SlideShare a Scribd company logo
©2017 Check Point Software Technologies Ltd. All rights reserved. [Protected] Non-confidential content | January 23, 2017 | Page 1
Check Point 5100 Security Gateway | Datasheet
CHECK POINT
5100 NEXT GENERATION SECURITY GATEWAY
FOR THE SMALL ENTERPRISE AND BRANCH OFFICE
CHECK POINT 5100 NEXT
GENERATION SECURITY
GATEWAY
Small enterprise and branch
office security
Product Benefits
 High performance protection against
the most advanced cyber attacks
 Unique “first time prevention” for the
most sophisticated zero day attack
 Optimized for inspecting SSL
encrypted traffic
 Future-proofed technology
safeguards against tomorrow’s risks
 Centralized control and LOM
improves serviceability
 Modular, expandable chassis with
flexible I/O options
Product Features
 Simple deployment and management
 Secure remote access to corporate
resources from a wide variety of
devices
 One network expansion slot to add
port density, fiber and fail-open IO
card options
 Redundant clustering technologies
eliminate a single point of failure
OVERVIEW
The Check Point 5100 Next Generation Security Gateway combines the most
comprehensive security protections to safeguard your small enterprise and branch
office deployments. The 5100 delivers high performance and port modularity for higher
port capacity. This powerful Next Generation Security Gateway is optimized to deliver
threat prevention for your enterprise or branch offices against present and future
threats to secure your critical assets and environments.
COMPREHENSIVE THREAT PREVENTION
Check Point delivers fully integrated, comprehensive Threat Prevention with award-
winning SandBlast™ Threat Emulation and Threat Extraction for complete protection
against the most sophisticated threats and zero-day vulnerabilities.
Unlike traditional solutions that are subject to evasion techniques, introduce
unacceptable delays, or let potential threats through while evaluating files, Check
Point SandBlast stops more malware from entering your network. Our solution enables
your employees to work safely - no matter where they are and without compromising
their productivity.
PERFORMANCE HIGHLIGHTS
Firewall IPS NGFW
1
Threat Prevention
2
14.5 Gbps 2.45 Gbps 2.2 Gbps 450 Mbps
Performance measured under ideal testing conditions. Additional performance details on page 4.
1. Includes Firewall, Application Control, and IPS Software Blades.
2. Includes Firewall, Application Control, URL Filtering, IPS, Antivirus, Anti-Bot and SandBlast Zero-Day Protection Software
Blades.
©2017 Check Point Software Technologies Ltd. All rights reserved. [Protected] Non-confidential content | January 23, 2017 | Page 2
Check Point 5100 Security Gateway | Datasheet
ALL-INCLUSIVE SECURITY SOLUTIONS
Check Point 5100 Next Generation Security Gateways offer a
complete and consolidated security solution available in two
complete packages:
 NGTP: prevent sophisticated cyber-threats with
Application Control, URL Filtering, IPS, Antivirus,
Anti-Bot and Email Security.
 NGTX: NGTP with SandBlast Zero-Day Protection,
which includes Threat Emulation and Threat
Extraction.
PREVENT KNOWN AND ZERO-DAY THREATS
The 5100 Next Generation Security Gateway protects
organizations from both known and unknown threats with
Antivirus, Anti-Bot, SandBlast Threat Emulation
(sandboxing), and SandBlast Threat Extraction technologies.
As part of the Check Point SandBlast Zero-Day Protection
solution, the cloud-based Threat Emulation engine detects
malware at the exploit phase, even before hackers can apply
evasion techniques attempting to bypass the sandbox. Files
are quickly quarantined and inspected, running in a virtual
sandbox to discover malicious behavior before it enters your
network. This innovative solution combines cloud-based
CPU-level inspection and OS-level sandboxing to prevent
infection from the most dangerous exploits, and zero-day and
targeted attacks.
Furthermore, SandBlast Threat Extraction removes
exploitable content, including active content and embedded
objects, reconstructs files to eliminate potential threats, and
promptly delivers sanitized content to users to maintain
business flow.
NGTP
NGTX
(SandBlast)
Prevent known
threats
Prevent known
and zero-day
attacks
Firewall  
VPN (IPsec)  
IPS  
Application Control  
URL Filtering  
Anti-Bot  
Anti-Virus  
Anti-Spam  
SandBlast Threat Emulation  
SandBlast Threat Extraction  
INSPECT ENCRYPTED CONNECTIONS
There is a shift towards more use of HTTPS, SSL and TLS
encryption to increase Internet security. At the same time
files delivered into the organization over SSL and TLS
represent a stealthy attack vector that bypasses traditional
security implementations. Check Point Threat Prevention
looks inside encrypted SSL and TLS tunnels to detect
threats, ensuring users remain in compliance with company
policies while surfing the Internet and using corporate data.
INCLUSIVE HIGH PERFORMANCE PACKAGE
Customers with high connection capacity requirements can
purchase the affordable High Performance Package (HPP).
This includes the base system plus one 4x 1Gb SFP
interface card, transceivers and Lights-Out-Management.
Base HPP Max
1 GbE ports (Copper) 6 6 14
1 GbE ports (Fiber) 0 4 4
Transceivers (SR) 0 4 4
RAM 8GB 8GB 16GB
Power Supply Units 1 1 1
Lights Out Management Optional Included Included
REMOTE MANAGEMENT AND MONITORING
An optional Lights-Out-Management (LOM) card provides
out-of-band remote management to remotely diagnose, start,
restart and manage the Next Generation Security Gateway
from a remote location. Administrators can also use the LOM
web interface to remotely install an OS image from an ISO
file.
SECURE REMOTE ACCESS
Each Check Point Next Generation Security Gateway is
configured with mobile access connectivity for up to 5 users,
using the Mobile Access Blade. This license provides secure
remote access to corporate resources from a wide variety of
devices including smartphones, tablets, PCs, Mac and Linux.
INTEGRATED SECURITY MANAGEMENT
Every Check Point appliance can either be managed locally
with its available integrated security management or via
central unified management. Using local management, the
appliance can manage itself and one adjacent appliance for
high availability deployments.
©2017 Check Point Software Technologies Ltd. All rights reserved. [Protected] Non-confidential content | January 23, 2017 | Page 3
Check Point 5100 Security Gateway | Datasheet
ORDERING INFORMATION
BASE CONFIGURATION 1
5100 Next Generation Security Gateway base configuration, includes 6x1GbE copper ports, 8GB RAM, 1
HDD, 1 AC power unit, Next Generation Threat Prevention (NGTP) security subscription package for 1
year.
CPAP-SG5100-NGTP
5100 SandBlast Next Generation Security Gateway base configuration, includes 6x1GbE copper ports,
8GB RAM, 1 HDD, 1 AC power unit, SandBlast (NGTX) security subscription package for 1 year
CPAP-SG5100-NGTX
HIGH PERFORMANCE PACKAGES 1
5100 Next Generation Security Gateway with High Performance Package, includes 6x1GbE copper ports,
4x1Gb SFP ports, 4 SR transceivers, 16 GB RAM, 1 HDD, 1 AC power unit, Lights Out Management
(LOM), Next Generation Threat Prevention (NGTP) security subscription package for 1 year
CPAP-SG5100-NGTP-HPP
5100 Next Generation Security Gateway with High Performance Package, includes 6x1GbE copper ports,
4x1Gb SFP ports, 4 SR transceivers, 16 GB RAM, 1 HDD, 1 AC power unit, Next Generation Threat
Extraction (SandBlast) security subscription package for 1 year
CPAP-SG5100-NGTX-HPP
1
SKUs for 2 and 3 years, for High Availability and Appliances with an SSD option are also available, see the online Product Catalog
ACCESSORIES
INTERFACE CARDS AND TRANSCEIVERS
8 Port 10/100/1000 Base-T RJ45 interface card CPAC-8-1C-B
4 Port 1000Base-F SFP interface card; requires additional 1000Base SFP transceivers CPAC-4-1F-B
SFP transceiver module for 1G fiber ports - long range (1000Base-LX) CPAC-TR-1LX-B
SFP transceiver module for 1G fiber ports - short range (1000Base-SX) CPAC-TR-1SX-B
SFP transceiver to 1000 Base-T RJ45 (Copper) CPAC-TR-1T-B
4 Port 1GE copper Bypass (Fail-Open) network interface card (10/100/1000 Base-T) CPAC-4-1C-BP-B
SPARES AND MISCELLANEOUS
Memory upgrade kit from 8GB to 16GB for 5100 appliance CPAC-RAM8GB-5000
Lights Out Management module CPAC-LOM-B
Slide rails for 5000 Appliances (22” - 32”) CPAC-RAIL-5000
Extended slide rails for 5000 Appliances (26” - 36”) CPAC-RAIL-EXT-5000
5100 SECURITY GATEWAY
Management 10/100/1000Base-T RJ45 port
RJ45/micro USB console port
One network card expansion slot
5x 10/100/1000Base-T RJ45 ports
2x USB ports for ISO installation
Lights-Out Management port
3
1 2
5
1
2
3
4
5
6
4
2
6
©2017 Check Point Software Technologies Ltd. All rights reserved. [Protected] Non-confidential content | January 23, 2017 | Page 4
Check Point 5100 Security Gateway | Datasheet
Performance
Ideal Testing Conditions
 14.5 Gbps of UDP 1518 byte packet firewall throughput
 2.45 Gbps IPS
 2.2 Gbps of NGFW
1
 450 Mbps of Threat Prevention
2
 1.6 Gbps of AES-128 VPN throughput
 110,000 connections per second, 64 byte response
 3.2/6.4M concurrent connections (base/HPP memory), 64
byte response
3
Real-World Production Conditions
 340 SecurityPower Units
 4.2 Gbps of firewall throughput
 730 Mbps IPS
 450 Mbps of NGFW
1
 200 Mbps of Threat Prevention
2
Your performance may vary depending on different factors.
Visit www.checkpoint.com/partnerlocator to find an appliance
that matches your unique requirements.
1. Includes Firewall, Application Control and IPS Software Blades. 2. Includes Firewall, Application
Control, URL Filtering, IPS, Antivirus, Anti-Bot and SandBlast Zero-Day Protection Software
Blades. 3. Performance measured with default/maximum memory.
Expansion Options
Base Configuration
 6 on-board 10/100/1000Base-T RJ-45 ports
 8 GB memory (16 GB option)
 1 power supply
 1x 500GB (HDD) or 1x 240GB (SSD) drive
 Fixed rails (slide rail option)
 (Lights-Out-Management (LOM) option)
Network Expansion Slot Options (1 slot available)
 8x 10/100/1000Base-T RJ45 port card, up to 14 ports
 4x 1000Base-F SFP port card, up to 4 ports
Fail-Open/Bypass Network Options
 4x 10/100/1000Base-T RJ45 port card
Network
Network Connectivity
 Total physical and virtual (VLAN) interfaces per gateway:
1024/4096 (single gateway/with virtual systems)
 802.3ad passive and active link aggregation
 Layer 2 (transparent) and Layer 3 (routing) mode
High Availability
 Active/Active and Active/Passive - L3 mode
 Session failover for routing change, device and link failure
 ClusterXL or VRRP
IPv6
 NAT66, NAT64
 CoreXL, SecureXL, HA with VRRPv3
Routing
Unicast and Multicast Routing (see SK98226)
 OSPFv2 and v3, BGP, RIP
 Static routes, Multicast routes
 Policy-based routing
 PIM-SM, PIM-SSM, PIM-DM, IGMP v2, and v3
Physical
Power Requirements
 Single Power Supply rating: 250W
 AC power input: 90-264V, (47-63Hz)
 Power consumption maximum: 62.9W
 Maximum thermal output: 214.6 BTU/hr.
Dimensions
 Enclosure: 1RU
 Dimensions (W x D x H): 17.2x16x1.73 in.(438x406.5x44mm)
 Weight: 13.7 lbs. (6.22 kg)
Environmental Conditions
 Operating: 0° to 40°C, humidity 5% to 95%
 Storage: –40° to 70°C, humidity 5% to 95% at 60°C
Certifications
 Safety: UL, CB, CE, TUV GS
 Emissions: FCC, CE, VCCI, RCM/C-Tick
 Environmental: RoHS, REACH
1
, ISO14001
1
1
factory certificate
CONTACT US
Worldwide Headquarters | 5 Ha’Solelim Street, Tel Aviv 67897, Israel | Tel: 972-3-753-4555 | Fax: 972-3-624-1100 | Email: info@checkpoint.com
U.S. Headquarters | 959 Skyway Road, Suite 300, San Carlos, CA 94070 | Tel: 800-429-4391; 650-628-2000 | Fax: 650-654-4233 | www.checkpoint.com

More Related Content

PDF
Как развернуть кампусную сеть Cisco за 10 минут? Новые технологии для автомат...
PDF
Putting Firepower Into The Next Generation Firewall
PDF
Cisco Connect Toronto 2017 - Putting Firepower into the Next Generation Firewall
PPTX
Secure Data Center Solution with FP 9300 - BDM
DOCX
Migration to cisco next generation firewall
PDF
Новая эра корпоративных сетей с Cisco Catalyst 9000 и другие инновации для ма...
PDF
Cisco Connect Toronto 2017 - Security Through The Eyes of a Hacker
PDF
Presentación - Cisco ASA with FirePOWER Services
Как развернуть кампусную сеть Cisco за 10 минут? Новые технологии для автомат...
Putting Firepower Into The Next Generation Firewall
Cisco Connect Toronto 2017 - Putting Firepower into the Next Generation Firewall
Secure Data Center Solution with FP 9300 - BDM
Migration to cisco next generation firewall
Новая эра корпоративных сетей с Cisco Catalyst 9000 и другие инновации для ма...
Cisco Connect Toronto 2017 - Security Through The Eyes of a Hacker
Presentación - Cisco ASA with FirePOWER Services

What's hot (19)

PDF
Hillstone-Corporate-Overview-EN-V3.0
PDF
FireSIGHT Management Center (FMC) slides
PDF
ASA Firepower NGFW Update and Deployment Scenarios
PDF
Deployment of cisco_iron_portweb_security_appliance
PPT
Asa sslvpn security
PDF
Cisco Connect Toronto 2017 - Model-driven Telemetry
PDF
CCNP Security-Firewall
PPTX
Vision one-customer
PDF
Brkcrt 1160 c3-rev2
PDF
Cisco Connect Vancouver 2017 - Anatomy of Attack
PDF
Meraki powered services bell
DOCX
How to use mtr 2
PDF
Cisco, Sourcefire and Lancope - Better Together
PPTX
Cisco ASA Firepower
PDF
Novosco Zero day protection webinar
PDF
Cisco Connect Toronto 2017 - Accelerating Incident Response in Organizations...
PDF
TechWiseTV Workshop: Programmable ASICs
PDF
Emerging Threats - The State of Cyber Security
PPTX
Kaspersky Kesb ep10 no_cm_v01a
Hillstone-Corporate-Overview-EN-V3.0
FireSIGHT Management Center (FMC) slides
ASA Firepower NGFW Update and Deployment Scenarios
Deployment of cisco_iron_portweb_security_appliance
Asa sslvpn security
Cisco Connect Toronto 2017 - Model-driven Telemetry
CCNP Security-Firewall
Vision one-customer
Brkcrt 1160 c3-rev2
Cisco Connect Vancouver 2017 - Anatomy of Attack
Meraki powered services bell
How to use mtr 2
Cisco, Sourcefire and Lancope - Better Together
Cisco ASA Firepower
Novosco Zero day protection webinar
Cisco Connect Toronto 2017 - Accelerating Incident Response in Organizations...
TechWiseTV Workshop: Programmable ASICs
Emerging Threats - The State of Cyber Security
Kaspersky Kesb ep10 no_cm_v01a
Ad

Viewers also liked (20)

PDF
CHECK POINT 3100 NEXT GENERATION SECURITY GATEWAY FOR THE BRANCH AND SMALL OF...
PDF
CHECK POINT 5900 NEXT GENERATION SECURITY GATEWAY FOR THE MID-SIZE ENTERPRISE
PPTX
CheckPoint Sandblast _Защита от угроз Нулевого дня
PDF
Н.Зайцев Советник по ИТ Л’Этуаль "Визуальные цифровые технологии Digital sign...
PPTX
Prostokvashino maslenitsa case for digital branding
PPTX
RTB-Media Ukraine, Cчастье Хаб 19.11
PPTX
Digital signage для логистических компаний
PDF
iBeacons для ритейла и ТРЦ
PDF
Интерактивные возможности видеорекламы и Digital Signage
PDF
Аудитория Интернета
PDF
Мобильная интернет-реклама, Mail ru Group, Mobile Maketing Day
PDF
"Нужны ли социальные сети в маркетинге ТРЦ". Презентация выступления Михаила ...
PPTX
решения для трк и трц
PDF
Как превратить посетителей ТРЦ в лояльных покупателей
 
PPSX
Сила букв: как текст объявления повышает CTR
PDF
Digital signage in a FMCG network // Grocery stores
PDF
Программатик кампании в потоковом видео
PDF
Программа лояльности для ТРЦ
PDF
Стратегия взаимодействия с потребителем на основе PROGRAMMATIC
PPT
Digital signaga общая презентация
CHECK POINT 3100 NEXT GENERATION SECURITY GATEWAY FOR THE BRANCH AND SMALL OF...
CHECK POINT 5900 NEXT GENERATION SECURITY GATEWAY FOR THE MID-SIZE ENTERPRISE
CheckPoint Sandblast _Защита от угроз Нулевого дня
Н.Зайцев Советник по ИТ Л’Этуаль "Визуальные цифровые технологии Digital sign...
Prostokvashino maslenitsa case for digital branding
RTB-Media Ukraine, Cчастье Хаб 19.11
Digital signage для логистических компаний
iBeacons для ритейла и ТРЦ
Интерактивные возможности видеорекламы и Digital Signage
Аудитория Интернета
Мобильная интернет-реклама, Mail ru Group, Mobile Maketing Day
"Нужны ли социальные сети в маркетинге ТРЦ". Презентация выступления Михаила ...
решения для трк и трц
Как превратить посетителей ТРЦ в лояльных покупателей
 
Сила букв: как текст объявления повышает CTR
Digital signage in a FMCG network // Grocery stores
Программатик кампании в потоковом видео
Программа лояльности для ТРЦ
Стратегия взаимодействия с потребителем на основе PROGRAMMATIC
Digital signaga общая презентация
Ad

Similar to CHECK POINT 5100 NEXT GENERATION SECURITY GATEWAY FOR THE SMALL ENTERPRISE AND BRANCH OFFICE (20)

PDF
SANGFOR NGAF FIREWALL SG TECHNICAL PVT LTD 03002019693
PDF
Cisco Firewall secure firewall configuration
PPTX
PA-1400-customer-presentation PowerPoint
PDF
PDF
Cisco Connect Halifax 2018 Putting firepower into the next generation firewall
PDF
Fortinet FortiGate 100D
PPT
從INTEL技術談網路卡
PDF
security-products-comparison-chart.pdf
PDF
Putting Firepower into the Next Generation Firewall
PPTX
ICC Networking Link Series unified controller solution
PPTX
ICC Networking Link Series unified controller solution
PPTX
pa-3400_customer-presentation Presentation Powerpoint
PDF
PDF
Cisco Next Generation Firewall with Firepower
PDF
Cisco connect winnipeg 2018 putting firepower into the next generation fire...
PDF
Netronome Corporate Brochure
PDF
Cisco Connect Vancouver 2017 - Putting firepower into the next generation fir...
PDF
FortiGate 1500D Series Delivers High-Performance Next-Generation Firewall
PDF
Advanced Networking: The Critical Path for HPC, Cloud, Machine Learning and more
PDF
Meraki Cloud Networking Workshop
SANGFOR NGAF FIREWALL SG TECHNICAL PVT LTD 03002019693
Cisco Firewall secure firewall configuration
PA-1400-customer-presentation PowerPoint
Cisco Connect Halifax 2018 Putting firepower into the next generation firewall
Fortinet FortiGate 100D
從INTEL技術談網路卡
security-products-comparison-chart.pdf
Putting Firepower into the Next Generation Firewall
ICC Networking Link Series unified controller solution
ICC Networking Link Series unified controller solution
pa-3400_customer-presentation Presentation Powerpoint
Cisco Next Generation Firewall with Firepower
Cisco connect winnipeg 2018 putting firepower into the next generation fire...
Netronome Corporate Brochure
Cisco Connect Vancouver 2017 - Putting firepower into the next generation fir...
FortiGate 1500D Series Delivers High-Performance Next-Generation Firewall
Advanced Networking: The Critical Path for HPC, Cloud, Machine Learning and more
Meraki Cloud Networking Workshop

More from Alexander Kravchenko (7)

PDF
Penta Security
PPTX
Check Point Infinity
PPTX
Not petya business case
PDF
CheckPoint DEMO Azerbaijan
PDF
Check point sandblast2
DOCX
Radware все продукты_ua
PDF
Penta Security
Check Point Infinity
Not petya business case
CheckPoint DEMO Azerbaijan
Check point sandblast2
Radware все продукты_ua

Recently uploaded (20)

PPTX
Entre CHtzyshshshshshshshzhhzzhhz 4MSt.pptx
PPTX
PLC ANALOGUE DONE BY KISMEC KULIM TD 5 .0
PPTX
Embeded System for Artificial intelligence 2.pptx
PPTX
DEATH AUDIT MAY 2025.pptxurjrjejektjtjyjjy
PPTX
code of ethics.pptxdvhwbssssSAssscasascc
PPTX
quadraticequations-111211090004-phpapp02.pptx
PPT
FABRICATION OF MOS FET BJT DEVICES IN NANOMETER
PPTX
Lecture-3-Computer-programming for BS InfoTech
PPTX
1.pptxsadafqefeqfeqfeffeqfqeqfeqefqfeqfqeffqe
PPTX
title _yeOPC_Poisoning_Presentation.pptx
PPTX
Syllabus Computer Six class curriculum s
PPT
Hypersensitivity Namisha1111111111-WPS.ppt
PPTX
Fundamentals of Computer.pptx Computer BSC
PPTX
5. MEASURE OF INTERIOR AND EXTERIOR- MATATAG CURRICULUM.pptx
PPTX
Prograce_Present.....ggation_Simple.pptx
PPTX
Sem-8 project ppt fortvfvmat uyyjhuj.pptx
DOCX
A PROPOSAL ON IoT climate sensor 2.docx
PPTX
material for studying about lift elevators escalation
PDF
How NGOs Save Costs with Affordable IT Rentals
PPTX
STEEL- intro-1.pptxhejwjenwnwnenemwmwmwm
Entre CHtzyshshshshshshshzhhzzhhz 4MSt.pptx
PLC ANALOGUE DONE BY KISMEC KULIM TD 5 .0
Embeded System for Artificial intelligence 2.pptx
DEATH AUDIT MAY 2025.pptxurjrjejektjtjyjjy
code of ethics.pptxdvhwbssssSAssscasascc
quadraticequations-111211090004-phpapp02.pptx
FABRICATION OF MOS FET BJT DEVICES IN NANOMETER
Lecture-3-Computer-programming for BS InfoTech
1.pptxsadafqefeqfeqfeffeqfqeqfeqefqfeqfqeffqe
title _yeOPC_Poisoning_Presentation.pptx
Syllabus Computer Six class curriculum s
Hypersensitivity Namisha1111111111-WPS.ppt
Fundamentals of Computer.pptx Computer BSC
5. MEASURE OF INTERIOR AND EXTERIOR- MATATAG CURRICULUM.pptx
Prograce_Present.....ggation_Simple.pptx
Sem-8 project ppt fortvfvmat uyyjhuj.pptx
A PROPOSAL ON IoT climate sensor 2.docx
material for studying about lift elevators escalation
How NGOs Save Costs with Affordable IT Rentals
STEEL- intro-1.pptxhejwjenwnwnenemwmwmwm

CHECK POINT 5100 NEXT GENERATION SECURITY GATEWAY FOR THE SMALL ENTERPRISE AND BRANCH OFFICE

  • 1. ©2017 Check Point Software Technologies Ltd. All rights reserved. [Protected] Non-confidential content | January 23, 2017 | Page 1 Check Point 5100 Security Gateway | Datasheet CHECK POINT 5100 NEXT GENERATION SECURITY GATEWAY FOR THE SMALL ENTERPRISE AND BRANCH OFFICE CHECK POINT 5100 NEXT GENERATION SECURITY GATEWAY Small enterprise and branch office security Product Benefits  High performance protection against the most advanced cyber attacks  Unique “first time prevention” for the most sophisticated zero day attack  Optimized for inspecting SSL encrypted traffic  Future-proofed technology safeguards against tomorrow’s risks  Centralized control and LOM improves serviceability  Modular, expandable chassis with flexible I/O options Product Features  Simple deployment and management  Secure remote access to corporate resources from a wide variety of devices  One network expansion slot to add port density, fiber and fail-open IO card options  Redundant clustering technologies eliminate a single point of failure OVERVIEW The Check Point 5100 Next Generation Security Gateway combines the most comprehensive security protections to safeguard your small enterprise and branch office deployments. The 5100 delivers high performance and port modularity for higher port capacity. This powerful Next Generation Security Gateway is optimized to deliver threat prevention for your enterprise or branch offices against present and future threats to secure your critical assets and environments. COMPREHENSIVE THREAT PREVENTION Check Point delivers fully integrated, comprehensive Threat Prevention with award- winning SandBlast™ Threat Emulation and Threat Extraction for complete protection against the most sophisticated threats and zero-day vulnerabilities. Unlike traditional solutions that are subject to evasion techniques, introduce unacceptable delays, or let potential threats through while evaluating files, Check Point SandBlast stops more malware from entering your network. Our solution enables your employees to work safely - no matter where they are and without compromising their productivity. PERFORMANCE HIGHLIGHTS Firewall IPS NGFW 1 Threat Prevention 2 14.5 Gbps 2.45 Gbps 2.2 Gbps 450 Mbps Performance measured under ideal testing conditions. Additional performance details on page 4. 1. Includes Firewall, Application Control, and IPS Software Blades. 2. Includes Firewall, Application Control, URL Filtering, IPS, Antivirus, Anti-Bot and SandBlast Zero-Day Protection Software Blades.
  • 2. ©2017 Check Point Software Technologies Ltd. All rights reserved. [Protected] Non-confidential content | January 23, 2017 | Page 2 Check Point 5100 Security Gateway | Datasheet ALL-INCLUSIVE SECURITY SOLUTIONS Check Point 5100 Next Generation Security Gateways offer a complete and consolidated security solution available in two complete packages:  NGTP: prevent sophisticated cyber-threats with Application Control, URL Filtering, IPS, Antivirus, Anti-Bot and Email Security.  NGTX: NGTP with SandBlast Zero-Day Protection, which includes Threat Emulation and Threat Extraction. PREVENT KNOWN AND ZERO-DAY THREATS The 5100 Next Generation Security Gateway protects organizations from both known and unknown threats with Antivirus, Anti-Bot, SandBlast Threat Emulation (sandboxing), and SandBlast Threat Extraction technologies. As part of the Check Point SandBlast Zero-Day Protection solution, the cloud-based Threat Emulation engine detects malware at the exploit phase, even before hackers can apply evasion techniques attempting to bypass the sandbox. Files are quickly quarantined and inspected, running in a virtual sandbox to discover malicious behavior before it enters your network. This innovative solution combines cloud-based CPU-level inspection and OS-level sandboxing to prevent infection from the most dangerous exploits, and zero-day and targeted attacks. Furthermore, SandBlast Threat Extraction removes exploitable content, including active content and embedded objects, reconstructs files to eliminate potential threats, and promptly delivers sanitized content to users to maintain business flow. NGTP NGTX (SandBlast) Prevent known threats Prevent known and zero-day attacks Firewall   VPN (IPsec)   IPS   Application Control   URL Filtering   Anti-Bot   Anti-Virus   Anti-Spam   SandBlast Threat Emulation   SandBlast Threat Extraction   INSPECT ENCRYPTED CONNECTIONS There is a shift towards more use of HTTPS, SSL and TLS encryption to increase Internet security. At the same time files delivered into the organization over SSL and TLS represent a stealthy attack vector that bypasses traditional security implementations. Check Point Threat Prevention looks inside encrypted SSL and TLS tunnels to detect threats, ensuring users remain in compliance with company policies while surfing the Internet and using corporate data. INCLUSIVE HIGH PERFORMANCE PACKAGE Customers with high connection capacity requirements can purchase the affordable High Performance Package (HPP). This includes the base system plus one 4x 1Gb SFP interface card, transceivers and Lights-Out-Management. Base HPP Max 1 GbE ports (Copper) 6 6 14 1 GbE ports (Fiber) 0 4 4 Transceivers (SR) 0 4 4 RAM 8GB 8GB 16GB Power Supply Units 1 1 1 Lights Out Management Optional Included Included REMOTE MANAGEMENT AND MONITORING An optional Lights-Out-Management (LOM) card provides out-of-band remote management to remotely diagnose, start, restart and manage the Next Generation Security Gateway from a remote location. Administrators can also use the LOM web interface to remotely install an OS image from an ISO file. SECURE REMOTE ACCESS Each Check Point Next Generation Security Gateway is configured with mobile access connectivity for up to 5 users, using the Mobile Access Blade. This license provides secure remote access to corporate resources from a wide variety of devices including smartphones, tablets, PCs, Mac and Linux. INTEGRATED SECURITY MANAGEMENT Every Check Point appliance can either be managed locally with its available integrated security management or via central unified management. Using local management, the appliance can manage itself and one adjacent appliance for high availability deployments.
  • 3. ©2017 Check Point Software Technologies Ltd. All rights reserved. [Protected] Non-confidential content | January 23, 2017 | Page 3 Check Point 5100 Security Gateway | Datasheet ORDERING INFORMATION BASE CONFIGURATION 1 5100 Next Generation Security Gateway base configuration, includes 6x1GbE copper ports, 8GB RAM, 1 HDD, 1 AC power unit, Next Generation Threat Prevention (NGTP) security subscription package for 1 year. CPAP-SG5100-NGTP 5100 SandBlast Next Generation Security Gateway base configuration, includes 6x1GbE copper ports, 8GB RAM, 1 HDD, 1 AC power unit, SandBlast (NGTX) security subscription package for 1 year CPAP-SG5100-NGTX HIGH PERFORMANCE PACKAGES 1 5100 Next Generation Security Gateway with High Performance Package, includes 6x1GbE copper ports, 4x1Gb SFP ports, 4 SR transceivers, 16 GB RAM, 1 HDD, 1 AC power unit, Lights Out Management (LOM), Next Generation Threat Prevention (NGTP) security subscription package for 1 year CPAP-SG5100-NGTP-HPP 5100 Next Generation Security Gateway with High Performance Package, includes 6x1GbE copper ports, 4x1Gb SFP ports, 4 SR transceivers, 16 GB RAM, 1 HDD, 1 AC power unit, Next Generation Threat Extraction (SandBlast) security subscription package for 1 year CPAP-SG5100-NGTX-HPP 1 SKUs for 2 and 3 years, for High Availability and Appliances with an SSD option are also available, see the online Product Catalog ACCESSORIES INTERFACE CARDS AND TRANSCEIVERS 8 Port 10/100/1000 Base-T RJ45 interface card CPAC-8-1C-B 4 Port 1000Base-F SFP interface card; requires additional 1000Base SFP transceivers CPAC-4-1F-B SFP transceiver module for 1G fiber ports - long range (1000Base-LX) CPAC-TR-1LX-B SFP transceiver module for 1G fiber ports - short range (1000Base-SX) CPAC-TR-1SX-B SFP transceiver to 1000 Base-T RJ45 (Copper) CPAC-TR-1T-B 4 Port 1GE copper Bypass (Fail-Open) network interface card (10/100/1000 Base-T) CPAC-4-1C-BP-B SPARES AND MISCELLANEOUS Memory upgrade kit from 8GB to 16GB for 5100 appliance CPAC-RAM8GB-5000 Lights Out Management module CPAC-LOM-B Slide rails for 5000 Appliances (22” - 32”) CPAC-RAIL-5000 Extended slide rails for 5000 Appliances (26” - 36”) CPAC-RAIL-EXT-5000 5100 SECURITY GATEWAY Management 10/100/1000Base-T RJ45 port RJ45/micro USB console port One network card expansion slot 5x 10/100/1000Base-T RJ45 ports 2x USB ports for ISO installation Lights-Out Management port 3 1 2 5 1 2 3 4 5 6 4 2 6
  • 4. ©2017 Check Point Software Technologies Ltd. All rights reserved. [Protected] Non-confidential content | January 23, 2017 | Page 4 Check Point 5100 Security Gateway | Datasheet Performance Ideal Testing Conditions  14.5 Gbps of UDP 1518 byte packet firewall throughput  2.45 Gbps IPS  2.2 Gbps of NGFW 1  450 Mbps of Threat Prevention 2  1.6 Gbps of AES-128 VPN throughput  110,000 connections per second, 64 byte response  3.2/6.4M concurrent connections (base/HPP memory), 64 byte response 3 Real-World Production Conditions  340 SecurityPower Units  4.2 Gbps of firewall throughput  730 Mbps IPS  450 Mbps of NGFW 1  200 Mbps of Threat Prevention 2 Your performance may vary depending on different factors. Visit www.checkpoint.com/partnerlocator to find an appliance that matches your unique requirements. 1. Includes Firewall, Application Control and IPS Software Blades. 2. Includes Firewall, Application Control, URL Filtering, IPS, Antivirus, Anti-Bot and SandBlast Zero-Day Protection Software Blades. 3. Performance measured with default/maximum memory. Expansion Options Base Configuration  6 on-board 10/100/1000Base-T RJ-45 ports  8 GB memory (16 GB option)  1 power supply  1x 500GB (HDD) or 1x 240GB (SSD) drive  Fixed rails (slide rail option)  (Lights-Out-Management (LOM) option) Network Expansion Slot Options (1 slot available)  8x 10/100/1000Base-T RJ45 port card, up to 14 ports  4x 1000Base-F SFP port card, up to 4 ports Fail-Open/Bypass Network Options  4x 10/100/1000Base-T RJ45 port card Network Network Connectivity  Total physical and virtual (VLAN) interfaces per gateway: 1024/4096 (single gateway/with virtual systems)  802.3ad passive and active link aggregation  Layer 2 (transparent) and Layer 3 (routing) mode High Availability  Active/Active and Active/Passive - L3 mode  Session failover for routing change, device and link failure  ClusterXL or VRRP IPv6  NAT66, NAT64  CoreXL, SecureXL, HA with VRRPv3 Routing Unicast and Multicast Routing (see SK98226)  OSPFv2 and v3, BGP, RIP  Static routes, Multicast routes  Policy-based routing  PIM-SM, PIM-SSM, PIM-DM, IGMP v2, and v3 Physical Power Requirements  Single Power Supply rating: 250W  AC power input: 90-264V, (47-63Hz)  Power consumption maximum: 62.9W  Maximum thermal output: 214.6 BTU/hr. Dimensions  Enclosure: 1RU  Dimensions (W x D x H): 17.2x16x1.73 in.(438x406.5x44mm)  Weight: 13.7 lbs. (6.22 kg) Environmental Conditions  Operating: 0° to 40°C, humidity 5% to 95%  Storage: –40° to 70°C, humidity 5% to 95% at 60°C Certifications  Safety: UL, CB, CE, TUV GS  Emissions: FCC, CE, VCCI, RCM/C-Tick  Environmental: RoHS, REACH 1 , ISO14001 1 1 factory certificate CONTACT US Worldwide Headquarters | 5 Ha’Solelim Street, Tel Aviv 67897, Israel | Tel: 972-3-753-4555 | Fax: 972-3-624-1100 | Email: info@checkpoint.com U.S. Headquarters | 959 Skyway Road, Suite 300, San Carlos, CA 94070 | Tel: 800-429-4391; 650-628-2000 | Fax: 650-654-4233 | www.checkpoint.com