Overview:
Today the enterprise gateway is more than a firewall. It is a security device presented
with an ever-increasing number of sophisticated threats. As an enterprise security
gateway it must use multiple technologies to control network access, detect
sophisticated attacks and provide additional security capabilities like data loss
prevention and protection from web-based threats. The proliferation of mobile
devices like smartphones and Tablets and new streaming, social networking and
P2P applications requires a higher connection capacity and new application control
technologies. Finally, the shift towards enterprise private and public cloud services,
in all its variations, changes the company borders and requires enhanced capacity
and additional security solutions.
Check Point's new appliances combine fast networking technologies with high
performance multi-core capabilities—providing the highest level of security without
compromising on network speeds to keep your data, network and employees secure.
Optimized for the Software Blades Architecture, each appliance is capable of running
any combination of Software Blades—providing the flexibility and the precise level of
security for any business at every network location by consolidating multiple security
technologies into a single integrated solution.
Each Check Point Appliance supports the Check Point 3D security vision of
combining policies, people and enforcement for unbeatable protection and is
optimized for enabling any combination of the following Software Blades: (1) Firewall,
(2) VPN, (3) IPS, (4) Application Control, (5) Mobile Access, (6) DLP, (7) URL Filtering,
(8) Antivirus, (9) Anti-spam, (10) Identity Awareness and (11) Advanced Networking
& Clustering.
Check Point 21400 Appliance
Leveraging its multi-core and acceleration technologies, with 2900 SecurityPower
Units, the Check Point 21400 appliance supports lightning fast firewall throughput of
up-to 100 Gbps1 and IPS throughput of more than 21 Gbps. The 21400 is designed
from the ground up for unmatched flexibility for even the most demanding enterprise
and data center network environments.
The 21400 appliance has 3 expansion slots supporting a wide range of network
options.
The 21400 standard configuration includes a twelve 1 Gigabit Ethernet
copper port card. A maximally configured 21400 provides up to 36 Gigabit
Ethernet copper or fiber ports or twelve 10 Gigabit Ethernet fiber ports.
Furthermore, the 21400 also has a slot for an optional
acceleration card that will be available in 2012. In addition to
hot-swappable redundant disk drives and power supply units,
the 21400 appliance also supports the Lights-Out-Management
(LOM) option for remote support and maintenance capabilities.
The 21400 Appliance is a highly serviceable chassis. Access
to all components is easily available from the front and the
back of the unit when mounted in the rack.
Key Features
- 2003 - 29001 SecurityPower ™
- Simple Deployment and Management
- High Availability and Serviceability
- Optimized for Software Blades Architecture
- Optimized for low latency
- High Port Density
- Maximum Security and Performance
Key Benefits
- Security of data center assets
- A modular, serviceable platform fits easily
into complex networking environments
- High availability and redundant
components eliminates down time
- Centralize control with unified security
management and LOM
- Ideal for applications that require low
latency transactions
| Gateway Software Blades |
| |
21412 |
| Firewall |
 |
| IPsec VPN |
 |
| Mobile Access
(5 users) |
 |
| Advanced Networking |
 |
| Acceleration and Clustering |
 |
| Identity Awareness |
 |
| IPS |
 |
| Application Control |
 |
| Data Loss Prevention |
 |
| URL Filtering |
 |
| Antivirus & Anti-malware |
 |
| Anti-spam & Email Security |
 |
Key Features:
SecurityPower
Until today security appliance selection has been based upon
selecting specific performance measurements for each security
function, usually under optimal lab testing conditions and using
a security policy that has one rule. Today customers can select
security appliances by their SecurityPower ratings which are
based on real-world customer traffic, multiple security functions
and a typical security policy.
SecurityPower is a new benchmark that measures the capability
and capacity of an appliance to perform multiple advanced
security functions (Software Blades) such as IPS, DLP and
Application Control in real world traffic conditions. This provides
an effective metric to better predict the current and future
behavior of appliances under security attacks and in day-to-day
operations. Customer SecurityPower Unit (SPU) requirements,
determined using the Check Point Appliance Selection Tool,
can be matched to the SPU ratings of Check Point Appliances
to select the right appliance for their specific requirements.
Integrated Security Management
The appliance can either be managed locally with its available
integrated security management or via central unified
management. Using local management, the appliance
can manage itself and one adjacent appliance for high
availability purposes.
Business Continuity, Reliability and Extensibility
The Check Point 21400 appliance delivers business continuity
and serviceability through features such as hot-swappable
redundant power supplies, hot-swappable redundant hard
disk drives (RAID), redundant fans and an advanced LOM card for
out-of-band management. Combined together, these features
ensure a greater degree of business continuity and serviceability
when these appliances are deployed in the customer's networks.
Remote Access Connectivity for Mobile Devices
The 21400 appliance arrives with mobile access connectivity
for 5 users, using the Mobile Access Blade. This license enables
secure remote access to corporate resources from a wide variety
of devices including smartphones, tablets, PCs, Mac and Linux.
Remote Platform Management and Monitoring
Lights-Out-Management is also available, providing out-of-band
remote management to remotely diagnose, start, restart and
manage the appliance from a remote location. Administrators can
also use the LOM web interface to remotely install an OS image
from an ISO file.
Product Comparison:
2012 Appliances Appliance Comparison Chart
|
| 2200
| 4200
| 4600
| 4800
| 12200
| 12400
| 12600
| 21400
| 61000
|
| |
Small-Office |
Enterprise Grade |
Data Center Grade |
Ultra-High End |
| Performance |
| SecurityPower |
114 |
114 |
374 |
623 |
738 |
1046 |
1861 |
2003/29001 |
3000 to 14600 |
| Firewall Throughput (Gbps) |
3 |
3 |
9 |
11 |
15 |
25 |
30 |
50/1001 |
Up to 200 |
| IPS Default Profile (Gbps) |
2 |
2 |
4 |
6 |
8 |
12 |
17 |
21 |
Up to 85 |
| Connections Per Second (K) |
25 |
25 |
50 |
70 |
90 |
110 |
130 |
120/3002 |
Up to 600 |
| Concurrent Sessions (M) |
1.2 |
1.2 |
1.2 |
3.52 |
3.52 |
3.52 |
3.52 |
102 |
Up to 70 |
| Performance |
| 10/100/1000Base-T/Max Ports |
6/6 |
4/8 |
8/12 |
8/16 |
8/16 |
10/26 |
14/26 |
13/37 |
NA |
| 1000Base-F SFP (MAX Ports) |
NA |
4 |
4 |
4 |
4 |
12 |
12 |
36 |
NA3 |
| 10GBase-F SFP+ (MAX Ports) |
NA |
NA |
NA |
2 |
4 |
12 |
12 |
12 |
16/323 |
| 40GBase-F MAX Ports |
NA |
NA |
NA |
NA |
NA |
NA |
NA |
NA |
43 |
| Expansion Slot |
0 |
1 |
1 |
1 |
1 |
3 |
3 |
3 |
14 |
| Additional Features |
| Software Edition |
R71.x, R75.x |
R71.x, R75.x |
R71.x, R75.x |
R71.x, R75.x |
R71.x, R75.x |
R71.x, R75.x |
R71.x, R75.x |
R71.x, R75.x |
R75.x 64 bit |
| Storage |
250 GB |
250 GB |
250 GB |
250 GB |
1+1 500 GB |
1+1 500 GB |
GB 2x500 GB RAID 1 |
GB 2x500 GB RAID 1 |
- |
| Memory / Max |
2/2 GB |
4/4 GB |
4/4 GB |
4/8 GB |
4/12 GB |
4/12 GB |
6/12 GB |
12/24 GB |
12/24 GB5 |
| LOM Card (Optional) |
NA |
NA |
NA |
Yes |
Yes |
Yes |
Yes |
Yes |
Included |
| Physical |
| Enclosure |
Desktop |
1U |
1U |
1U |
1U |
2U |
2U |
2U |
15U |
| Dimensions WxDxH (Standard) |
8.27 x 8.25 x
1.65 in. |
17.25 x 12.56 x
1.73 in. |
17.25 x 12.56 x
1.73 in. |
17.25 x 16.14 x
1.73 in. |
17.25 x 16.14 x
1.73 in. |
17.24 x 22.13 x
3.46 in. |
17.24 x 22.13 x
3.46 in. |
17 x 28 x
3.5 in. |
17.5 x 15.16 x
26.25 in. |
| Dimensions WxDxH (Metric) |
210 x 209.5 x
42 mm |
439 x 319 x
44 mm |
439 x 320 x
44 mm |
438 x 410 x
44 mm |
438 x 410 x
44 mm |
438 x 562 x
88 mm |
438 x 562 x
88 mm |
431 x 710 x
88 mm |
445 x 385 x
660 mm |
| Weight |
2kg (4.4 lbs) |
4kg (8.82 lbs) |
7.5kg (16.53 lbs) |
7.6kg (16.76 lbs) |
7.6kg (16.76 lbs) |
23.4kg (51.6 lbs) |
23.4kg (51.6 lbs) |
26kg (57.4 lbs) |
Max: 90kg
(198.4 lbs) |
| Power |
| Dual, Hot-Swappable
Power Supplies |
No |
No |
No |
Optional |
Optional |
Yes |
Yes |
Yes |
Yes6 |
| Power Input |
100-240VAC, 47-63Hz |
| Single Power Supply Rating |
100W |
100W |
250W |
275W |
275W |
300W |
400W |
910W |
1200W @ 110V,
1600W @ 220V |
| Power Consumption (Max) |
35W |
57W |
90W |
140W |
121W |
132W |
220W |
449W |
- |
| DC Option |
No |
No |
No |
No |
No |
No |
No |
No |
Yes |
1 With acceleration card in 2012
2 With software upgrade in 2012
3 Not including Security Switch Module Management Ports
4 Maximum of 256 VLANs per Interface
5 Per Security Gateway Module
6 Includes 5 AC PSUs or 2 DC PSUs
Technical Specifications:

Base Configuration
- 1 on-board 1GbE copper interface
- 12 x 1GbE copper interfaces card (for 1 of the 3 expansion slots)
- Acceleration card expansion slot 1
- 12 GB Memory
- Redundant dual hot-swappable Power Supplies
- Redundant dual hot-swappable 500GB Hard Drives
- Telescopic rails
Network Expansion Slot Options
- 12 x 10/100/1000Base-T RJ45 ports
- 12 x 1000Base-F SFP ports
- 4 x 10GBase-F SFP+ ports
Max Configuration
- Up to 37 x 10/100/1000Base-T RJ45 ports
- Up to 36 x 1000Base-F SFP ports
- Up to 12 x 10GBase-F SFP+ ports
- 24 GB RAM
- LOM card
Performance
- 2003-2900 1 SecurityPower 2
- 50 - 100 1 Gbps of firewall throughput, 1518 byte UDP
- 21 Gbps of IPS throughput Default IPS profile
- 5.5 Gbps of IPS throughput Recommended IPS profile
- 10 million concurrent connections 3
- 120,000/300,000 1 connections per second
Network Connectivity
- 1024 VLANs
- 256 VLANs per interface
- 802.3ad passive and active link aggregation
- Layer 2 (transparent) and Layer 3 (routing) mode
|
High Availability
- Active/Active - L3 mode
- Active/Passive - Transparent & L3 mode
- Session synchronization for firewall and VPN
- Session failover for routing change
- Device failure detection
- Link failure detection
Dimensions
- Enclosure: 2RU
- Standard (W x D x H): 17 x 28 x 3.5 in.
- Metric (W x D x H): 431 x 710 x 88 mm
- Weight: 26 kg (57.4 lbs.)
Power Requirements
- AC Input Voltage: 100-240V
- Frequency: 47-63Hz
- Single Power Supply Rating: 910W
- Power Consum ption Maximum: 449 W
- Maximum thermal output: 1533 BTU
Operating Environmental Conditions
- Tem perature: 32°to104°F / 0° to 40°C
- Humidity: 5%-90% (non-condensing)
Storage Conditions
- Tem perature: –4° to 158°F / –20° to 70°C
- Humidity: 5% to 95% at 60°C
Certifications
- Safety: UL, cUL
- Emissions: CE, FCC Class A
- Environmental: RoHS
|
1Available in Q1 2012
2A metric to measure appliance performance based on real world traffic given
the deployed software blades. Find the right appliance for your performance and security needs.
3 With 24GB RAM and software upgrade available in 2012
| Check Point Products |
| Check Point 21400 Appliance |
21400 Appliance with 12 Security blades
- Includes Firewall, VPN, Identity Awareness, Advanced Networking, Acceleration & Clustering, Mobile Access for 5 concurrent users, IPS, Application Control, URL Filtering, Anti-Virus & Anti-Malware, Anti-Spam & Email Security, and DLP blades. Bundled with local management for up to 2 gateways. |
#CPAP-SG21412
List Price: $115,000.00
Our Price: $89,930.00 |
|
| Software Blades Packages |
Extended Security Software Blades Package for 21400, 1 year
- Includes IPS, URL Filtering, Application Control, Anti-Malware, Email Security, and DLP blades |
CPSB-ESEC-6B-21400
Our Price: $20,000.00 |
|
DLP+ Software Blades Package for 21400, 1 year
- Includes IPS, Application Control, and DLP |
CPSB-DLPP-3B-21400
Our Price: $18,500.00 |
|
UTM+ Software Blades Package for 21400, 1 year
- Includes IPS, URL Filtering, Application Control, Anti-Malware, and Email Security blades |
CPSB-UTMP-5B-21400
Our Price: $12,500.00 |
|
Extended Threat Protection Software Blades Package for 21400, 1 year
- Includes Application Control and IPS blades |
CPSB-ETPR-2B-21400
Our Price: $8,000.00 |
|
Web Control Software Blades Package for 1 year for 21400, 1 year
- Includes Application Control and URL Filtering blades |
CPSB-WBCL-2B-21400
Our Price: $8,000.00 |
|
| Software blades |
Mobile Access Blade
for unlimited concurrent connections |
CPSB-MOB-U
Our Price: $9,000.00 |
|
Data Loss Prevention Blade, 1 year
or 1,500 users and above, up to 250,000 mails per hour and max throughput of 2.5 Gbps |
CPSB-DLP-U
Our Price: $12,000.00 |
|
| IPS blade, 1 year |
CPSB-IPS-L
Our Price: $4,500.00 |
|
| Application Control blade, 1 year |
CPSB-APCL-L
Our Price: $4,500.00 |
|
| URL Filtering blade, 1 year |
CPSB-URLF-L
Our Price: $4,500.00 |
|
| Anti-Virus & Anti-Malware Blade, 1 year |
CPSB-AV
Our Price: $1,500.00 |
|
| Anti-Spam & Email Security Blade, 1 year |
CPSB-ASPM
Our Price: $1,500.00 |
|
| Check Point Accessories |
| Accessories - Miscellaneous |
| Lights out Management interface card for 21400 appliance |
CPAC-LOM-21000-INSTALL
Our Price: $2,500.00 |
|
| 12GB RAM Memory upgrade for 21400 appliance |
CPAC-12-1C-21000-INSTALL
Our Price: $2,500.00 |
|
| Accessories - Interface cards & Transceivers |
| 4 Port 10/100/100 Base-T RJ45 interface card |
CPAC-4-1C-INSTALL
Our Price: $2,500.00 |
|
| 8 Port 10/100/100 Base-T RJ45 interface card |
CPAC-8-1C-INSTALL
Our Price: $6,000.00 |
|
4 Port 1000Base-F SFP interface card
Requires additional 1000Base SFP transceiver modules per interface port. |
CPAC-4-1F-INSTALL
Our Price: $3,600.00 |
|
SFP transceiver for 1G fiber ports
long range (1000Base-LX) for CPAC-4-1F |
CPAC-TR-1LX
Our Price: $1,000.00 |
|
SFP transceiver for 1G fiber ports
short range (1000Base-SX) for CPAC-4-1F |
CPAC-TR-1SX
Our Price: $500.00 |
|
2 Port 10GBase-F SFP+ interface card
Requires an additional 10GBase SFP+ transceiver per interface port. |
CPAC-2-10F-INSTALL
Our Price: $10,000.00 |
|
4 Port 10GBase-F SFP+ interface card
Requires an additional 10GBase SFP+ transceiver per interface port. |
CPAC-4-10F-INSTALL
Our Price: $19,000.00 |
|
SFP+ transceiver for 10G fiber ports
long range (10GBase-LR) for CPAC-2-10F, CPAC-4-10F-INSTALL |
CPAC-TR-10LR
Our Price: $2,500.00 |
|
SFP+ transceiver for 10G fiber ports
short range (10GBase-SR) for CPAC-2-10F, CPAC-4-10F |
CPAC-TR-10SR
Our Price: $1,000.00 |
|
| Accessories - Spare parts |
Replacement parts kit for 21400 appliance
Includes 1 Hard Disk Drive, and one Power Supply |
CPAC-SPARES-21400
Our Price: $5,000.00 |
|
| Replacement AC Power Supply for 21400 appliance |
CPAC-PSU-21000
Our Price: $2,000.00 |
|
| Replacement 500G Hard Disk Drive for 21400 appliance |
CPAC-HDD-500G-21000
Our Price: $2,000.00 |
|