- Products
- Learn
- Local User Groups
- Partners
- More
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Improve Your Security Posture with
Threat Prevention and Policy Insights
Overlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hello and Happy new year checkmates,
I'm coming back to you for some discussion and guidance as this year we're looking into refreshing our CheckPoint infrastructure in our DataCenters.
Just to have the clearest picture of our environment, currently we have 3 clusters like below, plus couple of virtual (that are not performing anything else just IPS and FWL) and 2 x Management :
As active services on all clusters we have:
Now going back on the hardware renewal, I was looking on several models and I was pretty impressed by the QLS models.
Therefore I was looking into getting a cluster of 2 x QLS450 in each DC, as I really liked the Nvidia Network cards and packet acceleration that can be done with them, and at the same time, my manager was considering the Maestro Hyperscale way. Just if we would require in future to quickly grow in capacity - still I don't see it as a need currently .
If we consider the current HW capacity and future capacity we have on old HW approx. 20Gbps FWL throughput or 2.2Gbps NGTP to what QLS450 supports ~154Gbps NGFW, we should have room to grow .
Reading in the last days/weeks on QLS450 Nvidia card traffic and Maestro Hyperscale, I started to have some questions and not only in regard to that.
Like:
So, does any of you uses QLS series and can provide more details on the Nvidia acceleration? Also can an of you share thoughts on Maestro Hyperscale and if it's worth going that path, even we would not grow that much.
I'll add other comments as the discussion builds.
Thank you and have a nice week,
PS: if there are unclarities on the topics, let me know.
Start with a CPsizeme on all active gateways that support it. After that load in in the sales tool to see what new appliance could replace it. Run the script on the most busy days of the week! But not to long, 2 - 3 days is OK. Couple hours
CPSizeme:
https://support.checkpoint.com/results/sk/sk88160
Sales tool:
https://usercenter.checkpoint.com/ucapps/appliance-sizing-tool
Hello Lesley,
I think we already pass the HW selection as we look for QLS450.
If we were to migrate to the 15000 series replacement, that is recommended, we would go with 16200 or higher.
Still we have to consider future growth as we might have to firewall more traffic in future - like Cloud Connect traffic (Microsoft Azure and similar) - and therefore we look for a bigger appliances.
Thank you,
Future growth is also calculated in the appliance size tool.
I highly suspect the SE you are going to contact will also ask for CPSizeme. I would recommend to perform the cpsizeme to make sure you make the right pick. Potentially you can save some budget. And if you picked undersized unit would be a bummer. Long story short, spend some time on the cpsimeme 😉
For what its worth, AI copilot response about it.
Andy
***********************
Certainly! The new Quantum LightSpeed (QLS) appliances are designed to provide hyper-fast network security for data centers and large enterprises. These appliances are built to handle high-performance requirements, such as large file transfers, low latency for high-frequency applications, and dynamic scalability as business needs grow.
The Quantum LightSpeed appliances leverage Nvidia acceleration to enhance their performance capabilities. Nvidia's technology provides hardware acceleration for various security functions, significantly boosting the throughput and efficiency of the appliances. This integration allows for:
These models are designed to meet the needs of different enterprise environments, providing a range of performance and connectivity options.
For more detailed information, you can refer to the Check Point LightSpeed Appliances documentation.
Why waste so much electrical power for information readily available in CP user center ?
Thank you the_rock, still ChatGPT or any other "AI" does not answer my questions.
Please discuss the detailed requirements with your local SE.
Likely the Quantum Force family of appliances are best suited to this need.
The throughput numbers you've quoted for QLS seem not to align with the high level datasheet figures, moreover please note the fields are not additive nor consider things such as HTTPs inspection etc.
sk179432: Lightspeed and Quantum Force Software Releases
sk181128: R82 Known Limitations
sk173183: Maestro Comparison Between Versions
sk79700 - VSX Supported Features
Hello Chris,
We'll discuss with our SE, still I wanted to see if others are using those appliances and get secomandarions.
In regard to the numbers, I got them from an initial specs document, I see that in the newer ones that is no longer there. Still the numbers would cover our current and future needs.
Thank you,
Noted but just to clarify further this is still not the NGFW number rather FW-only.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 36 | |
| 18 | |
| 8 | |
| 7 | |
| 7 | |
| 6 | |
| 4 | |
| 3 | |
| 3 | |
| 2 |
Wed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY