Overview:
Check Point Quantum Spark security gateways are high performance, integrated devices offering firewall, VPN, antivirus, application visibility and control, URL filtering, email security and SandBlast ZeroDay Protection, all in compact form factors that are simple to configure and manage.
Industry’s best security used by the world’s largest enterprises, tailored to protect your SMB from cyberattacks
Quantum Spark 1900 and 2000 NGFWs are fast, high port density firewalls with integrated AI ML security to prevent new and novel threats. Integrated capabilities like SD-WAN and IoT security provide faster Internet connectivity, application performance, proven security, and maximum uptime with management made easy via an intuitive web interface.
AI-Powered advanced security, uncompromising performance
Spark 1900 and 2000 security gateways deliver enterprise-grade security in simple, affordable, all-inone security solutions in a 1 Rack Unit (RU) form factor to protect small to mid-size business employees, networks, and data from cyber-theft. High threat prevention throughput and high port capacity with 18x1GbE, 2x2.5GbE and 4x10GbE network interfaces make these gateways ideal for larger branch and SMB networks..
Features:
Comprehensive, Industry-Leading Security
- Next Generation Firewall
- Site-to-Site, Remote Access VPN
- Application Control and Web Filtering
- Intrusion Prevention
- Antivirus and Anti-Bot
- Anti-Spam Email Security
- SandBlast Threat Emulation (sandboxing)
- Integrated SD-WAN network optimization
Part of the Quantum Cyber Security Family
R81 software for SMB increases performance and brings enterprise-grade security to small and midsized businesses. Centrally managed SMB gateways support:
- Unified access policy: firewall, application control, URLF
- Policy layers and sub-policies
- Acceleration of domain, dynamic and time objects
- Multicore VPN and VPN acceleration
- Smart Accel 30% performance improvement of low risk,
high bandwidth apps
High Port Capacity for Large SMB Networks
The 1900 and 2000 have a 18 1GbE coppper LAN switch, ideal for segmenting multiple networks by department or function. Two copper 2.5GbE ports and four fiber 10GbE SFP+ LAN ports are also available. In addition, the 1GbE copper or fiber WAN and DMZ ports offer connection flexibility. The DMZ can also be used as a second WAN port.
Security Management App
The intuitive mobile app provides real-time monitoring of network events, alerts you when your network is at risk, enables you to quickly block security threats, and configure the security policy for multiple gateways.
- Network security snapshot: view connected devices and any threats
- Real-time security alerts: of attacks or unauthorized devices
- On-the-spot threat mitigation: quickly block infected devices
- Network statistic reports and charts: gain insights on network usage patterns
- Manage multiple gateways: manage security in the palm of your hand
Specifications:
Enterprise Testing Conditions |
Threat Prevention1 |
4 Gbps |
Next Generation Firewall2 |
8 Gbps |
IPS Throughput |
9 Gbps |
Firewall Throughput |
20 Mbps |
RFC 3511, 2544, 2647, 1242 Performance (LAB) |
Firewall 1518 Byte UDP Packets |
40 Gbps |
VPN AES-128 Throughput |
5 Gbps |
Connections per Second |
90,000 |
Concurennt Connections |
4,200,000 |
Software |
Security |
Firewall, VPN, User Aware, QoS, Application Control, URLF, IPS, Anti-Bot, Antivirus, Anti-Spam, sandboxing |
Unicast, Multicast Routing |
OSPFv2, BGPv4 and 4++, RIP, PIM (SM, DM, SSM), IGMP, ClusterXL High Availability |
IPv6 |
local network and internet connections, dual stack tunneling IPv4 over IPv6 networks, prefix delegation |
Mobile Access License (Users) |
1000 remote SNX or Mobile VPN client users |
Hardware |
WAN Port |
1x 10/100/1000Base-T RJ-45 port |
DMZ Port |
1x 10/100/1000Base-T RJ-45 port |
LAN 1 GbE and 2.5 GbE copper Ports |
2x 2.5GbE Base-T RJ-45 plus 16x 10/100/1000Base-T RJ-45 ports |
LAN 10 GbE fiber Ports |
4x10GbE SFP+ ports |
Console Ports |
1x USB-C or RJ45 |
USB Port |
2x USB 3.0 |
Memory |
16 GB DDR |
Storage |
512 GB SSD and Micro-SD slot with 32 and 64 GB card options |
Dimensions |
Enclosure |
1U |
Dimensions (W x D x H) |
432 x 300 x 44 mm (16.93 x 11.8 x 1.74 in.) |
Weight |
6.76 kg (14.9 lbs.) |
Environment |
Operating / Storage |
0ºC ~ 40ºC / -45ºC ~ 60ºC (5~95%, non-condensing) |
Power Requirements |
AC Input |
110 – 240VAC, 50 – 60 Hz |
Power Supply Rating |
two redundant 150W power supplies |
Power Consumption (Max) |
93.6W |
Heat Dissipation |
319.3 BTU/hr. |
Certifications |
Safety | Emissions | Environment |
UL/c-UL 62368-1 , IEC 62368-1 CB / EMC, EMI EN55024, EN55032 Class B, VCCI, AS, NZS CISPR 32, IC ICES 03, FCC: Part 15 Class B / RoHS, REACH, WEEE |
1 Includes Firewall, Application Control, URL Filtering, IPS, Antivirus, Anti-Bot, SandBlast Zero-Day Protection with logging.
2 Includes Firewall, Application Control, IPS with logging.
Subscription Services:
Service |
Services Highlights |
Next-Gen Firewall (NGFW):
segment networks and apply zero trust policy with IPS |
- Accept, prevent, schedule, and apply traffic-shaping based controls to application traffic
- 10,000+ pre-defined apps or customize your own application
- Protect vulnerable systems with 12,000+ IPS protections
|
Next-Gen Threat Prevention (NGTP):
AI Deep Learning DNS security with antivirus and anti-bot prevents threats |
- DNS security prevents Command & Control (C2) connections and blocks data theft through DNS tunneling
- Antivirus stops incoming malicious files and links in web, email, FTP and SMB content
- Anti-Bot detects infected hosts and prevents communications with external C2 servers
- Apply web and application control using 100+ categories or customize your own
|
SandBlast (SNBT):
comprehensive, multi-layered defense with sandboxing protection from unknown and zero-day threats |
- Average emulation time for unknown files that require full sandbox evaluation is under 100 seconds
- CPU-level, OS-level and static file analysis
- Maximal file size for Emulation is 15MB
|
IoT Network Protection:
simple, effective, autonomous discovery and protection of IoT devices in minutes |
- Passive and active discovery of enterprise IoT devices with autonomous mapping to 200+ profiles
- IoT attributes include function, manufacturer, model, risk, confidence, VLAN, IP and MAC address
- Automatically creates and applies an inline zero-trust IoT policy layer
|
SD-WAN:
reliable and optimum network connectivity at the lowest cost |
- Link aggregation and link prioritization according to latency, jitter, and packet loss
- Advanced multi-path orchestration and steering for 10,000+ apps
- Sub-second failover for overlay and supported applications
- SLA monitoring and autonomous link swapping
|
|
NGFW |
NGTP |
SNBT |
Security Appliance (wired, Wi-Fi or Wi-Fi with xDSL or embedded LTE) |
|
|
|
Premium Support (24x7 response, software upgrades and more) |
|
|
|
PRO Support option (proactive health monitoring service) |
|
|
|
Firewall |
|
|
|
VPN |
|
|
|
Mobile Access (includes 500 concurrent users in the 1900, 2000) |
|
|
|
Identity Awareness |
|
|
|
Application Control |
|
|
|
Intrusion Prevention System |
|
|
|
SD-WAN Network Optimization Services for Web UI/SMP |
|
|
|
URL Filtering |
|
|
|
Antivirus and Anti-Bot |
|
|
|
Anti-Spam and Email Security |
|
|
|
DNS Security |
|
|
|
Treat Emulation (sandboxing) |
|
|
|
IoT Network Protection Services for Web UI/SMP |
|
|
|
IoT Network protection for SMBs* |
|
|
|
SD-WAN network optimization for SMBs* |
|
|
|
IoT network protection for enterprises** |
Optional |
Optional |
Optional |
SD-WAN network optimization for enterprises** |
Optional |
Optional |
Optional |
Optional security capabilities can be ordered a-la-carte or separately
* Starting from release R81.10.10. and supported on Web UI and Spark Management only
** Supported on Smart-1 only