Check Point 1595 Rugged Security Gateways Datasheet
QUANTUM RUGGED SERIES SECURITY GATEWAYS
To Secure OT/ICS/SCADA and Critical Infrastructure Systems
Secure. Rugged. Simple.
Check Point Quantum Rugged appliances ensure industrial sites, manufacturing floors and mobile fleets are connected and secure. The solid-state design of the Quantum Rugged security gateways operates in temperatures ranging from -40°C to 75°C, making it ideal for securing any industrial application - power and manufacturing plants, oil and gas facilities, maritime fleets, building management systems, and more. Connect your field devices to the Rugged LAN switch and your Rugged gateway to OT management networks via copper and fiber Ethernet ports as well as via integrated Wi-Fi, LTE, and 5G cellular connectivity.
!
Transportation
Oil & Gas
1595R 5G & 1575R (WiFi/LTE)
!
The Check Point Quantum Rugged Next Generation Firewall (NGFW) secures Critical Infrastructure and Industrial Control Systems (ICS) without impacting operations. Our NGFWs identify and secure over 70 standard and proprietary SCADA (Supervisory Control and Data Acquisition) and ICS protocols. This includes the most popular protocols used in utilities and energy sectors, manufacturing sectors, Building Management Systems and IoT (Internet of Things) devices.
Manufacturing
SECURE SCADA AND ICS ENVIRONMENTS
Utilities
RUGGED FORM FACTOR
The rugged solid-state form factor enables Quantum Rugged to operate in a temperature range of -40C to +75C, making it ideal for deployment in harsh environments. The Rugged family is certified for the industrial specifications IEEE 1613 and IEC 61850-3 for heat, vibration, and immunity to electromagnetic interference (EMI). In addition, these firewalls are certified for maritime operation per IEC-60945 and IACS E10 and comply with DNV-GL-CG-0339.
SPOTLIGHT ON SECURITY
Advanced security, uncompromising performance
The Quantum Rugged industrial security gateways ensures robust cybersecurity for critical infrastructure and OT environments. These security gateways offer top-tier protection for your mission-critical operations. They are managed through the latest R81 software, providing a fortified defense against cyber threats in industrial and OT environments.
!
!
1575R Wi-Fi LTE
!
1595R 5G
!
!
Comprehensive Protection
- Next Generation Firewall
- Site-to-Site VPN
- Remote Access VPN
- Application Control and Web Filtering
- IoT Device Recognition & Protection
- Intrusion Prevention (IPS)
- SandBlast Threat Emulation (sandboxing)
- Antivirus
ICS/SCADA Protocol Support
1575R & 1595R Performance Highlights:
- BACNet, CIP, DNP3, IEC-60870-5-104, IEC 60870-6 (ICCP), IEC 61850, MMS, ModBus, OPC DA & UA, Profinet, Step7 (Siemens) and more; 1400+ in all. See the full list at appwiki.checkpoint.com.
| VPN | Firewall | NGFW¹ | Threat Prevention² |
|---|---|---|---|
| 1,100 Mbps | 1,970 Mbps | 830 Mbps | 400 Mbps |
Protect unpatched ICS systems from known exploits.
1: Includes Firewall, Application Control, IPS. 2: Includes Firewall, Application Control, URL Filtering, IPS, Antivirus, Anti-Bot, sandboxing
SPOTLIGHT ON HARDWARE
Reliable, Rugged, Always Available
The solid-state Quantum Rugged security gateways have no moving parts like disks or fans, enabling them to operate in environments with extreme temperatures and are certified for industrial applications. The embedded wireless modem dual SIM functionality enables automatic fail over between SIMs and has a peak download rate of 4.5 Gbps and an uplink rate of 660 Mbps.
Rugged 1595R Wired | 5G
- RJ45 serial console port
- 1x 1GbE copper/fiber WAN interface
- 4x 1GbE LAN switch
- DC power connector
- AC to DC power adapter connection
- USB-C console port
- 1x 1GbE copper/fiber DMZ interface
- Embedded Dual SIM LTE modem (optional)
- DB9 RS232/422/485 to PLCs
Rugged 1575R Wired | Wi-Fi with LTE
- 8x 1GbE LAN switch
- 1x 1GbE WAN interface
- LED tower
- 802.11 a/b/g/n/ac/ax
SPOTLIGHT ON MANAGEMENT
Lower the complexity of managing your security
Check Point Infinity delivers a fully consolidated cybersecurity architecture that protects your business and IT infrastructure across complex environments against Generation V cyber-attacks across networks, IoT devices, endpoint, cloud and mobile. Check Point Infinity delivers unprecedented protection against current and potential attacks—today and in the future.
Zero-touch Deployment, Central Management
An intuitive web-based user interface enables large enterprises to provision security efficiently. Apply a template to your inventory of new security gateways. The template specifies common device configuration settings and readies the gateway for central security management. When powered on Check Point gateways get their configuration from the cloud and are ready for a security policy.
Cyber security management for Industrial IoT (IIoT)
Check Point offers the industry’s most comprehensive cyber-security solution for different IoT environments, including Smart Office, Smart Building, Industrial, and Healthcare. The solution enables organizations to prevent IoT related attacks and minimize their IoT attack surface. All in a way that is easily scalable and non-disruptive to critical processes.
BENEFITS
- Instantly secure all your existing IoT devices and safely implement new ones.
- Cut down security man-hours with automated detection and remediation of threats.
- Keep critical processes undisrupted with adaptive policies and no need to physically patch devices.
CAPABILITIES
IoT Risk Analysis: Check Point offers two solutions for discovering IoT devices: IoT Protect and integrations with leading IIoT discovery vendors who use the Check Point IoT API. IoT Protect leverages Check Point firewalls for discovery and this can be enriched with imports of discovered IIoT devices from leading IIoT discovery vendors. Objects are classified based on their risk level. The solution continually performs a comprehensive risk analysis to expose all the risks associated with your devices.
Auto-Segmentation: Minimize risk exposure with auto-generated IoT policies. Save time in manually creating the IoT security policy and ensure IoT devices are secure from the moment they connect to your network. The solution automatically generates and enforces a policy for every device. Policies that allow only authorized access to (and from) IoT devices and ensure devices only use communication protocols they were designed to use.
SmartConsole Policy Automatically Generated by IoT Vendor using the IoT API
Threat Prevention: Block known and unknown IoT related attacks with virtual patching. The IoT import can also include a CVE assessment of the imported IoT object so that a threat prevention policy can be applied. This protects vulnerable devices against known malicious exploits with the appropriate IPS signatures on the Check Point firewalls.
1500 RUGGED SPECIFICATIONS
| 1575R | 1595R | |
|---|---|---|
| **Threat Prevention [Mbps]**¹ | 400 | |
| **Next Generation Firewall [Mbps]**² | 830 | |
| Firewall Throughput [Mbps] | 1970 | |
| VPN AES-128 Throughput [Mbps] | 1100 | |
| Connections per Second | 14600 | |
| Concurrent Connections | 1000000 | |
| Protocols | Over 70 protocols, including the most popular in the industry: Modbus, Bacnet, CIP, S7, IEC-104, DNP3 and many more |
1: Includes Firewall, Application Control, URL Filtering, IPS, Antivirus, Anti-Bot, SandBlast Zero-Day Protection
2: Includes Firewall, Application Control, IPS
1575R - 1595R SPECIFICATIONS (continued)
| 1575R | 1595R | |
|---|---|---|
| MTBF | ||
| DC Input(@25℃) | 268.8 years | Wired(11.27 years),5G(30.16 years) |
ORDERING THE 1595R - 1575R RUGGED
1595R RUGGEDIZED SPECIFICATIONS
| Ruggedized Next Generation appliance with one year SNBT subscription package | CPAP-SG1595R-SNBT |
|---|---|
| 1595R 5G Ruggedized Next Generation appliance with one year SNBT subscription package | CPAP-SG1595R5G-SNBT |
| 1575R Ruggedized Next Generation appliance with one year SNBT subscription package | CPAP-SG1575R-SNBT-DC |
| 1575R WiFi and LTE Ruggedized Next Generation appliance with one year SNBT subscription package | CPAP- SG1575RWLTE-xx-SNBT-DC |
ACCESSORIES
| Description | SKU |
|---|---|
| SFP Short range transceiver(for the DMZ 1000BaseF port) | CPAC-1500-TR-1SX |
| SFP Long range transceiver(for the DMZ 1000BaseF port) | CPAC-1500-TR-1LX |
| SD memory card32GB | CPAC-1500-32GB-SD |
| Replacement 5G Antenna(4 antennas) | CPAC-1595R-5G-ANTENNA |
| Replacement Wi-Fi Antenna(4 antennas) | CPAC-1500-WIFI-ANTENNA |
| Replacement LTE Antenna(1 piece) | CPAC-1590-LTE-ANTENNA |
| Industrial grade power adapter,120W | CPAC-1575R/1595R-PSU |
| Rack Mount shelf for Single/Dual for 1575R security gateways | CPAC-1575R-RM-DUAL |
ORDERING THE 1595R - 1575R RUGGED (continued)
Services Bundles
| NGFW | NGTP | SNBT | |
|---|---|---|---|
| Security Appliance | √ | √ | √ |
| Premium Support | √ | √ | √ |
| Pro Support option | √ | √ | √ |
| Firewall | √ | √ | √ |
| VPN | √ | √ | √ |
| Mobile Access | √ | √ | √ |
SERVICE SERVICES HIGHLIGHTS
| SERVICE | SERVICES HIGHLIGHTS |
|---|---|
| Next-Gen Firewall (NGFW) | Segment networks and apply zero trust policy with IPS. Accept, prevent, schedule, and apply traffic-shaping based controls to application traffic10,000+ pre-defined apps or customize your own application. Protect vulnerable systems with 12,000+ IPS protections. |
| Next-Gen Threat Prevention (NGTP) | AI Deep Learning DNS security with antivirus and anti-bot prevents threats. DNS security prevents Command & Control (C2) connections and blocks data theft through DNS tunneling. |
| SandBlast(SNBT) | Comprehensive, multi-layered defense with sandboxing protection from unknown and zero-day threats. Average emulation time for unknown files that require full sandbox evaluation is under 100 seconds. |
| IoT Network Protection | Simple, effective, autonomous discovery and protection of IoT devices in minutes. Passive and active discovery of enterprise IoT devices with autonomous mapping to 200+ profiles. |
| SD-WAN: | Reliable and optimum network connectivity at the lowest cost with link aggregation and link prioritization according to latency, jitter, and packet loss. |