Check Point VPN-1 Virtual Edition Bundle
Total Security for Virtual Systems

| Check Point Product | ||
|---|---|---|
| Check Point VPN-1 Power VSX Multi-core for up to 2 cores | ||
| Check Point VPN-1 Power VSX Multi-core for up to 2 cores 10 Gateways | #CPPWR-VSX-U2-10 Our Price: $23,999.95 |
|
| Check Point VPN-1 Power VSX Multi-core for up to 2 cores 25 Gateways | #CPPWR-VSX-U2-25 Our Price: $49,999.95 |
|
| Check Point VPN-1 Power VSX Multi-core for up to 8 cores | ||
| Check Point VPN-1 Power VSX Multi-core for up to 8 cores 10 Gateways | #CPPWR-VSX-U8-10 Our Price: $29,999.95 |
|
| Check Point VPN-1 Power VSX Multi-core for up to 8 cores 25 Gateways | #CPPWR-VSX-U8-25 Our Price: $64,999.95 |
|
| Check Point VPN-1 Power VSX Multi-core for up to 8 cores 50 Gateways | #CPPWR-VSX-U8-50 Our Price: $109,999.95 |
|
| Check Point VPN-1 Power VSX Multi-core for up to 8 cores 100 Gateways | #CPPWR-VSX-U8-100 Our Price: $199,999.95 |
|
| Check Point VPN-1 Power VSX Multi-core for up to 8 cores 250 Gateways | #CPPWR-VSX-U8-250 Our Price: $409,999.95 |
|
Click here to jump to more pricing!
Check Point VPN-1 Power VSX Overview:
VPN-1® Power VSX™ is a virtualized security gateway that allows virtualized enterprises to create up to 250 virtual systems—firewall, VPN, and intrusion prevention functionality within a virtual network environment—on a single hardware platform.
Your Challenge:Our Solution:There is a growing need within large enterprises to extend networks, applications, and corporate databases to employees, business partners, and other guest users. This need has resulted in large, complex networks that are hard to manage and secure. At the same time, many administrators are starting to divide their infrastructure among various departments and groups using virtual LANs (VLANs). Although VLAN technology is effective at functionally dividing these networks, companies are still required to deploy separate firewall, VPN, and intrusion prevention devices in front of each network segment to achieve comprehensive security. This is expensive and creates a large, complex management overhead.
VPN-1® Power VSX™ is a high-speed, multipolicy virtualized security solution designed for large-scale enterprise environments like data centers and campus networks. Based on the proven security of VPN-1 Power, VPN-1 Power VSX provides comprehensive protection to multiple networks or VLANs within complex infrastructures, securely connects them to shared resources like the Internet and DMZs, and allows each of them to interact with each other safely, while providing centralized management. The VPN-1 Power VSX gateway enables organizations to create an advanced, virtual network of routers, switches, and VPN-1 gateways utilizing a single piece of hardware. This reduces the hardware investment and physical space needed to achieve security across the entire network by replacing and consolidating physical security and network devices. Only VPN-1 Power VSX provides a platform for highly scalable, virtualized network and security services that is easy to deploy and manage.
VPN-1 Power VSX is supported by SmartDefense™ Services, which maintain the most current preemptive security of the Check Point security infrastructure. To help you stay ahead of new threats and attacks, SmartDefense Services provide real-time updates and configuration advisories for defenses and security policies.
Features & Benefits:
Product Features
- Virtualized security, including firewall, VPN, and intrusion prevention
- Virtualized network environment
- Support for virtual systems in bridge mode to create transparent firewalls
- Clustering and wire-speed security for gigabit networks
- Minimizes hardware investment
- Improves management efficiency
- Provides carrier-class availability and scalability
- Reduces physical space requirements
- Protects against new threats through SmartDefense Services
Scalable Virtualized Architecture:
VPN-1 Power VSX is composed of multiple virtualized security systems, each of which is a complete virtualized version of the market-leading VPN-1 gateway. Multiple virtual systems may be associated with a single physical interface on the gateway but remain completely separated from other virtual systems, maintaining a completely secure and private network environment. Up to 250 virtual systems can be deployed on a single VPN-1 Power VSX installation, providing a highly scalable virtual platform while reducing incremental hardware investment and space requirements.

VPN-1 Power VSX is a high-speed virtualized security solution designed for large-scale virtualized environments like campus networks.
Additional Capabilities:
Virtualized network connectivity
VPN-1 Power VSX supports the creation of virtualized
network components including routers, switches, cables,
and routing protocols, providing complete control of
the setup and configuration of the virtual network environment.
With access to a virtualized network environment, administrators
can create virtualized implementations of familiar physical
topologies and designs. In addition, VPN-1 Power VSX
has the ability to host virtual systems running in either
router or bridge mode. The ability to deploy virtual
systems in bridge mode allows administrators to seamlessly
add a virtual system to the network without reconfiguring
network settings and topologies.
Wire-speed security
High-bandwidth networks require high-performance gate-ways
in order to support thousands of applications and users.
To provide world-class security at wire speed, VPN-1
Power VSX can be deployed on multiple carrier-class
platforms using Check Point’s SecureXL™ performance
technology, ensuring the delivery of secure, multigigabit
throughput.
Nonstop security
Check Point’s ClusterXL® technology enables virtualized
enterprises to configure VPN-1 Power VSX for nonstop
security. As with clustering on a physical system, VPN-1
Power VSX clustering connects and synchronizes two or
more VPN-1 Power VSX gateways so that if one fails another
one immediately takes over its networking and security
responsibilities. VPN-1 Power VSX provides seamless
failover of connections and routing from one cluster
member to another. It also includes graceful failover
of VPN-1 Power VSX gateways in a dynamically routed
environment to minimize network disruption. In bridge
mode, individual virtual systems can failover to their
virtual peers within the cluster. This level of high
availability and resiliency promotes network-wide, nonstop,
secure business operations at both the application and
network levels.

A cluster of VPN-1 Power VSX gateways delivers nonstop, wire-speed security.
Unparalleled protection
Enabling security for a wide range of network demands,
VPN-1 Power VSX supports more than 150 predefined applications,
services, and protocols out-of-the-box, as well as instant
messaging, peer-to-peer applications, and VoIP.
In addition, VPN-1 Power VSX includes the same proven Check Point security technologies utilized in VPN-1 Power including Application Intelligence™ and SmartDefense , along with the ability to receive constant updates and protections from emerging threats with SmartDefense Services.
Secure remote access
Every enterprise has a unique blend of requirements
for remote access, depending on its types of users,
the mix of applications to be accessed, and the level
of endpoint security and management control demanded.
With the integrated VPN features of VPN-1 Power, VPN-1
Power VSX provides flexibility, supporting multiple
client options. Its SecuRemote feature provides basic
connectivity that is easy for the user requiring occasional
remote access to IP applications. And VPN-1 Power VSX’s
SecureClient™ functionality provides a higher level
of security by adding a centrally managed personal firewall.
These capabilities allow secure remote access to be made an integrated part of the overall security policy in a VLAN environment. All elements of the security policy, including access control, attack protection, and user authentication, are strictly enforced, ensuring the highest levels of security down to the remote user level.

A VPN-1 Power VSX gateway uses virtual systems to protect multiple VLANs.
Easy, Efficient, Centralized Enterprise Management:
VPN-1 Power VSX is managed with Check Point’s SmartCenter™ and Provider-1® management solutions. Both provide powerful tools for centrally configuring, managing, and monitoring multiple VPN-1 Power VSX gateways, virtual systems, and physical VPN-1 gateways. Based on Check Point’s Security Management Architecture (SMART), these solutions deliver the flexibility of choosing the appropriate management solution based on their network requirements. Check Point’s One-Click VPN technology also enables virtual systems to be added seamlessly to a VPN community. The new virtual system automatically inherits the appropriate properties and can immediately establish secure sessions with all other VPN community members within the enterprise network. Additional tools such as virtual system creation wizards and templates further streamline the process of deploying and configuring VPN-1 Power VSX.
VPN-1 Power VSX provides administrative controls that maximize the efficiency of its hardware platform. Resource controls ensure that the consumption of CPU resources by each virtual system is optimal for overall network security. They can limit the CPU time available to a lower-priority virtual system and assign more capacity to mission-critical virtual systems.
Lightweight Quality of Service enforcement provides the ability to assign optimal transmission characteristics to different classes of traffic. This reduces the need to build out costly network infrastructure while minimizing any congestion at the VPN-1 Power VSX gateway.
Flexible Policy Segmentation:
An enterprise can use virtual systems to segment different business groups and classify the network either by service and function or by network segment. Therefore, administrators can maintain separate policies for different network segments and can divide large rulebases into several smaller rulebases for ease of management and better control of network security.
In an enterprise or campus deployment, a VPN-1 Power VSX gateway or cluster can be installed between VLAN switches, aggregating traffic to and from multiple subnets and the main enterprise/campus Internet link. A separate virtual system— providing access control, logging, and SmartDefense Services—protects each subnet. VPN-1 Power VSX also enables secure connectivity between subnets.
Specifications:
| Firewall: | |
| Protocol/Application support | Secures more than 200 applications and protocols |
| VoIP Protection | Sip, H.323, MGCP, and SIP with NAT support |
| Instant Messaging Control | MSN, Yahoo, ICQ, and Skype (including over HTTP and SSL) |
| Peer-to-peer Blocking | Kazaa, GNUTella, BitTorrent, eMule, IRC (including over HTTP) |
| Network Address Translation | Static/hide NAT support with manual or automatic rules |
| VPN | |
| Encryption Support | AES 128-256 bit, 3DES 56-168 bit |
| Authentication Methods | Password, RADIUS, TACACS, X.509, SecurID |
| Certificate Authority | Integrated X.509 certificate authority |
| VPN communities | Automatically sets up site-to-site connections as objects are created |
| Topology Support | Star and mesh |
| VPN Routing | Link selection for gateways with dynamically allocated IP addresses, generic route encapsulation (GRE) support, wire mode VPN |
| VPN Client | Check Point Endpoint Security, VPN-1 SecureClient, VPN-1 SecuRemote |
| SSL-based remote access | Fully integrated SSL VPN gateway provides on-demand SSL-based access |
| SSL-based endpoint scanning | Scans endpoint for compliance/malware prior to admission to the network |
| Site-to-site VPN | Explicit multiple entry point (MEP) configuration support |
| VPN tunnel management | VPN links can be configured to be "always" on |
| Intrusion Prevention | |
| Network-layer protection | Blocks attacks such as DoS, Port Scanning, IP/ICMP/TCP related |
| Application-layer protection | Blocks attacks such as DNS cache poisoning, FTP bounce, improper commands and more |
| Detection Methods | Signature-based and protocol anomaly |
| Networking | |
| Virtualization | Complete virtualization of all networking components such as virtual routers & switches |
| VLAN interfaces | 4096 per cluster |
| Dynamic Routing Support | OSPF, BGP, RIP v1/2,Multicast in multiple virtual system mode |
| DHCP Support | SecurePlatform™ DHCP server and Relay |
| Layer-2 bridge support | Transparently integrates into existing network |
| ISP Redundancy | Protocol-based, source/destination and port route decisions |
| Performance and Availability | |
| Failover recovery | Active/standby bridge mode for instantaneous failover |
| Load balancing | VSLS (virtual system load balancing) to distribute VS load across cluster members |
| Quality of Service | Support for Differentiated Services for outbound and inbound traffic |
| ISP Redundancy | Automatically reroutes traffic to second interface |
| Traffic Acceleration | SecureXL accelerates security decisions |
| Management | |
| Policy segregation | Virtual and logical grouping of customers, global and customer specific security and VPN policies* |
| Centralized management | Logging, monitoring, event correlation, reporting, security updates, VPN and large-scale policy management and management high availability |
| Role-based administration | Global and granular administrative access and permissions, multiple simultaneous administrator access* |
| Log management | Automatic log maintenance and consolidation |
| Hardware Specifications: | |
| Platforms | Check Point SecurePlatform™, Crossbeam X Series, IBM BladeCenter (firewall module only), Nokia IPSO |
| Processor Disk space Memory Network interfaces |
Intel Pentium II 1GHz-plus or equivalent
processor 4 GB 256 MB Three minimum (four for a VPN-1 Power VSX cluster) |
| SmartDashboard platforms Disk space Memory |
Windows 2000/2003/XP/ME/98 100 MB 256 MB |
| Provider-1 platforms Disk space Memory |
SecurePlatform™, Linux, Solaris 800 MB; 50MB for each CMA 256 MB |
| Remote access client
platforms Disk space Memory |
Windows 2000/XP/2003, Macintosh, Linux 20 MB 64 MB |
Documentation:
![]()
Download the Check Point VPN-1 Power VSX Enterprise Datasheet (PDF).
![]()
Download the Check Point VPN-1 Power VSX Enterprise Providers
Datasheet (PDF).
- VPN – IPSec Remote Access, Site-to-Site VPN and SSL VPN included
- SmartDefense - Integrated Intrusion Prevention updates (IPS) with update service – optional
- SmartDefense Total Security – Integrated IPS, Anti-Virus, Web (URL) filtering and 6 dimensional protections Messaging Security, all with update services – optional
| Check Point Product | ||
|---|---|---|
| Check Point VPN-1 Power VSX Multi-core for up to 2 cores | ||
| Check Point VPN-1 Power VSX Multi-core for up to 2 cores 10 Gateways | #CPPWR-VSX-U2-10 Our Price: $23,999.95 |
|
| Check Point VPN-1 Power VSX Multi-core for up to 2 cores 25 Gateways | #CPPWR-VSX-U2-25 Our Price: $49,999.95 |
|
| Check Point VPN-1 Power VSX Multi-core for up to 8 cores | ||
| Check Point VPN-1 Power VSX Multi-core for up to 8 cores 10 Gateways | #CPPWR-VSX-U8-10 Our Price: $29,999.95 |
|
| Check Point VPN-1 Power VSX Multi-core for up to 8 cores 25 Gateways | #CPPWR-VSX-U8-25 Our Price: $64,999.95 |
|
| Check Point VPN-1 Power VSX Multi-core for up to 8 cores 50 Gateways | #CPPWR-VSX-U8-50 Our Price: $109,999.95 |
|
| Check Point VPN-1 Power VSX Multi-core for up to 8 cores 100 Gateways | #CPPWR-VSX-U8-100 Our Price: $199,999.95 |
|
| Check Point VPN-1 Power VSX Multi-core for up to 8 cores 250 Gateways | #CPPWR-VSX-U8-250 Our Price: $409,999.95 |
|
| VPN-1 Power VSX Multi-core for up to 2 cores for High Availability and Load Sharing | ||
| Secondary VPN-1 Power VSX Multi-core for up to 2 cores 10 Gateways for High Availability | #CPPWR-VSX-U2-HA-10 Our Price: $19,199.95 |
|
| Secondary VPN-1 Power VSX Multi-core for up to 2 cores 25 Gateways for High Availability | #CPPWR-VSX-U2-HA-25 Our Price: $39,999.95 |
|
| VPN-1 Power VSX Multi-core for up to 8 cores for High Availability and Load Sharing | ||
| Secondary VPN-1 Power VSX Multi-core for up to 8 cores 10 Gateways, HA | #CPPWR-VSX-U8-HA-10 Our Price: $23,999.95 |
|
| Secondary VPN-1 Power VSX Multi-core for up to 8 cores 25 Gateways, HA | #CPPWR-VSX-U8-HA-25 Our Price: $51,999.95 |
|
| Secondary VPN-1 Power VSX Multi-core for up to 8 cores 50 Gateways, HA | #CPPWR-VSX-U8-HA-50 Our Price: $87,999.95 |
|
| Secondary VPN-1 Power VSX Multi-core for up to 8 cores 100 Gateways, HA | #CPPWR-VSX-U8-HA-100 Our Price: $159,999.95 |
|
| Secondary VPN-1 Power VSX Multi-core for up to 8 cores 250 Gateways, HA | #CPPWR-VSX-U8-HA-250 Our Price: $327,999.95 |
|
| VPN-1 Power VSX Multi-core for up to 2 cores - an additional (third, fourth and beyond) cluster member for load sharing | ||
| Additional VPN-1 Power VSX Multi-core for up to 2 cores 10 Gateways for Load sharing | #CPPWR-VSX-U2-VSLS-10 Our Price: $4,799.95 |
|
| Secondary VPN-1 Power VSX Multi-core for up to 8 cores 25 Gateways, HA | #CPPWR-VSX-U2-VSLS-25 Our Price: $9,999.95 |
|
| VPN-1 Power VSX Multi-core for up to 8 cores - an additional (third, fourth and beyond) cluster member for load sharing | ||
| Additional VPN-1 Power VSX Multi-core for up to 8 cores 10 Gateways for Load sharing | #CPPWR-VSX-U8-VSLS-10 Our Price: $5,999.95 |
|
| Additional VPN-1 Power VSX Multi-core for up to 8 cores 25 Gateways for Load sharing | #CPPWR-VSX-U8-VSLS-25 Our Price: $12,999.95 |
|
| Additional VPN-1 Power VSX Multi-core for up to 8 cores 50 Gateways for Load sharing | #CPPWR-VSX-U8-VSLS-50 Our Price: $21,999.95 |
|
| Additional VPN-1 Power VSX Multi-core for up to 8 cores 100 Gateways for Load sharing | #CPPWR-VSX-U8-VSLS-100 Our Price: $39,999.95 |
|
| Additional VPN-1 Power VSX Multi-core for up to 8 cores 250 Gateways for Load sharing | #CPPWR-VSX-U8-VSLS-250 Our Price: $81,999.95 |
|
| Check Point SmartDefense Services for VPN-1 Power VSX | ||
| Check Point SmartDefense Services for VPN-1 Power VSX 10 Gateways Annual Subscription | #CPPWR-SMDF-VSX-10 Our Price: $4,499.95 |
|
| Check Point SmartDefense Services for VPN-1 Power VSX 25 Gateways Annual Subscription | #CPPWR-SMDF-VSX-25 Our Price: $8,999.95 |
|
| Check Point SmartDefense Services for VPN-1 Power VSX 50 Gateways Annual Subscription | #CPPWR-SMDF-VSX-50 Our Price: $14,499.95 |
|
| Check Point SmartDefense Services for VPN-1 Power VSX 100 Gateways Annual Subscription | #CPPWR-SMDF-VSX-100 Our Price: $23, 999.95 |
|
| Check Point SmartDefense Services for VPN-1 Power VSX 250 Gateways Annual Subscription | #CPPWR-SMDF-VSX-250 Our Price: $44,999.95 |
|
| Check Point Professional Services Jump Start/ Upgrade Package | ||
| 5 Days Jump Start package to be used with the following products: Provider-1, VSX, VSX/Crossbeam, GX, FW-1/VPN-1, Endpoint Full Disk Encryption, Media Encryption under 5000 seats | #CPTS-PRO-5D-JS Our Price: $9,999.95 |
|
*All VPN-1 VE licenses can be used only on VMware ESX or ESXi servers. VPN-1 VE Unlimited licenses are designed to utilize up to 4 virtual cores.
