Check Point 1595 Rugged Security Gateways Datasheet

QUANTUM RUGGED SERIES SECURITY GATEWAYS

To Secure OT/ICS/SCADA and Critical Infrastructure Systems

Secure. Rugged. Simple.

Check Point Quantum Rugged appliances ensure industrial sites, manufacturing floors and mobile fleets are connected and secure. The solid-state design of the Quantum Rugged security gateways operates in temperatures ranging from -40°C to 75°C, making it ideal for securing any industrial application—power and manufacturing plants, oil and gas facilities, maritime fleets, building management systems, and more. Connect your field devices to the Rugged LAN switch and your Rugged gateway to OT management networks via copper and fiber Ethernet ports as well as via integrated Wi-Fi, LTE, and 5G cellular connectivity.

Transportation

Oil & Gas

The Check Point Quantum Rugged Next Generation Firewall (NGFW) secures Critical Infrastructure and Industrial Control Systems (ICS) without impacting operations. Our NGFWs identify and secure over 70 standard and proprietary SCADA (Supervisory Control and Data Acquisition) and ICS protocols. This includes the most popular protocols used in utilities and energy sectors, manufacturing sectors, Building Management Systems and IoT (Internet of Things) devices.

Manufacturing

SECURE SCADA AND ICS ENVIRONMENTS

Utilities

RUGGED FORM FACTOR

The rugged solid-state form factor enables Quantum Rugged to operate in a temperature range of -40C to +75C, making it ideal for deployment in harsh environments. The Rugged family is certified for the industrial specifications IEEE 1613 and IEC 61850-3 for heat, vibration, and immunity to electromagnetic interference (EMI). In addition, these firewalls are certified for maritime operation per IEC-60945 and IACS E10 and comply with DNV-GL-CG-0339.


SPOTLIGHT ON SECURITY

Advanced security, uncompromising performance

The Quantum Rugged industrial security gateways ensures robust cybersecurity for critical infrastructure and OT environments. These security gateways offer top-tier protection for your mission-critical operations. They are managed through the latest R81 software, providing a fortified defense against cyber threats in industrial and OT environments.

Comprehensive Protection

ICS/SCADA Protocol Support

1575R & 1595R Performance Highlights

BACNet, CIP, DNP3, IEC-60870-5-104, IEC 60870-6 (ICCP), IEC 61850, MMS, ModBus, OPC DA & UA, Profinet, Step7 (Siemens) and more; 1400+ in all. See the full list at appwiki.checkpoint.com.

VPN Firewall NGFW¹ Threat Prevention²
1,100 Mbps 1,970 Mbps 830 Mbps 400 Mbps

Protect unpatched ICS systems from known exploits.

1: Includes Firewall, Application Control, IPS.
2: Includes Firewall, Application Control, URL Filtering, IPS, Antivirus, Anti-Bot, sandboxing


SPOTLIGHT ON HARDWARE

Reliable, Rugged, Always Available

The solid-state Quantum Rugged security gateways have no moving parts like disks or fans, enabling them to operate in environments with extreme temperatures and are certified for industrial applications. The embedded wireless modem dual SIM functionality enables automatic failover between SIMs and has a peak download rate of 4.5 Gbps and an uplink rate of 660 Mbps.

Rugged 1595R

Component Description
1. RJ45 serial console port
2. 1x 1GbE copper/fiber WAN interface
3. 4x 1GbE LAN switch
4. DC power connector
5. AC to DC power adapter connection
6. USB-C console port
7. 1x 1GbE copper/fiber DMZ interface
8. Embedded Dual SIM LTE modem (optional)
9. DB9 RS232/422/485 to PLCs

Rugged 1575R

Component Description
1. 802.11 a/b/g/n/ac/ax
2. LED tower
3. 1x 1GbE WAN interface
4. 8x 1GbE LAN switch

SPOTLIGHT ON MANAGEMENT

Lower the complexity of managing your security

Check Point Infinity delivers a fully consolidated cybersecurity architecture that protects your business and IT infrastructure across complex environments against Generation V cyber-attacks across networks, IoT devices, endpoint, cloud and mobile. Check Point Infinity delivers unprecedented protection against current and potential attacks—today and in the future.

Zero-touch Deployment, Central Management

An intuitive web-based user interface enables large enterprises to provision security efficiently. Apply a template to your inventory of new security gateways. The template specifies common device configuration settings and readies the gateway for central security management. When powered on Check Point gateways get their configuration from the cloud and are ready for a security policy.

Cybersecurity management for Industrial IoT (IIoT)

Check Point offers the industry’s most comprehensive cybersecurity solution for different IoT environments, including Smart Office, Smart Building, Industrial, and Healthcare. The solution enables organizations to prevent IoT related attacks and minimize their IoT attack surface. All in a way that is easily scalable and non-disruptive to critical processes.

BENEFITS

CAPABILITIES
IoT Risk Analysis: Check Point offers two solutions for discovering IoT devices: IoT Protect and integrations with leading IIoT discovery vendors who use the Check Point IoT API. IoT Protect leverages Check Point firewalls for discovery and this can be enriched with imports of discovered IIoT devices from leading IIoT discovery vendors. Objects are classified based on their risk level. The solution continually performs a comprehensive risk analysis to expose all the risks associated with your devices.

Auto-Segmentation: Minimize risk exposure with auto-generated IoT policies. Save time manual creating the IoT security policy and ensure IoT devices are secure from the moment they connect to your network. The solution automatically generates and enforces a policy for every device, allowing only authorized access to (and from) IoT devices and ensuring devices only use communication protocols they were designed to use.

SmartConsole Policy Automatically Generated by IoT Vendor using the IoT API

Threat Prevention: Block known and unknown IoT related attacks with virtual patching. The IoT import can also include a CVE assessment of the imported IoT object so that a threat prevention policy can be applied. This protects vulnerable devices against known malicious exploits with the appropriate IPS signatures on the Check Point firewalls.


1500 RUGGED SPECIFICATIONS

1575R 1595R
Enterprise Testing Conditions
Threat Prevention [Mbps]¹ 400
Next Generation Firewall [Mbps]² 830
IPS Throughput [Mbps] 1000
Firewall Throughput [Mbps] 1,970
RFC 3511, 2544, 2647, 1242 Performance (LAB)
Firewall 1518 Byte UDP Packets [Mbps] 4,000
VPN AES-128 Throughput [Mbps] 1,100
Connections per Second 14,600
Concurrent Connections 1,000,000
Software
Security Firewall, VPN, User Awareness, QoS, Application Control, URL Filtering, IPS, Anti-Biot, Antivirus and SandBlast Threat Emulation [sandboxing]
Unicast, Multicast Routing and Clustering DSPFv2, BGPv4 and 4++, RIP, PIM [SM, DSM, ISM], IGMP, ClusterXL High Availability
IPv6 local network and internet connections, dual stack tunneling IPv4 over IPv6 networks, prefix delegation
Mobile Access License [Users] 200 remote SNX or Mobile VPN client users
Protocols Over 70 protocols, including the most popular in the industry: Modbus, Bacnet, CIP, S7, IEC-104, DNP3 and many more
Hardware
WAN Port 1x 10/100/1000Base-T RJ-45 / 1x 1000BaseF SFP port [transceiver not included]
DMZ Port 1x 10/100/1000Base-T RJ-45 / 1x 1000BaseF SFP port [transceiver not included]
LAN Ports 8x 10/100/1000Base-T RJ-45 ports 4x 10/100/1000Base-T RJ-45 ports
Wi-Fi 6 (optional) 802.11 a/b/g/n/acax MU-MIMO 3x3 -
Wi-Fi Radio Bands (association rate) One radio band non-concurrent: 2.4GHz (max 450 Mbps) & 5 GHz (max 1,300 Mbps) -
Wireless (optional) LTE Embedded modem supporting fallback to 3G,CAT13 with Main and Auxiliary antenna max 400Mbps downlink speed and 150Mbps uplink speed with dual SIM support 5G Embedded modem, sub-6 GHz, max 4.5 Gbps downlink and 660 Mbps uplink speed
SIM (optional) Dual SIM [Nano and Micro]
Console Port 1x USB-C 1x USB-C and RJ45
USB Port 1x USB 3.0
SD Card Slot Micro-SD slot
Bypass NIC No Yes
Serial Port 1x DB9 female connector, supports RS232 serial protocols, [RS422, R485 ready] 1 x RJ45 female connector, supports RS232 serial protocols
Dimensions
Enclosure Desktop, wall mount, DIN rail (bottom and back mount options)
Dimensions(W x D x H) 150 x 150 x 90 mm, 5.9 x 5.9 x 3.5 in. 150 x 170 x 42 mm, 5.9 x 6.7 x 1.7 in.
Weight 1.8 kg (3.0 lbs.) Wired 1.21kg (2.66lbs), 5G 1.36kg (2.99lbs)
Environment
Operating -40°C -75°C (-40°F +167°F)
Storage -45°C -85°C (-49°F -185°F), 5-95%, non-condensing
Power Requirements
Power Redundancy Supported
Power Adapter AC Input 110 - 240VAC, 50 - 60 Hz, AC socket IEC 320-C14 Type
Power Adapter Options 12V/10A 120W industrial grade (-40° -70°C, -40° -158°F) power adapter Note: power adapter sold separately
DC Input (3-pin terminal) Nominal 12 to 60VDC,-48VDC, Maximum Range 10.2VDC to 72VDC
Power Consumption (Max) Wired: 25.1W, Wi-Fi-LTE: 30.7W Wired: 26.8W, 5G 29.5W
Heat Disposition Wired: 85.6 BTU/hr, Wi-Fi-LTE: 104.8 BTU/hr. Wired: 91.4 BTU/hr, 5G 100.6 BTU/hr.
  1. Includes Firewall, Application Control, URL Filtering, IPS, Antivirus, Anti-Bot, SandBlast Zero-Day Protection
  2. Includes Firewall, Application Control, IPS

1575R - 1595R SPECIFICATIONS (continued)

1575R 1595R
MTBF
DC Input(@25℃) 268.8 years Wired(11.27 years), 5G(30.16 years)
AC Input, Industrial grade(@25℃) 30.2 years Wired(8.35 years), 5G(15.37 years)
Certifications
Safety CB IEC,UL,CE LVD-IEC 62368-1,UL/c 62368-1,CE LVDEN62368-1,ASNZ 62368-1 CB IEC,UL,CE LVD-IEC 62368-1,UL/c 62368-1,CE LVDEN62368-1,ASNZ 62368-1
EMC(Emissions) CE,UKCA,FCC,IC,VCCI,AS_NZS ACMA CE,UKCA,FCC,IC,VCCI,AS_NZS ACMA
Environment RoHS,REACH,WEEE,POP,TSCA RoHS,REACH,WEEE,POP,TSCA
Industrial Certifications IEEE1613,IEC61850-3,IEC60945,EN/IEC60529 IEEE1613,IEC61850-3
Rugged Certifications EN/IEC60529,IEC60068-2-27 shock,IEC60068-2-6 vibration EN/IEC60529,IEC61850-3,IEC60255-27C2.2
Maritime IEC-60945B,DNV-GL-CG-0339 -
IP Rating IP30 IP30 according EN/IEC60529
Cellular PTCRB,GCF and Carriers AT&T and Verizon certified PTCRB,GCF and Carriers AT&T & Verizon

ORDERING THE 1595R - 1575R RUGGED

Description SKU
1 1595R Ruggedized Next Generation appliance with one year SNBT subscription package CPAP-SG1595R-SNBT
2 1595R 5G Ruggedized Next Generation appliance with one year SNBT subscription package CPAP-SG1595R5G-SNBT
3 1575R Ruggedized Next Generation appliance with one year SNBT subscription package CPAP-SG1575R-SNBT-DC
4 1575R WiFi and LTE Ruggedized Next Generation appliance with one year SNBT subscription package CPAP-SG1575RWLTE-xx-SNBT-DC

USA, Canada

Wi-Fi Regions SKU Note
USA, Canada change-xx to-US
Europe change-xx to-EU
Japan change-xx to-JP
Australia, Argentina change-xx to-AU
Israel change-xx to-IL
China change-xx to-CN
India, Chile change-xx to-IN
New Zealand change-xx to-NZ
Latin America, Singapore,Hong Kong,Thailand,Sri-Lanka change-xx to-LA

ACCESSORIES

Accessory Description SKU
SFP Short range transceiver(for the DMZ 1000BaseF port) CPAC-1500-TR-1SX
SFP Long range transceiver(for the DMZ 1000BaseF port) CPAC-1500-TR-1LX
SFP Short Range 100BaseF transceiver. compatible with 1575R appliance CPAC-1500-TR-100BASE-FX
SD memory card32GB CPAC-1500-32GB-SD
SD memory card64GB CPAC-1500-64GB-SD
Replacement 5G Antenna(4 antennas) CPAC-1595R-5G-ANTENNA
Replacement Wi-Fi Antenna(4 antennas) CPAC-1500-WIFI-ANTENNA
Replacement LTE Antenna(1 piece) CPAC-1590-LTE-ANTENNA
Industrial grade power adapter,120W(-40°70°C,-40°158°F) CPAC-1575R/1595R-PSU
Rack Mount shelf for Single/Dual for 1575R security gateways CPAC-1575R-RM-DUAL

ORDERING THE 1595R - 1575R RUGGED (continued)

Services Bundles

NGFW NGTP SNBT
Security Appliance √ √ √
Premium Support √ √ √
PRO Support option √ √ √
Firewall √ √ √
VPN √ √ √
Mobile Access √ √ √
Application Control √ √ √
Intrusion Prevention System √ √ √
URL Filtering √ √
Antivirus and Anti-Bot √ √
Anti-Spam and Email Security √ √
DNS Security √ √
Threat Emulation √
IoT Network protection for SMBs* √
SD-WAN network optimization for SMBs* √ √ √
IoT network protection for enterprises** Optional Optional Optional
SD-WAN network optimization for enterprises** Optional Optional Optional

Optional security capabilities can be ordered a-la-carte or separately.


SUBSCRIPTION SERVICES

See the table above for security capabilities included in the NGFW, NGTP and SNBT services packages. IoT and SD-WAN are ordered a la carte.

SERVICE SERVICES HIGHLIGHTS

SERVICE SERVICES HIGHLIGHTS
Next-Gen Firewall (NGFW): segment networks and apply zero trust policy with IPS Accept, prevent, schedule, and apply traffic-shaping based controls to application traffic 10,000+ pre-defined apps or customize your own application Protect vulnerable systems with 12,000+ IPS protections
Next-Gen Threat Prevention (NGTP): AI Deep Learning DNS security with antivirus and anti-bot prevents threats DNS security prevents Command & Control(C2) connections and blocks data theft through DNS tunneling Antivirus stops incoming malicious files and links in web, email, FTP and SMB content Anti-Bot detects infected hosts and prevents communications with external C2 servers Apply web and application control using 100+ categories or customize your own
SandBlast (SNBT): comprehensive, multi-layered defense with sandboxing protection from unknown and zero-day threats Average emulation time for unknown files that require full sandbox evaluation is under 100 seconds Emulation OS Support: Windows XP, 7, 8.1, 10 applications CPU-level, OS-level and static file analysis Maximal file size for emulation is 15MB
IoT Network Protection: simple, effective, autonomous discovery and protection of IoT devices in minutes Passive and active discovery of enterprise IoT devices with autonomous mapping to 200+ profiles IoT attributes include function, manufacturer, model, risk, confidence, VLAN, IP and MAC address Automatically creates and applies an inline zero-trust IoT policy layer
SD-WAN: reliable and optimum network connectivity at the lowest cost Link aggregation and link prioritization according to latency, jitter, and packet loss Advanced multi-path orchestration and steering for 10,000+ apps Sub-second failover for overlay and supported applications SLA monitoring and autonomous link swapping