As the other have said Checkpoint does have a software-based solution which is not commonly used due to the limitations.
I totally believe the control/management-plane traffic should be separated out from data-plane traffic, and it would be useful if checkpoint actually consider this for the next generation of hardware so that the control/management-plane traffic is truley separated without the need for software configuration.
I've mentioned in a few posts now that I personally feel that the hardware Checkpoint utilises is behind the times and they need a solution which truly has the ability to run all blades including https inspect from the bottom up rather than the current range which in reality would be high end devices which is not best fit for regional office from a pricing point of view.
This is somewhat of a challenge for Checkpoint considering they are software-based company, yes lightspeed card has been released and this mostly likely works well in high-end devices, but this does not address low/medium end deployments which most companies have.