Call a Specialist Today! 888-785-4407

Checkpoint VSX 12600 Series
Virtualized Security Gateway

Checkpoint VSX 12600 Series

Sorry, this unit has been discontinued. Please, contact us for a replacement product!

Click here to jump to more pricing!

Checkpoint VSX Overview:

The Check Point 12600 VSX Appliance is a dedicated solution for multi-layer, multi-domain virtualized security for multi-layer, multi-domain virtualized security. Check Point 12600 VSX Appliances provides organizations with maximum security in high-performance environments such as large campuses or data centers. They allow enterprises, data centers and service providers to consolidate up to 150 security gateways with firewall, IPsec and SSL virtual private network (VPN), intrusion prevention and URL filtering on a single device. The VSX bundle offering provides linear performance scalability with system high availability. Note: These products are based on NGX architecture.

Check Point VSX and VPN-1 Power VSX enable organizations to consolidate infrastructure in high-performance environments, such as large campuses or data centers, by virtualizing physical network components into one physical device. They include firewall, Virtual Private Network (VPN), URL filtering and intrusion prevention technology (IPS).

VSX Benefits:

Hardware cost savings and comprehensive security via a virtual platform:

  • Consolidate hundreds of security gateways into one physical device
  • Includes firewall, IPS, URL filtering, IPSec and SSL VPN
  • Increased hardware utilization and reduced power, space and cooling

Simplified management and flexible deployment:

  • Service multiple customers, groups and business units from a single system
  • Centralized management unifies both physical and virtual management
  • Flexible deployment—open platforms and full line of turnkey appliances

High availability and easy scalability:

  • Easily add and extend virtual systems without purchasing more hardware
  • Delivers linear scalability, load sharing and multi-gigabit performance
  • Cost-efficiency, redundancy and performance via ClusterXL and SecureXL

Features:

Scalable Virtual Environment

With VSX—deployed as VSX Software or VSX turnkey appliances—administrators can create virtualized implementations of conventional physical topologies and designs such as central and remote DMZs. The Virtual System Extension (VSX) platform can create and manage up to 250 fully independent security systems on a single or clustered hardware platform. This delivers scalability while dramatically reducing hardware investment, space requirements and maintenance costs.

Flexible Virtual Connectivity

Virtual routers and switches can be used to forward traffic between networks located behind virtual systems, much in the same manner as their physical counterparts. VSX supports a wide range of routing scenarios, enabling flexible network connectivity.

  • Virtual System in Bridge Mode - VSX has the ability to host virtual systems running in either router or bridge mode. The ability to deploy virtual systems in bridge mode allows administrators to implement native layer-2 bridging instead of IP routing, and transparently add a virtual system to the network without reconfiguring network settings and topologies.
  • Route Propagation - When a virtual system is connected to a virtual router or to a virtual switch, an administrator can choose to propagate its routing information to adjacent virtual devices. This feature enables network nodes located behind neighboring virtual systems to communicate without the need for manual configuration.
  • Overlapping IP Address Space - VSX facilitates connectivity when multiple network segments share the same IP address range. This scenario occurs when a single VSX gateway protects several independent networks that assign IP addresses to endpoints from the same pool of IP addresses. Thus, more than one endpoint in a VSX environment may share the same IP address, provided that each is located behind different virtual systems. Overlapping IP address space in VSX environments is possible because each virtual system maintains its own unique state and routing tables. These tables can contain identical entries, but within different, segregated contexts.
  • Source-based Routing - Source-based routing allows an administrator to define routing definitions that take precedence over ordinary, destination-based, routing decisions. This allows the administrator to route packets according to their source IP address or a combination of their source IP address and destination IP address. Source-based routing is useful in deployments where a single physical interface without VLAN tagging connects several protected customer networks. Each virtual system is connected to an internal virtual router. The virtual router routes traffic to the appropriate virtual system based on the source IP address, as defined in source-based routing tables.
  • Dynamic Routing - Virtual devices can communicate and distribute routes amongst themselves using dynamic routing. VSX provides full layer-3 dynamic routing for virtual systems and virtual routers. The following unicast and multicast dynamic routing protocols are supported: OSPF, RIP-v1/2, BGP-v4, IGMP, PIM-SM, PIM-DM.

High Performance Security

High bandwidth networks require high-performance gateways in order to support thousands of users and applications. VSX employs Check Point-patented SecureXL™ security acceleration, enabling maximum performance from open servers and appliances. To provide security at wire speed, VSX can be deployed on multiple carrier-class platforms using Check Point high-performance technology, ensuring secure, resilient, multi-gigabit throughput. And to maximize performance, capacity and system scalability, VSX provides the following features and technologies:

  • Virtual System Load Sharing (VSLS) provides the ability to distribute virtual systems across cluster members, effectively distributing traffic load within a cluster.
  • VSX Resource Control allows administrators to manage the processing load by guaranteeing that each virtual system will receive its minimum CPU allocation. Resources not needed by one virtual system are automatically made available to other virtual systems. Administrators can also limit the CPU time available to a lower-priority virtual system and assign more capacity to mission-critical virtual systems.
  • VSX QoS Enforcement provides the ability to control network quality of service in the VSX network environment by supporting the Differentiated Services (DiffServ) protocol and assigning different transmission characteristics to different classes of service. This helps prioritize the order in which traffic will be processed when resources are under heavy load.
  • ClusterXL provides high availability and load sharing to keep businesses running. It distributes traffic between clusters of redundant gateways so that the computing capacity of multiple machines may be combined to increase total throughput. If an individual gateway becomes unreachable, all connections are redirected to a designated backup without interruption.
  • Link Aggregation, also known as interface bonding, is a powerful feature that provides support for bonding interfaces either in a high-availability or load sharing mode. This networking technology binds multiple physical interfaces together in parallel to increase throughput beyond the limits of a single interface and/or to provide redundancy.

Comprehensive Security Services

Based on FireWall-1 and SmartDefense intrusion prevention technologies, VSX provides comprehensive protection to multiple networks or VLANs within complex infrastructures, securely connecting them to shared resources like the Internet and DMZs. VSX gateways are based on Check Point-patented Stateful Inspection, the de facto standard for Internet security. VSX examines more than 150 predefined applications, services, and protocols out-of-the-box, ensuring that the vast majority of applications used by businesses are free of threats when entering the network. Examples include:

  • URL Filtering: Protects users or restricts access from an array of continually updated pre-profiled content
  • Voice over IP: With many companies rushing to adopt VoIP applications to lower telecommunications costs, VSX offers comprehensive VoIP protocol support to secure critical business communications. VoIP protocols supported include H.323, SIP, MGCP and Skinny (SCCP).
  • Instant messaging and P2P applications: These are common attack vectors for worms, viruses, and spyware. VSX provides security for these applications by inspecting their content or preventing them from entering the corporate network

VSX is supported by SmartDefense Services, which maintain the most current preemptive security for the Check Point security infrastructure. VSX also provides flexibility in secure remote access, supporting the most complete range of client access options (IPSec, SSL VPN, mobile access)

Proven, Mature Security Management Architecture

VSX is managed with Check Point's SmartCenter and Multi-Domain Security Management solutions. Both provide powerful tools for centrally configuring, managing, and monitoring multiple VSX security operations platforms, virtual systems, and physical VPN-1 gateways. VSX appliances feature hardware health monitoring capabilities over SNMP.

Based on Check Point Security Management Architecture (SMART), these solutions deliver the flexibility of choosing the appropriate management solution based on your network requirements. Check Point One-Click VPN technology also enables virtual systems to be added seamlessly to a VPN community. The new virtual system automatically inherits the appropriate properties and can immediately establish secure sessions with all other VPN community members within the enterprise network. Additional tools such as virtual system creation wizards and templates assist in enforcing server image standardization and further streamline the process of deploying and configuring VSX.

Used in conjunction with Multi-Domain Security Management, an enterprise can use VSX to segment different business groups or customers and classify the network either by function or by network segment. Therefore, administrators can maintain separate policies for different network segments and can delegate or divide large rule-bases into several smaller rule-bases for ease-of-management and better control of network security.

Service Provider Enablement

VSX delivers security service provisioning at the click of a button, enabling service providers to monetize virtual security service offerings at the lowest possible cost. Capabilities now include new URL filtering capability which protects users or restricts access from an array of profiled content. This adds to the best-in-class security services already available.

Specifications:

Checkpoint VSX 12600 Series Specifications

VSX Appliance Hardware Specifications: 12000 Series
Models: VSX 12200
Single Unit
VSX 12200
VSLS
VSX 12400
Single Unit
VSX 12400
VSLS
VSX 12600
Single Unit
VSX 12600
VSLS
Performance
Firewall Throughput (Gbps) 15 20 25 45 30 50
VPN Throughput (Gbps) 2.5 5 3.5 6 6 11
Concurrent Sessions (Millions) 1.2 1.6 1.2 1.6 1.2 1.6
Network
10/100/1000Base-T Port / (max) 8/16 16/32 10/26 20/52 14/26 28/52
1000Base-F SFP (Max Ports) 4 8 12 24 12 24
10GBase-F SFP+ (Max Ports) 4 8 12 24 12 24
Expansion Slot 1 2 3 6 3 6
VLANs 4096 4096 4096 4096 4096 4096
Additional Features
Software Edition VSX R67 VSX R67 VSX R67 VSX R67 VSX R67 VSX R67
Storage 1 + 1 500 GB 2 x 1 + 1 500 GB 1 + 1 500 GB 2 x 1 + 1 500 GB 2 x 500 GB RAID 1 2 x 2 x 500 GB RAID 1
Memory / Max 4 / 12 GB 2 x 4 / 12 GB 4 / 12 GB 2 x 4 / 12 GB 6 / 12 GB 2 x 6 / 12 GB
LOM Card Included Included Included Included Included Included
Virtual Systems (Included/Capacity) 5/10 5/10 10/50 10/50 10/150 10/150
Physical
Enclosure 1U 2U 2U 4U 2U 4U
Dimensions WxDxH (Standard) 17.25 x 16.14 x 1.73 in. 17.25 x 16.14 x 3.46 in. 17.25 x 22.13 x 3.46 in. 17.25 x 22.13 x 6.92 in. 17.24 x 22.13 x 3.46 in. 17.25 x 22.13 x 6.92 in.
Dimensions WxDxH (Metric) 438 x 410 x 44mm 438 x 410 x 88mm 438 x 562 x 88mm 438 x 562 x 176mm 438 x 562 x 88mm 438 x 562 x 176mm
Weight 7.6kg (16.76 lbs) 15.2kg (33.52 lbs) 23.4kg (51.6 lbs) 46.8kg (103.2 lbs) 23.4kg (51.6 lbs) 46.8kg (103.2 lbs)
Power
Dual, hot-swappable power supplies Optional Optional Yes Yes Yes Yes
Power Input 100~240V, 47~63Hz
Single Power Supply Rating 275W 275W 300W 300W 400W 400W
Power Consumption (Max) 121W 2 x 121W 132W 2 x 132W 220W 2 x 220W

 

VSX Appliance Hardware Specifications: 21000 Series
Models: VSX 21400
Single Unit
VSX 21400
VSLS
Performance
Firewall Throughput (Gbps) 50 85
VPN Throughput (Gbps) 7 12
Concurrent Sessions (Millions) 1.2 1.6
Network
10/100/1000Base-T Port / (max) 13/37 26/74
1000Base-F SFP (Max Ports) 12 24
10GBase-F SFP+ (Max Ports) 12 24
Expansion Slot 3 6
VLANs 4096 4096
Additional Features
Software Edition VSX R67 VSX R67
Storage 2 x 500 GB RAID 1 2 x 2 x 500 GB RAID 1
Memory / Max 4 / 12 GB 2 x 4 / 12 GB
LOM Card Included Included
Virtual Systems (Included/Capacity) 10/250 10/250
Physical
Enclosure 2U 4U
Dimensions WxDxH (Standard) 17 x 28 x 3.5 in. 17 x 28 x 7 in.
Dimensions WxDxH (Metric) 431 x 710 x 88mm 431 x 710 x 176mm
Weight 26kg (57.4 lbs) 52kg (114.8 lbs)
Power
Dual, hot-swappable power supplies Yes Yes
Power Input 100~240V, 47~63Hz
Single Power Supply Rating 910W 910W
Power Consumption (Max) 449W 2 x 449W

 

VSX Appliance Hardware Specifications: 3070 - VSX 11280 Series
Models: VSX-1 3070
Single Unit
VSX-1 9070
Single Unit
VSX-1 9090
VSLS
VSX-1 11060/070/080 Single Unit VSX-1 11260/270/280 VSLS
Performance
Firewall Throughput (Gbps) 4.6 14 28 15/20/25 30/40/50
VPN Throughput (Gbps) 1.0 3.6

7.2

3.7/4.0/4.5 7.4/8.0/9.0
Concurrent Sessions (Millions) 1 1.1 1.6 1.2 1.6
Network
10/100/1000Base-T Port / (max) 10 14 28 14 28
1000Base-F SFP (Max Ports) N/A 8 16 8 16
10GBase-F SFP+ (Max Ports) N/A 4 8 4 8
Expansion Slot N/A 2 4 2 4
VLANs 4096 4096 4096 4096 4096
Additional Features
Software Edition VSX R67 VSX R67 VSX R67 VSX R67 VSX R67
Storage 160 GB 2 x 160 GB 4 x 160 GB 2 x 250 GB 4 x 250 GB
LOM Card Included Included Included Included Included
Virtual Systems (Included/Capacity) 5/10 10/150 10/150 10/250 10/250
Physical
Enclosure 1U 2U 4U 2U 4U
Dimensions WxDxH (Standard) 17.4 x 15 x 1.73 in. 17 x 20 x 3.46 in. 17 x 20 x 7 in. 17 x 20 x 3.46 in. 17 x 20 x 7 in.
Dimensions WxDxH (Metric) 443 x 381 x 44mm 431 x 509.5 x 88mm 431 x 509.5 x 176mm 431 x 509.5 x 88mm 431 x 509.5 x 176mm
Weight 6.5kg (14.3 lbs) 16.5kg (36.3 lbs) 33kg (72.6 lbs) 23.4kg (51.6 lbs) 46.8kg (103.2 lbs)
Power
Dual, hot-swappable power supplies No Yes Yes Yes Yes
Power Input 100/240V, 50/60Hz
Single Power Supply Rating 250W 400W 400W 500W 500W
Power Consumption (Max) 78W 201W 2 x 201W 253W 2 x 253W

 

VSX Appliance Pricing Notes:

Check Point VSX Series
Total Security Services for VSX Appliances
Total Security Services for VSX appliances for 10 VSs
#CPPWR-SDTS-VSX-APP-10
Our Price: $13,900.00
Total Security Services for VSX appliances for additional 20 VSs
#CPPWR-SDTS-VSX-APP-ADD-20
Our Price: $13,500.00
Total Security Services for VSX appliances for 5 VSs
#CPPWR-SDTS-VSX-APP-5
Our Price: $8,000.00
SmartDefense Services for VSX Appliances
SmartDefense Services for VSX appliances for 10 VSs
#CPPWR-SMDF-VSX-APP-10
Our Price: $2,575.00
SmartDefense Services for VSX appliances for additional 20 VSs
#CPPWR-SMDF-VSX-APP-ADD-20
Our Price: $2,500.00
SmartDefense Services for VSX appliances for 5 VSs
#CPPWR-SMDF-VSX-APP-5
Our Price: $1,500.00
URL Filtering Services for VSX Appliances
URL Filtering Services for VSX appliances for 10 VSs
#CPPWR-URLF-VSX-APP-10
Our Price: $12,855.00
URL Filtering Services for VSX appliances for additional 20 VSs
#CPPWR-URLF-VSX-APP-ADD-20
Our Price: $12,855.00
URL Filtering Services for VSX appliances for 5 VSs
#CPPWR-URLF-VSX-APP-5
Our Price: $7,700.00
Smart Defense Services for VSX Appliances
Smart Defense Services for VPN-1 Power VSX 10 Gateways Annual Subscription
#CPPWR-SMDF-VSX-10
Our Price: $4,600.00
Smart Defense Services for VPN-1 Power VSX 25 Gateways Annual Subscription
#CPPWR-SMDF-VSX-25
Our Price: $9,250.00
Smart Defense Services for VPN-1 Power VSX 50 Gateways Annual Subscription
#CPPWR-SMDF-VSX-50
Our Price: $14,900.00
Smart Defense Services for VPN-1 Power VSX 100 Gateways Annual Subscription
#CPPWR-SMDF-VSX-100
Our Price: $24,700.00
Smart Defense Services for VPN-1 Power VSX 250 Gateways Annual Subscription
#CPPWR-SMDF-VSX-250
Our Price: $46,350.00