- Products
- Learn
- Local User Groups
- Partners
- More
Access Control and Threat Prevention Best Practices
5 November @ 5pm CET / 11am ET
Firewall Uptime, Reimagined
How AIOps Simplifies Operations and Prevents Outages
Overlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Spark Management Portal and More!
Hi All
We are happy to announce The release of the new 1500 series security gateways for SMBs.
Our first Models to be announced are the 1550 and 1590 gateways which set new standards of protection against the most advanced fifth-generation cyber attacks.
The 1550 and 1590 gateways are powered by Check Point’s R80 release. R80 is the industry’s most advanced security management software, and includes multi-layered next-generation protection from both known threats and zero-day attacks using the award-winning SandBlast™ Zero-Day Protection, plus antivirus, anti-bot, IPS, app control, URL filtering and identity awareness.
The 1500 Security Gateways offer integrated, multi-layered security in a compact desktop form factor. Setup can be done in minutes using pre-defined security policies and our step-by-step configuration wizard. Check Point 1500 Security Gateways are conveniently manageable both locally via a Web interface and centrally by means of a cloud-based Check Point Security Management Portal (SMP) or R80 Security Management.
The new 1500 series empowers Small and Midsize businesses with Enterprise Grade Security:
Want to know more ?
Visit the 1500 Series Security Gateways SK
And the R80.20 for Small and Medium Business Appliances
For full product specifications, visit: https://www.checkpoint.com/products/small-business-security/
Amir Ayalon | SMB Project Management Team Leader
Check Point SW Technologies. | ( +972-733-79-8629| Mobile: +972-545-787673 * amiray@checkpoint.com
Well, congratulations on your new series of SMB appliances!
As the current firmware state is more or less incomplete do you have a road map to share on what else will be implemented and when ?
Any details on the hardware inside these boxes is welcome.
What about SecureXL? How is it different compared to Gaia ?
These 1500 series boxes are running R80.20 which is a HUGE leap forward in regards to VPN Multicore, the removal of various SecureXL limitations, support for inline policy layers, and IPS integration with the rest of Threat Prevention. Nice!
"We have now" is incorrect, i fear - currently we have local and cloud management only, and a couple of Limitations:
These features are currently not available in the R80.20 release:
USB cellular modem
IPv6
ARP spoofing
MAC filtering
ThreatEmulation PrivateCloud Appliance
ADSL/VDSL
Internal LTE with SIM cards
Wow... Let's hope that their functionalities compensate for how ugly they look! 😅
1550:
If possible please paste output from commands bellow. Thank you.
# fwaccel stat
# df -h
# fw ctl affinity -l -a
#sim affinity -l
# fwaccel stat
+-----------------------------------------------------------------------------+
|Id|Name |Status |Interfaces |Features |
+-----------------------------------------------------------------------------+
|0 |SND |enabled |WAN,LAN1,wlan0 |Acceleration,Cryptography |
| | | | |Crypto: Tunnel,UDPEncap,MD5, |
| | | | |SHA1,NULL,3DES,DES,CAST, |
| | | | |CAST-40,AES-128,AES-256,ESP, |
| | | | |LinkSelection,DynamicVPN, |
| | | | |NatTraversal,AES-XCBC,SHA256 |
+-----------------------------------------------------------------------------+
Accept Templates : enabled
Drop Templates : disabled
NAT Templates : enabled
# df -h
Filesystem Size Used Available Use% Mounted on
tmpfs 20.0M 9.9M 10.1M 50% /tmp
tmpfs 40.0M 21.7M 18.3M 54% /fwtmp
/dev/mmcblk1p8 623.8M 2.4M 575.8M 0% /logs
/dev/mmcblk1p11 1.2G 674.9M 469.2M 59% /storage
/dev/mmcblk1p3 692.7M 370.3M 272.0M 58% /pfrm2.0
tmpfs 14.0M 9.7M 4.3M 69% /tmp/log/local
tmpfs 500.0M 0 500.0M 0% /tetmp
# fw ctl affinity -l -a
wifi0: CPU 0
eth0: CPU 3
WAN: CPU 3
fw_0: CPU 0
fw_1: CPU 1
fw_2: CPU 2
fw_3: CPU 3
ted: CPU all
ted: CPU all
# sim affinity -l
Multi queue interfaces: WAN LAN
I have been testing this model since end of August as locally and SMP managed device. Looks rather good to me - but i was not able to test management by SMS yet...
There are good features but it is not what I expected. I will wait for the central management support and then give them a try. I am also more interested in 1590. Any idea what is the hardware there ?
When will the 1400s go end of sale?
This has not yet been announced - see http://www.checkpoint.com/support-services/support-life-cycle-policy for details about the usual life spans of products !
Now the EOS is published 5/20/2020: https://www.checkpoint.com/press/2019/check-point-revamps-small-and-medium-businesses-security-to-pr...
For all except the VDSL ones.
This patch will be included in next R80.30 Jumbo Take (will take about a week from now) and in R80.40 GA.
Central management for 15x0 appliances is available now using R80.30 Jumbo Hotfix Accumulator - New Ongoing Take #107 and, in fact, SmartConsole R80.30 (GA Build 36) released !
Look at the new Advanced Settings for Central Managed 1550:
| Additional Management Settings - Move temporary policy files to storage | bool | false | Indicates whether the temporary policy installation files will be saved to the storage partition |
| Administrators RADIUS authentication - Local authentication (RADIUS inaccessible) | bool | false | Perform local administrator authentication only if RADIUS server is not configured or is inaccessible. |
| Anti ARP Spoofing - Anti ARP Spoofing mode | options | Off | Mode for Anti ARP spoofing protection. The protection can be turned off, on or in detect only mode |
| Anti ARP Spoofing - Detection window time to indicate attack | int | 180 | Time period (in seconds) during which IP addresses, assigned to the same MAC address, indicate an ARP spoofing attack |
| Anti ARP Spoofing - Number of IP addresses to indicate attack | int | 3 | The number of IP addresses assigned to the same MAC address during the Detection window time that will indicate an ARP spoofing attack |
| Anti ARP Spoofing - Suspicious MAC block period | int | 1800 | Time period (in seconds) during which suspicious MAC addresses are kept in the blocked list |
| DHCP relay - Use internal IP addresses as source | bool | false | Indicates if DHCP relay packets from the appliance will originate from internal IP addresses |
| Hotspot - Enable portal | options | Enabled | Select 'Disabled' to disable the hotspot feature entirely |
| Hotspot - Prevent simultaneous log-in | bool | false | The same user will not be allowed to login via hotspot portal from more than one machine in parallel |
| Internet - Reset Sierra USB on LSI error | bool | true | Indicates whether Sierra type USB modems will be reset when they send an Invalid LSI signal |
| MAC Filtering settings - Log blocked MAC addresses | options | Enabled | Indicates if blocked MAC addresses should be logged or not |
| MAC Filtering settings - Log suspension | int | 1 | Indicates the suspension time (in seconds) between logs for blocked MAC addresses |
| Report Settings - Max period | options | Weekly | Maximum period to collect and monitor data in central management. You must reboot your appliance to apply changes. |
| Serial port - Enable serial port | options | Enabled | Indicates if the serial port is enabled |
| Serial port - Flow control | options | RTS/CTS | Indicates the method of data flow control to and from the serial port |
| Serial port - Mode | options | Console | Indicates if the serial port is used to connect to the appliance's console, a remote telnet server or allow a remote telnet connection to the device connected to the serial port. |
| Serial port - Port speed | options | 115200 | Indicates the port speed (Baud Rate) of the serial connection |
| USB modem watchdog - Interval | int | 5 | Indicates how often the USB modem watchdog probes the internet |
| USB modem watchdog - Mode | options | Disabled | Indicates if the USB modem watchdog is enabled when internet probing is enabled, and the reset type (either hard-reset to shut down the power for the USB modem or gateway-reset to reboot the gateway itself). |
| USB modem watchdog - USB only | bool | false | Monitor only USB modem connection |
Still a lot of errors in new dashboard when inside the 1550 object:
IPS is flagged red and shows it is not working:
Error: IPS is not responding. verify that IPS is installed on the gateway
AV / ABOT look good , also TE:
But in TP rules, only TE counts the 1550 in:
According to the enabled Blades, there are 5 GWs with TE, AV and IPS enabled and 4 GWs have the ABOT enabled also...
In the 1550 WebGUI i can see that IPS updates are unreachable...
Device&Lic Info in SmartConsole has never been working properly for me. Like the device uptime is off by 2 hours (not respecting local time), Remote Users count is always 0, IPS and A/V update status is often not available at all, etc. Not that it bothers me 🙂
I have successfully reconnected the SMB to my SMS - in between, it did believe to run 80.20SP ! Now the IPS issue is resolved as status and shown version are correct - only that Dashboard still only shows the GW in TE updates More Details... section - the More Details... list for ABOT, AV and IPS does not include the 1550.
Next day update: Issue is here again, IPS is flagged although ips stat on SMB GW shows newest its update is installed.
And what we also have: SmartUpdate seems incapable of showing SW version as it did with 1200R, see details after Get Gateway Data !
Hello did you test it with Identity awareness blade, we had some issue with 910 gateways , the device had high cpu usage because of the Identity blade.
No - but if you do enable all blades, you will mostly get some issues - resources are rather low here...
I was thinking to install the 1590 for a 45 Mbps Internet and 110 Users with 100 devices. Could it handle it ?
Hard to say, depends on:
- Traffic mix
- TP blades enabled
- https inspection
According to specs, it has NGTX performance - 660 Mbps (CPEnt) with 10x 1GbE Copper: See the Data Sheet 1500 Appliances Datasheet.
1590 and 910 are not really comparable..
I have to add here that latest 14xx firmware I run is very stable and performance is surprisingly good. I have 100MBit/s WAN and more than 100 hosts behind it and it handles it very well. With some tweaks here and there of course 🙂
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 4 | |
| 2 | |
| 2 | |
| 2 | |
| 2 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 |
Wed 05 Nov 2025 @ 11:00 AM (EST)
TechTalk: Access Control and Threat Prevention Best PracticesThu 06 Nov 2025 @ 10:00 AM (CET)
CheckMates Live BeLux: Get to Know Veriti – What It Is, What It Does, and Why It MattersTue 11 Nov 2025 @ 05:00 PM (CET)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - AMERTue 11 Nov 2025 @ 10:00 AM (CST)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - EMEAAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY