# Quantum Force 19200 Security Gateway

## Unified Management and Ops Efficiency
Increase protection and reduce TCO with a consolidated security architecture.

## Top Security Effectiveness
### YOU DESERVE THE BEST SECURITY
Named a Leader by Top Analyst Firms:
- Forrester Wave $^{\mathrm{TM}}$ for Zero Trust Platform Providers, Q3 2023
- Gartner $^{\mathrm{R}}$ Firewall Magic Quadrant $^{\mathrm{TM}}$ [2022]

### AI/ML powered Threat Prevention
On-demand expansion, load balancing firewall clustering, and resilient access to mission-critical applications.
Protect networks and users from zero-days phishing, DNS, and ransomware attacks.
Quantum 19200 firewalls deliver up to 800 Gbps of firewall and 44 Gbps of threat prevention throughput with integrated AI/ML security power efficiency and space savings in a modular 2 RU platform.

Increase the efficiency of your datacenter's security operations. Prevent even the most advanced attacks before they can infect their target. Manage your on-premises and cloud firewalls from a unified platform.

## Fastest AI-Powered Threat Prevention
### Network Resilience & Power Efficiency

### 19200 Performance Highlights

| Firewall       | Next Gen Firewall | Threat Prevention |
|----------------|-------------------|------------------|
| 245 Gbps       | 100 Gbps          | 44 Gbps          |

---

AI-Powered advanced security and uncompromising performance, built for data centers. Quantum Force 19200 data center firewalls deliver high threat prevention performance in a small 2 RU form factor to protect employees, networks, and data from cyber-theft. Four network I/O slots can be configured to fit your network with a high port density of up to 32x 1/10GbE, 18x 10/25 GbE or 8x 40/100GbE with acceleration.

## Comprehensive and Industry-Leading Security
- Next Generation Firewall
- Site-to-Site and Remote Access VPN
- Application and Web Filtering
- Intrusion Prevention
- Advanced DNS Security
- Antivirus and Anti-Bot
- Zero-phishing (no agent required)

### Highest Performance Threat Prevention
With the 19200, organizations can inspect encrypted traffic and prevent even the most evasive attacks without impacting internal network performance. Achieve 44 Gbps of threat prevention throughput or up to 800 Gbps of UDP 1518B firewall throughput with a single 2RU firewall.

### Miercom Enterprise & Hybrid Mesh Firewall Benchmark 2025
Check Point ranks #1 again in threat prevention with 99.9% block rate.

### Power Efficient, Resilient Design
With a low power consumption per Gbps of threat prevention throughput, these large enterprise firewalls cut power costs in half when compared with similar firewalls from other vendors. Dual, redundant hot-swap power supplies and dual 960 GB RAID-1 NVMe storage provides complete redundancy.

### Flexible, High Performance HTTPS Inspection
While commonly used for good, HTTPS traffic can also hide illegal user activity and malicious traffic. Enterprises need the ability to inspect a broad range of encrypted TLS 1.3 and HTTP/2 channels while also excluding inspection of sensitive industry traffic, such as Health Care and Financial that have special regulatory requirements. Check Point makes it easy to fine-tune HTTPS security using customizable dynamic security policies.

---

## Specifications

### Enterprise Test Conditions1

| Enterprise Test Conditions1 |  |
|-----------------------------|--|
| Threat Prevention25[Gbps]   | 44|
| NGFW3[Gbps]                 | 100|
| IPS[Gbps]                   | 145|
| Firewall[Gbps]              | 245|
| RFC 3511,2544,2647,1242 Performance(Lab) |  |
| Firewall 1518B UDP[Gbps]    | 800|
| Firewall Latency(avg)       | 1.85μSec |
| VPN AES-GCM 1452B[Gbps]    | 86 |
| Connections/sec              | 1,000,000 |
| Concurrent connections(Base/Plus/Max) | 21M/31M/31M |
| HTTP/TLS Inspection Performance |  |
| Threat Prevention1,2[Gbps]  | 18.6 |
| Threat Prevention2web mix4[Gbps] | 11.2 |
| IPS web mix4[Gbps]          | 15.7 |

1 Enterprise traffic profile measured with maximum memory  
2 Includes Firewall, App Control, URLF, IPS, Anti Malware (Bot, Virus & Spam), DNS Security, Zero-Phishing and SandBlast Threat Emulation & Extraction with logging enabled.

### Additional Features
Includes Firewall, App Control, URLF, IPS, Anti Malware (Bot, Virus & Spam), DNS Security, Zero-Phishing and SandBlast Threat Emulation & Extraction with logging enabled
3 Includes Firewall, App Control and IPS with logging enabled.
4 Web traffic mix is based on RFC 9411 (NetSecOpen) web traffic profile.

- CPU: 40 physical cores, total of 80 logical cores
- Storage: BASE x 1 SSD 960GB NVMe, PLUS x 2 SSD 960GB NVMe

### Network Expansion Slot Options
- 8 x 1/10GBASE-F SFP+ port card, up to 32 ports
- 4 x 10/25GBASE-F SFP28 port card, up to 18 ports
- 2 x 40/100GBASE-F QSFP28 port card, up to 8 ports

---

### Network Connectivity
- Integrated SD-WAN network optimization and resilience
- Total physical and virtual (VLAN) interfaces per appliance: 1024/4096
- 802.3ad passive and active link aggregation
- Layer 2 (transparent) and Layer 3 (routing) mode

### High Availability
- Active/Active L2, Active/Passive L2 and L3
- Session failover for routing change, device and link failure
- ClusterXL or VRRP

### Power Requirements
- Single Power Supply rating AC: 850W
- Power input: 100 to 240VAC (47-63Hz)
- Power consumption 110VAC avg/max: 378W/630W
- Maximum thermal output AC: 2149.6 BTU/hr.

### Environmental Conditions
- Operating: 0° to 40°C, humidity 5% to 95%
- Storage: –20° to 70°C, humidity 5% to 95% at 60°C
- MTBF: > 10 years

### Certifications
- Safety: CB IEC 62368-1, CE LVD EN62368-1, UL62368-1, ASNZS 62368.1
- Emissions: CE, FCC IC, VCCI, ASNZS ACMA
- Environmental: ROHS, REACH, WEEE, ISO14001

### Maximum Virtual System Capacity

|                              | 1/10 GbE Copper | 1/10 GbE Fiber | 10/25 GbE Fiber | 40/100* GbE Fiber | Memory | Redundant Power | Redundant Storage | LOM |
|------------------------------|-----------------|-----------------|------------------|------------------|--------|-----------------|------------------|-----|
| Base model                   | 2               | 8               | 2                | 0                | 96 GB  | ●               | ○                | ○   |
| Plus model                   | 2               | 8               | 6                | 0                | 128 GB | ●               | ●                | ●   |
| Max capacity                 | 2               | 32              | 18               | 8                | 128 GB | ●               | ●                | ●   |
| Maestro/MHS                  | 2               | 0               | 0                | 4                | 128 GB | ●               | ●                | ●   |

The 19200 includes 2x 1/10 copper GbE management ports plus an additional 2x 1/10/25 SFP28 ports for synchronization when using the 19200 in a cluster. With the four network I/O slots, modify the base or plus configuration to meet your networking requirements. The 40/100G ports enable firewall traffic acceleration at line-rate.

---

## ACCESSORIES

### SECURITY APPLIANCE¹

| SECURITY APPLIANCE¹  | SKU  |
|-----------------------|------|
| 19200 Base configuration: 2x1/10GbE copper management ports, 2x, 1/10/25GbE SFP28 fiber sync ports, 8x1/10GBE SFP+ ports, 96 GB RAM, 1x960 GB NVMe, 2x10 GbE Short Range Transceivers, 2x AC PSUs, telescopic rails, SandBlast (SNBT) Security Subscription Package for 1 Year | CPAP-SG19200-SNBT |
| 19200 Plus configuration: 2x1/10GbE copper management ports, 2x1/10/25GbE SFP28 fiber sync ports, 8x1/10GBE SFP+ ports, 4x10/25GbE SFP28 fiber ports, 128 GB RAM, 2x960GB NVMe, 2x10 GbE Short Range Transceivers, 2x AC PSUs, Lights-Out Management(LOM), telescopic rails, 5 Virtual Systems, SandBlast(SNBT)Security Subscription Package for 1 Year | CPAP-SG19200-PLUS-SNBT |
| Quantum Force 19200 Maestro/MHS HyperScale configuration: 2x2x40/100GbE QSFP fiber ports, 2x100GbE DAC3m transceivers, 128 GB RAM, 2x960GB NVMe, 2x AC PSUs, Lights-Out Management(LOM), Sliding rails, with SandBlast subscription package for 1 year | CPAP-SG19200-PLUS-MHS-SNBT |
| Quantum Force 19200 Maestro/MHS HyperScale configuration with 1 MHO-175 orchestrator and 2 Quantum Force 19200 appliances, each appliance includes 2x2x40/100GbE QSFP fiber ports, 2x100GbE DAC3m transceivers, 128 GB RAM, 2x960GB NVMe, 2x AC PSUs, Lights-Out Management(LOM), Sliding rails, with SandBlast subscription package for 1 year | CPAP-MHS-19202-PLUS-SNBT |
| Quantum Force 19200 Maestro/MHS HyperScale configuration with 1 MHO-175 orchestrator and 3 Quantum Force 19200 appliances, each appliance includes 2x2x40/100GbE QSFP fiber ports, 2x100GbE DAC3m transceivers, 128 GB RAM, 2x960GB NVMe, 2x AC PSUs, Lights-Out Management(LOM), Sliding rails, with SandBlast subscription package for 1 year | CPAP-MHS-19203-PLUS-SNBT |
| Next Generation Threat Prevention&amp;SandBlast package for 1 year for Quantum Force 19200 appliance | CPSB-SNBT-19200-1Y |
| Next Generation Threat Prevention package for 1 year for Quantum Force 19200 appliance | CPSB-NGTP-19200-1Y |
| Next Generation Firewall Package for 1 year for Quantum Force 19200 appliance | CPSB-NGFW-19200-1Y |
| Quantum IoT Network Protection for 1 year for Quantum Force 19200 appliances | CPSB-IOTP-19200-1Y |
| Quantum SD-WAN subscription for 1 year for Quantum Force 19200 appliances | CPSB-SDWAN-19200-1Y |
| Data Loss Prevention(DLP) blade for 1 year for Quantum Force 19200 appliances | CPSB-DLP-19200-1Y |

1 The Base package includes 2 virtual systems (VS)—one management VS and one production/data VS which are not additive or counted when adding additional VS licenses. Plus model 5 VS licenses which are additive when adding additional VS licenses.

---

## SUBSCRIPTION SERVICES

|                     | NGFW | NGTP | SNBT(SandBlast) |
|---------------------|------|------|------------------|
| Application Control  | √    | √    | √                |
| IPS                 | √    | √    | √                |
| URL Filtering        |      | √    | √                |
| Anti-Bot            |      | √    | √                |
| Anti-Virus         |      | √    | √                |
| Anti-Spam          |      | √    | √                |
| DNS Security        |      | √    | √                |
| SandBlast Threat Emulation(sandboxing) | | | √                |
| SandBlast Threat Extraction(CDR) |  | | √                |
| Zero Phishing       |  | | √                |
| IoT Network Protection | optional | optional | optional        |
| SD-WAN Network Optimization | optional | optional | optional  |

---

## Contact Information
### Worldwide Headquarters  
5 Shlomo Kaplan Street, Tel Aviv 6789159, Israel | Tel: +972-3-753-4599  
### U.S. Headquarters  
100 Oracle Parkway, Suite 800 Redwood City, CA 94065 | Tel: 1-800-429-4391  
### Website  
www.checkpoint.com

The first-year purchase includes the SNBT package. Security subscription renewals, NGFW, NGTP and SNBT are available for subsequent years.
