21600 appliance datasheet.pdf

21600

Datacenter-grade security appliance (3300 SPU/110 Gbps¹) with high port density, low latency and acceleration options

Check Point 21600 Appliance

Today’s firewall is a security device presented with an ever-increasing number of sophisticated threats. As a security gateway it must use multiple technologies to control network access, detect sophisticated attacks and provide additional security capabilities like data loss prevention and protection from web-based threats. The proliferation of mobile devices like iPhones and Tablets and new streaming, social networking and P2P applications requires a higher connection capacity and new application control technologies. Finally, the shift towards enterprise private and public cloud services, in all its variations, changes the company borders and requires enhanced capacity and additional security solutions.

Check Point’s new 21600 Appliance combines fast networking technologies with high performance multi-core capabilities—providing the highest level of security without compromising on network speeds to keep your data, network and employees secure. Optimized for the Software Blades Architecture, the appliance is capable of running any combination of Software Blades—providing the flexibility and the precise level of security for any business at every network location by consolidating multiple security technologies into a single integrated solution.

The 21600 Appliance supports the Check Point 3D security vision of combining policies, people and enforcement for unbeatable protection and is optimized for enabling any combination of the following Software Blades: (1) Firewall, (2) VPN, (3) IPS, (4) Application Control, (5) Mobile Access, (6) DLP, (7) URL Filtering, (8) Antivirus, (9) Anti-spam, (10) Anti-Bot, (11) Identity Awareness and (12) Advanced Networking & Clustering.

OVERVIEW

Leveraging its multi-core and acceleration technologies, with 3300 SecurityPower Units, the Check Point 21600 appliance supports lightning fast firewall throughput of up-to 110 Gbps¹ with sub 5µs latency and IPS throughput of more than 21 Gbps. The 21600 is designed from the ground up for unmatched flexibility for even the most demanding enterprise and data center network environments.

The 21600 appliance has 3 expansion slots supporting a wide range of network options. The 21600 standard configuration includes a twelve 1 Gigabit Ethernet copper port card. A maximally configured 21600 provides up to 37 Gigabit Ethernet copper ports or 36 fiber ports or thirteen 10 Gigabit Ethernet fiber ports.

1 With Security Acceleration Module

KEY FEATURES

KEY BENEFITS

GATEWAY SOFTWARE BLADES

21607 21608 21609 21610 21612
Firewall ■ ■ ■ ■ ■
IPsec VPN ■ ■ ■ ■ ■
Mobile Access(5 users) ■ ■ ■ ■ ■
Advanced Networking and Clustering* ■ ■ ■ ■ ■
Identity Awareness ■ ■ ■ ■ ■
IPS ■ ■ ■ ■ ■
Application Control ■ ■ ■ ■
Data Loss Prevention ■ ■
URL Filtering ■ ■ ■
Antivirus ■ ■ ■
Anti-Spam ■ ■
Anti-Bot ■

1 image management

8 6 Lights Out Management card

21600
1 Graphic LCD display for IP address and image management
2 Two hot-swappable 500GB RAID-1 hard drives
3 One USB port for ISO installation
4 Sync port 10GBase-F SFP+
5 Management port 10/100/1000Base-T RJ45
6 Lights Out Management card
7 Console port RJ45
8 Three network card expansion slots (default one 12 x 10/100/1000Base-T port card)
9 Removable mother board
10 Security Acceleration Module slot
11 Removable fans
12 16GB RAM upgrade (optional)
13 Two redundant hot-swappable AC power supplies
14 Telescopic rails

Furthermore, the 21600 also has a slot for an optional Security Acceleration Module. In addition to hot-swappable redundant disk drives and power supply units, the 21600 appliance also supports Lights-Out-Management (LOM) for remote support and maintenance capabilities. The 21600 Appliance is a highly serviceable chassis. Access to all components is easily available from the front and the back of the unit when mounted in the rack.

SECURITYPOWER

Until today security appliance selection has been based upon selecting specific performance measurements for each security function, usually under optimal lab testing conditions and using a security policy that has one rule. Today customers can select security appliances by their SecurityPower ratings which are based on real-world customer traffic, multiple security functions and a typical security policy.

The optional Check Point Security Acceleration Module (SAM-108) for the 21000 Appliances is ideal for latency-sensitive applications such as financial trading and VoIP communication. With sub 5 micro-seconds firewall latency, this purpose-built acceleration module boasts 108 SecurityCores™ accelerating

SECURITY ACCELERATION MODULE

SecurityPower is a new benchmark that measures the capability and capacity of an appliance to perform multiple advanced security functions (Software Blades) such as IPS, DLP and Application Control in real world traffic conditions. This provides an effective metric to better predict the current and future behavior of appliances under security attacks and in day-to-day operations. Customer SecurityPower Unit (SPU) requirements, determined using the Check Point Appliance Selection Tool, can be matched to the SPU ratings of Check Point Appliances to select the right appliance for their specific requirements.

dow on all interface ports with a single SAM-108. Performance for the 21600 appliance is boosted to 110 Gbps of firewall throughput and 300,000 connections per second and 37 Gbps of VPN throughput.

The 21600 Appliance may be purchased with a Security Acceleration Module bundle pre-installed resulting in a significant cost savings. Included in the SAM-108 bundle is one 4 x 10 GbE Acceleration Ready card instead of the default 12 x 1 GbE network interface card.

INTEGRATED SECURITY MANAGEMENT

The appliance can either be managed locally with its available integrated security management or via central unified management. Using local management, the appliance can manage itself and one adjacent appliance for high availability purposes.

BUSINESS CONTINUITY, RELIABILITY AND EXTENSIBILITY

The Check Point 21600 appliance delivers business continuity and serviceability through features such as hot-swappable redundant power supplies, hot-swappable redundant hard disk drives (RAID), redundant fans and an advanced LOM card for out-of-band management. Combined together, these features ensure a greater degree of business continuity and serviceability when these appliances are deployed in the customer’s networks.

REMOTE ACCESS CONNECTIVITY SECURITY ACCELERATION MODULE

REMOTE ACCESS CONNECTIVITY FOR MOBILE DEVICES

The 21600 appliance arrives with mobile access connectivity for 5 users, using the Mobile Access Blade. This license enables secure remote access to corporate resources from a wide variety of devices including smartphones, tablets, PCs, Mac and Linux.


REMOTE PLATFORM MANAGEMENT AND MONITORING

A Lights-Out-Management (LOM) card provides out-of-band remote management to remotely diagnose, start, restart and manage the appliance from a remote location. Administrators can also use the LOM web interface to remotely install an OS image from an ISO file.

GAiA—THE UNIFIED SECURITY OS

Check Point GAiA™ is the next generation Secure Operating System for all Check Point appliances, open servers and virtualized gateways. GAiA combines the best features from IPSO and SecurePlatform into a single unified OS providing greater efficiency and robust performance. By upgrading to GAiA, customers will benefit from improved appliance connection capacity and reduced operating costs. With GAiA,

TECHNICAL SPECIFICATIONS

customers will gain the ability to leverage the full breadth and power of all Check Point Software Blades. GAiA secures IPv4 and IPv6 networks utilizing the Check Point Acceleration & Clustering technology and it protects the most complex network environments by supporting dynamic routing protocols like RIP, OSPF, BGP, PIM (sparse and dense mode) and IGMP. As a 64-Bit OS, GAiA increases the connection capacity of select appliances.

GAiA simplifies management with segregation of duties by enabling role-based administrative access. Furthermore, GAiA greatly increases operation efficiency by offering Automatic Software Updates. The intuitive and feature-rich Web interface allows for instant search of any commands or properties. GAiA offers full compatibility with IPSO and SecurePlatform command line interfaces, making it an easy transition for existing Check Point customers.

Base Configuration
1 on-board 10/100/1000Base-T RJ45
1 on-board 10GbE SFP+
12 x 10/100/1000BaseT RJ45 NIC(default) or4x10GbE SFP+Acceleration Ready NIC(with SAM-108 bundle)
Security Acceleration Module(with SAM-108 bundle)
16 GB Memory
Redundant dual hot-swappable Power Supplies
Redundant dual hot-swappable 500GB Hard Drives
LOM card
Telescopic rails(26"-35")
Network Expansion Slot Options(3 slots)
12x10/100/1000Base-TRJ45 ports
12x1000Base-FSFP ports
4x10GBase-FSFP+ports
Max Configuration
Up to37x10/100/1000Base-TRJ45 ports
Up to36x1000Base-FSFP ports
Up to13x10GBase-FSFP+ports
32GB RAM
Performance
2501-3300¹SecurityPower²
75-110¹Gbps of firewall throughput,1518 byte UDP
8.5-37¹Gbps of VPN throughput,AES-128
21 Gbps of IPS throughput Default IPS profile
6.8 Gbps of IPS throughput,recommended IPS profile
6/13³(default/max) million concurrent connections
140,000/300,000¹connections per second
Network Connectivity
IPv4 and IPv6
1024 VLANs
256 VLANs per interface
802.3ad passive and active link aggregation
Layer 2 (transparent) and Layer 3 (routing) mode
High Availability
Active/Active-L3 mode
Active/Passive-L3 mode
Session synchronization for firewall and VPN
Session failover for routing change
Device failure detection
Link failure detection
ClusterXL or VRRP
Virtual Systems4
Max VSs:150(w/16GB),250(w/32GB)
Dimensions
Enclosure:2RU
Standard(WxDxH):17x28x3.5in.
Metric(WxDxH):431x710x88mm
Weight:26kg(57.4lbs.)
Power Requirements
AC Input Voltage:100-240V
Frequency:47-63Hz
Single Power Supply Rating:1200W
Power Consumption Maximum:449W
Maximum thermal output:1533BTU
Operating Environmental Conditions
Temperature:32°to104°F/0°to40°C
Humidity:20%-90%(non-condensing)
Storage Conditions
Temperature:-4°to158°F/-20°to70°C
Humidity:5%to95%at60°C(non-condensing)
Certifications
Safety:UL/cULT
Emissions:FCC,CE
Environmental:RoHS

1 With Security Acceleration Module

2 A metric to measure appliance performance based on real world traffic given the deployed software blades. Find the right appliance for your performance and security needs.

3 With the Gaia OS and memory upgrade

4 Available in Q4 2012


SOFTWARE PACKAGE SPECIFICATIONS

Base System SKU
21600 Appliance with 12 Security blades (including Firewall, VPN, Advanced Networking, Acceleration and Clustering, Identity Awareness, and Mobile Access for 5 concurrent users, IPS, Application Control, URL Filtering, Antivirus, Anti-Spam & Email Security, and DLP blades); bundled with local management for up to 2 gateways CPAP-SG21612
21607 Appliance with 7 Security Software Blades (including Firewall, VPN, Advanced Networking & Clustering, Identity Awareness, Mobile Access for 5 concurrent users, IPS, and Application Control Software Blades); bundled with local management for up to 2 gateways CPAP-SG21607
21607 + SAM108 bundle includes the 21607 Software Blade package with the Security Acceleration Module, CPAC-SAM108,and one x 4 10GGE Acceleration Ready interface card, CPAC-ACCL-4-10F-21000,pre-installed instead of the default 12x10/100/1000Base7 interface card, CPAC-12-1C-21000 CPAP-SG21607-SAM-BUN
21608 Appliance with 8 Security blades (including Firewall, VPN, Advanced Networking & Clustering, Identity Awareness, Mobile Access for 5 concurrent users, IPS, Application Control, and DLP blades); bundled with local management for up to 2 gateways CPAP-SG21608
21609 Appliance with 9 Security blades (including Firewall, VPN, Advanced Networking & Clustering, Identity Awareness, and Mobile Access for 5 concurrent users, IPS, URL Filtering, Antivirus and Anti-Bot Security blades); bundled with local management for up to 2 gateways CPAP-SG21609
21610 Appliance with 10 Security Software Blades (including Firewall, VPN, Advanced Networking & Clustering, Identity Awareness, and Mobile Access for 5 concurrent users, IPS, Application Control, URL Filtering, Antivirus, and Email Security Software Blades); bundled with local management for up to 2 gateways CPAP-SG21610
Software Blades Packages SKU
Check Point Extended Security Software Blades Package for 1 year for 21600 appliance(including URL Filters,Application Control,Antivirus,Email Security,and DLP Software Blades) CPSB-ESEC-6B-21600-1Y
Check Point UTM+ Software Blades Package for 1 year for 21600 appliance(including URL Filters,Application Control,Antivirus,and Email Security Software Blades) CPSB-UTMP-5B-21600-1Y
Check Point Threat Prevention Software Blades Package for 1 year for 21600(including URL-Bot,URL Filtering and Antivirus blades) CPSB-TPRV-4B-21600-1Y
Secure Web Gateway Software Blades package for 1 year for SWG-21600 CPSB-SWG-3B-21600-1Y
Check Point DLP+ Software Blades Package for 1 year for 21600 appliance(including IPS,Application Control,and DLP) CPSB-DLPP-3B-21600-1Y
Check Point Extended Threat Protection Software Blades Package for 1 year for 21600(including Application Control and IPS Software Blades) CPSB-ETPR-2B-21600
Check Point Web Control Software Blades Package for 1 year for 21600(including Application Control and URL Filtering Software Blades) CPSB-WBCL-2B-21600
Check Point Anti-Malware Package for 1 year for 21600(including Anti-Bot and AV blades) CPSB-ABAV-2B-21600
Software Blades SKU
Check Point Mobile Access Blade for unlimited concurrent connections CPSB-MOB-U
Data Loss Prevention Blade for 1 year(for 1,500 users and above,up to 250,000 mails per hour and max throughput of 2.5 Gbps) CPSB-DLP-U-1Y
Check Point IPS blade for 1 year CPSB-IPS-XL-1Y
Check Point Application Control blade for 1 year CPSB-APCL-XL-1Y
Check Point URL Filtering blade for 1 year CPSB-URLF-XL-1Y
Check Point Antivirus Blade for 1 year CPSB-AV-XL-1Y
Check Point Anti-Spam & Email Security Blade for 1 year CPSB-ASPM-1Y
Check Point Anti-Bot blade for 1 year - for ultra high-end appliances and pre-defined systems CPSB-ABOT-XL-1Y
Virtual Systems Packages¹ SKU
50 Virtual Systems package CPSB-VS-50
50 Virtual Systems package for HA/VSLS CPSB-VS-50-VSLS
25 Virtual Systems package CPSB-VS-25
25 Virtual Systems package for HA/VSLS CPSB-VS-25-VSLS
10 Virtual Systems package CPSB-VS-10
10 Virtual Systems package for HA/VSLS CPSB-VS-10-VSLS

1 Available in Q4 2012


ACCESSORIES

Interface Cards and Transceivers SKU
Security Acceleration Module CPAC-SAM108
4 Port 10GBase-F SFP+ Acceleration Ready interface card CPAC-ACCL-4-10F-21000
12 Port 10/100/1000 Base-T RJ45 interface card CPAC-12-1C-21000
12 Port 1000Base-F SFP interface card; requires additional 1000Base SFP transceiver modules per interface port CPAC-12-1F-21000
SFP transceiver module for 1G fiber ports - long range (1000Base-LX) for CPAC-12-1F network interface card CPAC-TR-1LX-21000
SFP transceiver module for 1G fiber ports - short range (1000Base-SX) for CPAC-12-1F network interface card CPAC-TR-1SX-21000
SFP transceiver to 1000 Base-T RJ45(Copper) for CPAC-12-1F CPAC-TR-1T-21000
4 Port 10GBase-F SFP+ interface card; requires an additional 10GBase SFP+ transceiver per interface port CPAC-4-10F-21000
SFP+ transceiver module for 10G fiber ports - long range(10GBase-LR)for CPAC-4-10F-21000 network interface card CPAC-TR-10LR-21000
SFP+ transceiver module for 10G fiber ports - short range(10GBase-SR)for CPAC-4-10F-21000 network interface card CPAC-TR-10SR-21000
Spares and Miscellaneous
32 GB RAM Memory upgrade for 21600 appliance CPAC-RAM32GB-21600
Replacement parts kit(including 1 Hard Disk Drive, one Power Supply, one Fan) for 21600 appliance CPAC-SPARES-21600
Replacement AC Power Supply for 21600 appliance CPAC-PSU-21600
Replacement 500G Hard Disk Drive for 21600 appliance CPAC-HDD-500G-21000