C / 138550 hrs @ 40°C
- Noise Level: 34.3dB
Ordering Quantum Force 3950 Security Gateway
The 3950 includes 2x2.5GbE copper, 2x10GbE copper (1 Port is shared for management) and an additional 8x 1GbE ports to meet your networking requirements.
| Security Appliance | SKU |
|---|---|
| 3950 configuration: 2x10GbE RJ45(1 Port is shared for management) ports, 8x1GbE RJ45 ports, 2x2.5GbE RJ45 ports, 32GB RAM, 1x480 GB SSD SATA, 1x AC external PSUs, SandBlast(SNBT) Security Subscription Package for 1 Year | CPAP-SG3950-SNBT |
| Next Generation Threat Prevention & SandBlast package for 1 year for Quantum Force 3950 appliance | CPSB-SNBT-3950-1Y |
| Next Generation Threat Prevention package for 1 year for Quantum Force 3950 appliance | CPSB-NGTP-3950-1Y |
| Next Generation Firewall Package for 1 year for Quantum Force 3950 appliance | CPSB-NGFW-3950-1Y |
| Quantum IoT Network Protection for 1 year for Quantum Force 3950 appliances | CPSB-IOTP-3950-1Y |
| Quantum SD-WAN subscription for 1 year for Quantum Force 3950 appliances | CPSB-SDWAN-3950-1Y |
| Data Loss Prevention (DLP) blade for 1 year for Quantum Force 3950 appliances | CPSB-DLP-3950-1Y |
| SUBSCRIPTION SERVICES | NGFW | NGTP | SNBT(Sandblast) |
|---|---|---|---|
| Application Control | √ | √ | √ |
| IPS | √ | √ | √ |
| URL Filtering | √ | √ | |
| Anti-Bot | √ | √ | |
| Anti-Virus | √ | √ | |
| Anti-Spam | √ | √ | |
| DNS Security | √ | √ | |
| SandBlast Threat Emulation (sandboxing) | √ | ||
| SandBlast Threat Extraction (CDR) | √ | ||
| Zero Phishing | √ | ||
| DLP | Optional | Optional | Optional |
| IoT | Optional | Optional | Optional |
| SD-WAN | Optional | Optional | Optional |