- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hello Community!
We are currently working with a potential customer who requires VPN connectivity for more than 100 branch offices to their headquarters. Our plan is to deploy Check Point 1535 devices at each branch and a Check Point 1800 at the HQ as the VPN hub.
Based on our topology, we would need to configure a Star VPN Community with 120 satellite gateways and 1 central gateway. However, we came across the following limitation in sk178604
We would appreciate some clarification on this limitation and have the following questions:
Thanks in advance for your help!
Hi,
SPARK can act as VPN center only if it is managed by Spark management
In centrally managed, SPARK can be deployed only in branches
"100" limitation is not hard limit - it was the max scale during tests
Q - what is the scale target, how many branches?
BTW - It is strongly recommended to deploy SPARK cluster as VPN center (when managed by SPARK Management)
If you wish to further discuss this project, please contact me directly
Thanks
Hi,
SPARK can act as VPN center only if it is managed by Spark management
In centrally managed, SPARK can be deployed only in branches
"100" limitation is not hard limit - it was the max scale during tests
Q - what is the scale target, how many branches?
BTW - It is strongly recommended to deploy SPARK cluster as VPN center (when managed by SPARK Management)
If you wish to further discuss this project, please contact me directly
Thanks
We have several models from 1500-1600 that have the spark sizing that alerts in DR spark for 100 connected hosts. Is there anyway to see what model we need for more connected hosts? Currently when we open a ticket with support they say we are beyond the connected hosts sizing and they encourage us to upgrade hardware but can't tell us what hardware would be best for our connected host count. We don't use any blades except for "firewall" and "site to site vpn" other than that they are all disabled. We've had issues with it on the later firmware because it chews through memory.
What we can see is the included licenses that correspond roughly to the SMBs models power:
1535/55 100 Users
1575/95 200 Users
https://www.checkpoint.com/downloads/products/1500-pro-security-gateway-datasheet.pdf
1600 / 1800 500 Users
https://www.checkpoint.com/downloads/products/1600-1800-security-gateway-datasheet.pdf
1900 / 200 1000 Users
https://www.checkpoint.com/downloads/quantum-spark-1900-2000-datasheet.pdf
I would not see DR.Spark as the authority here 😉
Hello, the only limit I can see on that datasheet is for the mobile users/vpn license. This is just for connected hosts in general. CP support is saying we are over the sizing capacity of 100 users that dr spark reports and suggests we upgrade. They can't give me a model to upgrade to. Pre-sales has no idea on the connected hosts limitation so they are looking into this more too. fun!
Yes, but thius license gives at least a hint 😉 The real problem is that any enabled blade takes its toll, and if you use https inspection this will use up much ressources. So the number of users can vary according to configuration.
I also have heard this argument from TAC, but it clearly is nonsense - someone buildt things into Dr.Spark that sometimes do not make much sense, especially the report from standby cluster nodes is partly missleading/wrong.
If you experience issues like cpu too high, look into this: https://community.checkpoint.com/t5/SMB-Gateways-Spark/History-of-SMB-Specs-and-Performance/td-p/174... and decide about the upgrade...
Hello @Amir_Erman,
Thank you for your response. I sent you a PM in case you can help us a bit more.
Regards
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 5 | |
| 2 | |
| 2 | |
| 2 | |
| 1 | |
| 1 | |
| 1 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY