quantum spark 1900 2000 datasheet.pdf
QUANTUM SPARK 1900, 2000 FIREWALLS
QUANTUM SPARK 1900, 2000 SECURITY GATEWAYS
!
Hyperscale Network Security ! !
Top Security Effectiveness
! !
Forrester Wave™ for Zero Trust Platform Providers, Q3 2023
Gartner® Firewall Magic Quadrant™ (2022) ! !
Industry’s best security used by the world’s largest enterprises, tailored to protect your SMB from cyberattacks. ! !
Quantum Spark 1900 and 2000 NGFWs are fast, high port density firewalls with integrated AI ML security to prevent new and novel threats. Integrated capabilities like SD-WAN and IoT security provide faster Internet connectivity, application performance, proven security, and maximum uptime with management made easy via an intuitive web interface. ! !
SPARK 1900, 2000 HIGHLIGHTS
Next Gen Firewall Threat Prevention
| Next Gen Firewall | Threat Prevention | Interfaces |
|---|---|---|
| up to 10 Gbps | up to 5 Gbps | 24 ports |
AI-Powered advanced security, uncompromising performance. The Check Point Quantum Spark 1900 and 2000 security gateways deliver enterprise-grade security in simple, affordable, all-in-one security solutions in a 1 Rack Unit (RU) form factor to protect small to mid-size business employees, networks, and data from cyber-theft. High threat prevention throughput and high port capacity with 18x1GbE, 2x2.5GbE and 4x10GbE network interfaces make these gateways ideal for larger branch and SMB networks.
Comprehensive, Industry-Leading Security
- Next Generation Firewall
- Site-to-Site, Remote Access VPN
- Application Control and Web Filtering
- Intrusion Prevention
- Antivirus and Anti-Bot
- Anti-Spam Email Security
- SandBlast Threat Emulation (sandboxing)
- Integrated SD-WAN network optimization
High Port Capacity for Large SMB Networks
The 1900 and 2000 have a 18 1GbE copper LAN switch, ideal for segmenting multiple networks by department or function. Two copper 2.5GbE ports and four fiber 10GbE SFP+ LAN ports are also available. In addition, the 1GbE copper or fiber WAN and DMZ ports offer connection flexibility. The DMZ can also be used as a second WAN port.
Part of the Quantum Cyber Security Family
R81 software for SMB increases performance and brings enterprise-grade security to small and midsized businesses. Centrally managed SMB gateways support:
- Unified access policy: firewall, application control, URLF
- Policy layers and sub-policies
- Acceleration of domain, dynamic and time objects
- Multicore VPN and VPN acceleration
- Smart Accel 30% performance improvement of low risk, high bandwidth apps
SPECIFICATIONS
| 1900 | 2000 | |
|---|---|---|
| Enterprise Testing Conditions | ||
| Threat Prevention1 | 4 Gbps | 5 Gbps |
| Next Generation Firewall2 | 8 Gbps | 10 Gbps |
| IPS Throughput | 9 Gbps | 11 Gbps |
| Firewall Throughput | 16 Gbps | 20 Gbps |
| RFC 3511, 2544, 2647, 1242 Performance (LAB) | ||
| Firewall 1518 Byte UDP Packets | 32 Gbps | 40 Gbps |
| VPN AES-128 Throughput | 5 Gbps | 6 Gbps |
| Connections per Second | 90,000 | 100,000 |
| Concurrent Connections | 4,200,000 | 4,200,000 |
| Software | ||
| Security | Firewall, VPN, User Aware, QoS, Application Control, URLF, IPS, Anti-Bot, Antivirus, Anti-Spam, sandboxing | |
| Unicast, Multicast Routing and Clustering | OSPFv2, BGPv4 and 4++, RIP, PIM [SM, DM, SSMI], IGMP, ClusterXL High Availability | |
| IPv6 | local network and internet connections, dual stack tunneling IPv4 over IPv6 networks, prefix delegation | |
| Mobile Access License (Users) | 1000 remote SNX or Mobile VPN client users | |
| Hardware | ||
| WAN Port | 1x 1GBE RJ-45 port / 1GBE SFP+ ports (shared) | |
| DMZ Port | 1x 1GBE RJ-45 port / 1GBE SFP+ ports (shared) | |
| LAN 1 GbE and 2.5 GbE copper Ports | 2x 2.5GbE Base-T RJ-45 plus 16x 1 GbE RJ-45 ports | |
| LAN 10 GbE fiber Ports | 4x100GbE SFP+ ports | |
| Console Port | 1x USB-C or RJ45 | |
| USB Ports | 2x USB 3.0 | |
| Memory | 16 GB DDR | |
| Storage | 512 GB SSD and Micro-5D slot with 32 and 64 GB card options | |
| Dimensions | ||
| Enclosure | 1RU | |
| Dimensions(W x D x H) | 432 x 300 x 44 mm(16.93 x 11.8 x 1.74 in.) | |
| Weight | 6.76 kg(14.9 lbs.) | |
| Environment | ||
| Operating/Storage | 0°C - 40°C / -45°C - 60°C(5-95%, non-condensing) | |
| Power Requirements | ||
| AC Input | 100 - 240VAC, 50 - 60 Hz | |
| Power Supply Rating | two redundant 150W power supplies | |
| Power Consumption(Max) | 93.6W | |
| Heat Dissipation | 319.3 BTU/hr. | |
| Certifications | ||
| Safety Emissions Environment | UL/c-UL 62368-1 ,IEC 62368-1 CB / EMC,EMI EN55024,EN55032 Class B,VCCI,AS,NZ5 CISPR 32,IC ICES 03,FCC:Part 15 Class B/RohS,REACH,WEEE |
- Includes Firewall, Application Control, URL Filtering, IPS, Antivirus, Anti-Bot, SandBlast Zero-Day Protection with logging.
- Includes Firewall, Application Control, IPS with logging.
ORDERING QUANTUM SPARK 1900, 2000
1900, 2000 Firewall
- SD card slot
- 2x 2.5GbE LAN ports
- 16x 1GbE LAN switch
- 1x 1GbE copper/fiber DMZ port
- 4x 10GbE/1GbE SFP+ LAN ports
- Console port (USB-C or RJ45)
- 1x 1GbE copper/fiber WAN port
- USB ports
- 2x power supplies
- Fans
SECURITY APPLIANCES 1
- 1900 Security Appliance, includes SandBlast (SNBT) Security Subscription Package for 1 Year
- 2000 Security Appliance, includes SandBlast (SNBT) Security Subscription Package for 1 Year
CPAP-SG1900-SNBT
CPAP-SG2000-SNBT
ACCESSORIES
| ACCESSORIES | |
|---|---|
| SFP+ Short range transceiver | CPAC-1800-TR-10SR |
| SFP+ Long range transceiver | CPAC-1800-TR-10LR |
| SD memory card 32GB | CPAC-1500-32GB-SD |
| SD memory card 64GB | CPAC-1500-64GB-SD |
IOT, SD-WAN AND MOBILE SOFTWARE BLADES 1
| Mobile Access Blade for 50 concurrent connections | CPSB-MOB-50 |
|---|---|
| Quantum IoT Protect for 1 year for 15x5 Firewall(1535,1555,1575,1595) | CPSB-IOTP-15x5-1Y |
| Quantum SD-WAN for 1 year for 15x5 Firewall(1535,1555,1575,1595) | CPSB-SDWAN-15x5-1Y |
1Concurrent remote SNX or Mobile VPN client users. The MOB license is additive. The full Mobile Access web portal functionality is not supported.
SUBSCRIPTION SERVICES
See the table below for security capabilities included in the NGFW, NGTP and SNBT services packages. IoT and SD-WAN are ordered a la carte.
| SERVICE | SERVICES HIGHLIGHTS |
|---|---|
| Next-Gen Firewall (NGFW): segment networks and apply zero trust policy with IPS | Accept, prevent, schedule, and apply traffic-shaping based controls to application traffic. Protect vulnerable systems with 12,000+ IPS protections |
| Next-Gen Threat Prevention (NGTP): AI Deep Learning DNS security with antivirus and anti-bot prevents threats | DNS security prevents Command & Control(C2) connections and blocks data theft through DNS tunneling. Apply web and application control using 100+ categories or customize your own |
| SandBlast(SNBT): comprehensive, multi-layered defense with sandboxing protection from unknown and zero-day threats | Average emulation time for unknown files that require full sandbox evaluation is under 100 seconds. Maximal file size for Emulation is 15MB |
| IoT Network Protection: simple,effective,autonomous discovery and protection of IoT devices in minutes | Automatically creates and applies an inline zero-trust IoT policy layer |
| SD-WAN: reliable and optimum network connectivity at the lowest cost | SLA monitoring and autonomous link swapping |
Services Bundles
Optional security capabilities can be ordered a-la-carte or separately.