sk181924 - Spark Firewall 1900 and 2000 Models
Spark Firewall 1900 and 2000 Models
Solution
Overview
Check Point's Spark Firewall security appliances are high performance, integrated devices offering firewall, VPN, Anti-Virus, application visibility and control, URL filtering, email security and SandBlast Zero-Day Protection to small and medium sized businesses. Spark Firewall appliances are simple to configure and manage.
Spark Firewall 1900 and 2000 were designed for medium size business supporting up to 1,000 employees, and as such, they offer strong performance and high port capacity, including four 10GbE network interfaces.
Hardware
Spark Firewall 1900 and 2000
Spark Firewall 1900 and 2000 security appliances deliver enterprise-grade security in simple, affordable, all-in-one security solutions in a 1U Rack Unit (RU) form factor to protect mid-size business employees.
The two appliances offer the same amount of network ports (the difference is only in their Threat Prevention performance throughput). The appliances feature four 10GbE fiber ports as well as 18 x 1GbE and 2 x 2.5GbE copper ports.
Both the 1900 and the 2000 support Flexi-Port (each LAN port can be used as a WAN port).
What's New
- Network Interfaces:
- LAN: 16x1GbE, 2x2.5GbE, 4x10GbE SFP+
- LANX: 4x10Gbe SFP+ (can be assigned as internet connection)
- WAN: 1x1GbE / SFP port
- DMZ: 1x1GbE / SFP port
- Console Ports:
- USB Type-C console
- RJ45
- Dual USB 3.0 Ports
- SD Card Slot
- SSD Storage
- Power Redundancy
- Fan Cooled
- Operating Temperature - 0-40 degree Celsius
Software
The Spark Firewall 1900 and 2000 Security Gateways run the Gaia Embedded OS, which is aligned to the R81.10 version. As such, they are fast and easy to install. You can set them up in minutes using pre-defined security policies and a step-by-step configuration wizard, or by using Zero Touch Deployment, which enables managed service providers to provision security efficiently for small and medium-size businesses.
Comprehensive Protection
- Next Generation Firewall
- Site-to-Site VPN
- Remote Access VPN
- Application Control and Web Filtering
- Intrusion Prevention
- Anti-Virus
- Anti-Bot
- Anti-Spam
- SandBlast Threat Emulation (sandboxing)
- Device Recognition
- Remote Access Two-Factor Authentication;
- Email Inspection
- Updatable objects
Management
Spark Firewall 1900 and 2000 Security Gateways are conveniently managed locally via a Web interface (offering simple and intuitive management and configuration), and centrally by Cloud-hosted Spark Firewall Management service which can scale to manage over 10,000 Check Point Spark Firewall Appliances.
You can also manage these Gateways centrally by Check Point on-premises central management solutions: Security Management Server, Multi-Domain Security Management Server, and Provisioning (SmartLSM profiles). You can manage 1900 / 2000 Spark Firewall Appliances with these on-premises Management Servers:
- R81.20 with the R81.20 Jumbo Hotfix Accumulator, Take 43 and higher
- R81.10 with the R81.10 Jumbo Hotfix Accumulator, Take 131 and higher
Performance
| 1900 | 2000 | |
| Enterprise Testing Conditions | ||
| Threat Prevention1 | 4 Gbps | 5 Gbps |
| Next Generation Firewall2 | 8 Gbps | 10 Gbps |
| IPS Throughput | 9 Gbps | 11 Gbps |
| Firewall Throughput | 20 Gbps | 20 Gbps |
Supported Transceivers
| CP PN | CP SKU | ProLabs PN |
| 322474 | CPAC-TR-1T-C | ProLabs P/N SFP-1GB-T-CP Finisar P/N FCLF8521P2BTL-CQ |
| 326291 | CPAC-TR-10T-C | ProLabs P/N SFP-10GBASE-T-CP |
| 324871 | CPAC-1500-TR-1SX | SX-SFP-1G-I-CP |
| 324872 | CPAC-1500-TR-1LX | LX-SFP-1G-I-CP |
| 324873 | CPAC-1800-TR-10SR | SFP-1/10GB-SR-CP |
| 324914 | CPAC-1800-TR-10LR | FTLX1471D3BCV-CQ |
Software Enhancements
The 1900 and 2000 Appliances are running the latest R81.10.10 Spark Firewall firmware, increasing performance and bringing cutting edge enterprise grade security to your small and medium size business.
Locally Managed Enhancements
- New Threat Prevention blade control: Unified Threat Prevention policy, easy and intuitive to set and control
- New SSL inspection enforcement: Simultaneously support light SSL and Full SSL inspection
- Improved High Availability mechanism
- Geo Protection via updatable objects
- TLS Inspection and categorization (SNI support)
- SMP Cluster Management
- Security checkups
- Two-Factor Authentication for Remote Access VPN users using Google and Microsoft Authenticator, SMS, Email
- IoT security - Automatically identifies, maps, and assesses risk for IoT devices, Prevents unauthorized access to and from IoT assets with autonomous zero-trust profiles, threat prevention, virtual patching, and on-device run-time protection
- Smart SD-WAN to centralizes network management, improving performance and reducing costs by dynamically routing traffic over the most optimal path
- Smart Accel capabilities
- Dynamic routing configuration using the WebUI supporting OSPF, BGP, PIM
- Updatable objects and FQDN in Locally Managed mode (NAT / SSL / Threat Prevention)
- SSL inspection per device type
- New Usability and debug capabilities
- Two-Factor Authentication for admin access
Centrally Managed Enhancements
- Policy layers and sub-policy support for centrally managed mode
- Unified access policy support for centrally managed mode (Firewall, Application Control, and URL Filtering)
- Unified Threat Prevention policy (IPS, Anti-Virus, Anti-Bot, and Threat Emulation Software Blade policies)
- Acceleration of Domain Objects, Dynamic Objects, and Time Objects for centrally managed mode
- Wildcard network object in Access Control that represents a series of IP addresses that are not sequential
- Automatic SIC renewal
- SD-WAN DAIP
Centrally and Locally Managed Enhancements
- IMAPs email inspection
- POP3s email inspection
- Automatic Device recognition and discovery
- Multicore VPN and VPN acceleration
- Secured syslog
- Additional ciphers support for HTTPS Inspection
Networking Enhancements
- Link aggregation (bonding) on LAN and WAN
- Managing Bond with Cluster
- Supporting VLAN on Switch
- Alias IP
- Support for up to 200 VLANs
- Improved link monitoring
- Cluster Fast failover with dynamic routing
- Generic Routing Encapsulation tunnels (GRE)
Downloads
Refer to sk183406 - Spark Firewall Appliances R82.00.X Releases.
Documentation
Known Limitations and Resolved Issues
Refer to:
- sk178604 - Check Point R81.10.X for 1500, 1600, 1800, 1900, and 2000 appliance Known Limitations
- sk181134 - Check Point R81.10.X Resolved Issues and Enhancements
Article Properties
Access Level: General
Status: Approved
Date Created: 2024-01-27
Last Modified: 2026-05-04