Overview:
Check Point Quantum Spark security gateways are high performance, integrated devices offering firewall, VPN, antivirus, application visibility and control, URL filtering, email security and SandBlast ZeroDay Protection, all in compact form factors that are simple to configure and manage.
Full Protection for Small and Midsize Businesses
The Check Point Quantum Spark 1600 and 1800 security gateways deliver enterprise-grade security in simple, affordable, all-inone security solutions in a 1 Rack Unit (RU) form factor to protect small to mid-size business employees, networks and data from cyber-theft. High threat prevention throughput and high port capacity with 2.5 and 10 GbE network interfaces in the 1800 make these NGFWs ideal for larger branch and SMB networks.

Protection from Every Threat

Easy to Deploy and Manage

All-in-One Solution
Advanced security, uncompromising performance
The Check Point Quantum Spark 1600 and 1800 security gateways deliver enterprise-grade security in simple, affordable, all-in-one security solutions in a 1 Rack Unit (RU) form factor to protect small to mid-size business employees, networks, and data from cyber-theft. High threat prevention throughput and high port capacity with 2.5 and 10 GbE network interfaces in the 1800 make these NGFWs ideal for larger branch and SMB networks.
Features:
Comprehensive Protection
The 1800 series applianced provide comprehensive protection for any small office environment:
- Next Generation Firewall
- Site-to-Site VPN
- Remote Access VPN
- Application Control and Web Filtering
- IoT Device Recognition
- Intrusion Prevention
- Antivirus
- Anti-Bot
- Anti-Spam
- SandBlast Threat Emulation (sandboxing)
R80 Software for SMB Appliances
R80 software for SMB increases performance and brings enterprise-grade security to small and medium size businesses. Centrally managed SMB gateways support:
- Unified access policy: firewall, application control, URLF
- Policy layers and sub-policies
- Acceleration of Domain, Dynamic and Time objects
- Multicore VPN and VPN acceleration
1/2.5/5/10 GbE Network Connectivity
The 1800 has 1GbE copper or fiber options for the WAN and DMZ. The 1800 has a 1GbE Management port, 2.5GbE options for the LAN and a 10GbE copper or fiber option for the DMZ.
|
1600 |
1800 |
| LAN |
N 16x 1GbE copper |
16x 1GbE copper plus 2x 2.5GbE copper |
| DMZ |
1x 1GbE copper/fiber |
1x 10GbE copper/fiber |
| WAN |
1x 1GbE copper/fiber |
2x 1GbE copper/fiber |
| MGMT |
|
1x 1GbE copper |
Cloud Management
An intuitive web-based user interface, enables service providers to provision security efficiently for small and medium-size businesses. In addition a cloud-hosted Security Management Portal scales to manage over 10,000 Check Point Quantum Spark Gateways. SMBs can leave security to a service provider so they can focus on growing their own business.
Simple, Intuitive Monitoring and Reporting
The web interface shows logs, active computers, and hourly, daily, weekly and monthly reports. In network analysis find top applications and users consuming the most bandwidth. Security analysis shows users visiting high-risk sites and using high-risk applications. Also see any incidents or infected hosts found during the reporting period.
Security Management App
The intuitive mobile app provides real-time monitoring of network events, alerts you when your network is at risk, enables you to quickly block security threats, and configure the security policy for multiple gateways.
- Network security snapshot: view connected devices and any threats
- Real-time security alerts: of attacks or unauthorized devices
- On-the-spot threat mitigation: quickly block infected devices
- Network statistic reports and charts: gain insights on network usage patterns
- Manage multiple gateways: manage security in the palm of your hand
Specifications:

| Enterprise Testing Conditions |
| Threat Prevention1 |
2,000 Mbps |
| Next Generation Firewall2 |
5,000 Mbps |
| IPS Throughput |
5,500 Mbps |
| Firewall Throughput |
7,500 Mbps |
| RFC 3511, 2544, 2647, 1242 Performance (LAB) |
| Firewall 1518 Byte UDP Packetss |
17,000 Mbps |
| VPN AES-128 Throughput |
4,000 Mbps |
| Connections per Second |
66,000 |
| Concurennt Connections |
2,400,000 |
| Software |
| Security |
Firewall, VPN, User Awareness, QoS, Application Control, URL Filtering, IPS, Anti-Bot, Antivirus, Anti-Spam and SandBlast Threat Emulation (sandboxing) |
| Unicast, Multicast Routing |
OSPFv2, BGPv4 and 4++, RIP, IGMP |
| Mobile Access License (Users) |
500 remote SNX or Mobile VPN client users |
| Hardware |
| WAN Port |
2x 10/100/1000Base-T RJ-45 / 1000BaseF SFP ports (transceiver not included) *WAN2 support in future SW release |
| DMZ Port |
1x 10GbE Base-T RJ-45 / 10GbE SFP+ (transceiver not included) |
| LAN Switch Ports |
2x 2.5GbE Base-T RJ-45 plus 16x 10/100/1000Base-T RJ-45 ports |
| Management Ports |
1x 10/100/1000Base-T RJ-45 port *MGMT support in future SW release |
| Console Ports |
1x USB-C and 1x RJ-45 console port |
| USB Port |
2x USB 3.0 ports |
| Storage |
256 GB SSD and Micro-SD slot with 32 and 64 GB card options |
| eMMC |
32 GB |
| MTBF |
15.64 years @ 25ºC |
| Dimensions |
| Enclosure |
1U |
| Dimensions (W x D x H) |
430 x 300 x 44.2 mm (16.93 x 11.8 x 1.74 in.) |
| Weight |
6.76 kg (14.9 lbs.) |
| Environment |
| Operating / Storage |
0ºC ~ 40ºC / -45ºC ~ 60ºC (5~95%, non-condensing) |
| Power Requirements |
| AC Input |
110 – 240VAC, 50 – 60 Hz |
| Power Supply Rating |
two redundant 150W power supplies |
| Power Consumption (Max) |
93.6W |
| Heat Dissipation |
319.3 |
| Certifications |
| Safety | Emissions | Environment |
UL/c-UL 62368-1 , IEC 62368-1 CB / EMC, EMI EN55024, EN55032 Class B, VCCI, AS, NZS CISPR 32, IC ICES 03, FCC: Part 15 Class B / RoHS, REACH, WEEE |
1 Includes Firewall, Application Control, URL Filtering, IPS, Antivirus, Anti-Bot, SandBlast Zero-Day Protection with logging.
2 Includes Firewall, Application Control, IPS with logging.
Subscription Services:
| Service |
Services Highlights |
Next-Gen Firewall (NGFW): segment networks and apply zero trust policy with IPS |
- Accept, prevent, schedule, and apply traffic-shaping based controls to application traffic
- 10,000+ pre-defined apps or customize your own application
- Protect vulnerable systems with 12,000+ IPS protections
|
Next-Gen Threat Prevention (NGTP): AI Deep Learning DNS security with antivirus and anti-bot prevents threats |
- DNS security prevents Command & Control (C2) connections and blocks data theft through DNS tunneling
- Antivirus stops incoming malicious files and links in web, email, FTP and SMB content
- Anti-Bot detects infected hosts and prevents communications with external C2 servers
- Apply web and application control using 100+ categories or customize your own
|
SandBlast (SNBT): comprehensive, multi-layered defense with sandboxing protection from unknown and zero-day threats |
- Average emulation time for unknown files that require full sandbox evaluation is under 100 seconds
- CPU-level, OS-level and static file analysis
- Maximal file size for Emulation is 15MB
|
IoT Network Protection: simple, effective, autonomous discovery and protection of IoT devices in minutes |
- Passive and active discovery of enterprise IoT devices with autonomous mapping to 200+ profiles
- IoT attributes include function, manufacturer, model, risk, confidence, VLAN, IP and MAC address
- Automatically creates and applies an inline zero-trust IoT policy layer
|
SD-WAN: reliable and optimum network connectivity at the lowest cost |
- Link aggregation and link prioritization according to latency, jitter, and packet loss
- Advanced multi-path orchestration and steering for 10,000+ apps
- Sub-second failover for overlay and supported applications
- SLA monitoring and autonomous link swapping
|
|
NGFW |
NGTP |
SNBT |
| Security Appliance (wired, Wi-Fi or Wi-Fi with xDSL or embedded LTE) |
|
|
|
| Premium Support (24x7 response, software upgrades and more) |
|
|
|
| PRO Support option (proactive health monitoring service) |
|
|
|
| Firewall |
|
|
|
| VPN |
|
|
|
| Mobile Access (includes 100 concurrent users in the 1530, 1550, or 200 in the 1570, 1590) |
|
|
|
| Application Control |
|
|
|
| Intrusion Prevention System |
|
|
|
| URL Filtering |
|
|
|
| Antivirus and Anti-Bot |
|
|
|
| Treat Emulation (sandboxing) |
|
|
|
| IoT Network protection for SMBs* |
|
|
|
| SD-WAN network optimization for SMBs* |
|
|
|
| IoT network protection for enterprises** |
Optional |
Optional |
Optional |
| SD-WAN network optimization for enterprises** |
Optional |
Optional |
Optional |
Optional security capabilities can be ordered a-la-carte or separately
* Starting from release R81.10.10. and supported on Web UI and Spark Management only
** Supported on Smart-1 only