- CheckMates
- :
- Products
- :
- Quantum
- :
- SMB Gateways (Spark)
- :
- Re: SMB - New Product announcement - 1500 Series S...
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
SMB - New Product announcement - 1500 Series Security Gateways
Hi All
We are happy to announce The release of the new 1500 series security gateways for SMBs.
Our first Models to be announced are the 1550 and 1590 gateways which set new standards of protection against the most advanced fifth-generation cyber attacks.
The 1550 and 1590 gateways are powered by Check Point’s R80 release. R80 is the industry’s most advanced security management software, and includes multi-layered next-generation protection from both known threats and zero-day attacks using the award-winning SandBlast™ Zero-Day Protection, plus antivirus, anti-bot, IPS, app control, URL filtering and identity awareness.
The 1500 Security Gateways offer integrated, multi-layered security in a compact desktop form factor. Setup can be done in minutes using pre-defined security policies and our step-by-step configuration wizard. Check Point 1500 Security Gateways are conveniently manageable both locally via a Web interface and centrally by means of a cloud-based Check Point Security Management Portal (SMP) or R80 Security Management.
The new 1500 series empowers Small and Midsize businesses with Enterprise Grade Security:
- 100% block score for malware prevention for email and web, exploit resistance and post-infection catch rate, as seen in the NSS Labs’ recent Breach Prevention Systems (BPS) Group Test
- Up to 2 times more performance from previous generations. The 1550 Gateway offers 450Mbps of threat prevention performance, and the 1590 Gateway offers 660Mbps
- The 1550 provides maximum firewall throughput of 2Gbps and the 1590 provides maximum firewall throughput of 4Gbps
- The 1550 features six 1GbE ports and the 1590 features ten 1GbE ports.
- Check Point WatchTower mobile application, enables IT staff to monitor their networks and quickly mitigate security threats on the go from their mobile device
- Out-of-the-box zero-touch provisioning allows for under 1-minute setup
- IoT devices discovery and recognition for accurate security policy definition.
Want to know more ?
Visit the 1500 Series Security Gateways SK
And the R80.20 for Small and Medium Business Appliances
For full product specifications, visit: https://www.checkpoint.com/products/small-business-security/
Amir Ayalon | SMB Project Management Team Leader
Check Point SW Technologies. | ( +972-733-79-8629| Mobile: +972-545-787673 * amiray@checkpoint.com
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Well, congratulations on your new series of SMB appliances!
As the current firmware state is more or less incomplete do you have a road map to share on what else will be implemented and when ?
Any details on the hardware inside these boxes is welcome.
What about SecureXL? How is it different compared to Gaia ?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
These 1500 series boxes are running R80.20 which is a HUGE leap forward in regards to VPN Multicore, the removal of various SecureXL limitations, support for inline policy layers, and IPS integration with the rest of Threat Prevention. Nice!
March 27th with sessions for both the EMEA and Americas time zones
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
"We have now" is incorrect, i fear - currently we have local and cloud management only, and a couple of Limitations:
These features are currently not available in the R80.20 release:
USB cellular modem
IPv6
ARP spoofing
MAC filtering
ThreatEmulation PrivateCloud Appliance
ADSL/VDSL
Internal LTE with SIM cards
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Wow... Let's hope that their functionalities compensate for how ugly they look! 😅
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
1550:
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
If possible please paste output from commands bellow. Thank you.
# fwaccel stat
# df -h
# fw ctl affinity -l -a
#sim affinity -l
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
# fwaccel stat
+-----------------------------------------------------------------------------+
|Id|Name |Status |Interfaces |Features |
+-----------------------------------------------------------------------------+
|0 |SND |enabled |WAN,LAN1,wlan0 |Acceleration,Cryptography |
| | | | |Crypto: Tunnel,UDPEncap,MD5, |
| | | | |SHA1,NULL,3DES,DES,CAST, |
| | | | |CAST-40,AES-128,AES-256,ESP, |
| | | | |LinkSelection,DynamicVPN, |
| | | | |NatTraversal,AES-XCBC,SHA256 |
+-----------------------------------------------------------------------------+
Accept Templates : enabled
Drop Templates : disabled
NAT Templates : enabled
# df -h
Filesystem Size Used Available Use% Mounted on
tmpfs 20.0M 9.9M 10.1M 50% /tmp
tmpfs 40.0M 21.7M 18.3M 54% /fwtmp
/dev/mmcblk1p8 623.8M 2.4M 575.8M 0% /logs
/dev/mmcblk1p11 1.2G 674.9M 469.2M 59% /storage
/dev/mmcblk1p3 692.7M 370.3M 272.0M 58% /pfrm2.0
tmpfs 14.0M 9.7M 4.3M 69% /tmp/log/local
tmpfs 500.0M 0 500.0M 0% /tetmp
# fw ctl affinity -l -a
wifi0: CPU 0
eth0: CPU 3
WAN: CPU 3
fw_0: CPU 0
fw_1: CPU 1
fw_2: CPU 2
fw_3: CPU 3
ted: CPU all
ted: CPU all
# sim affinity -l
Multi queue interfaces: WAN LAN
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I have been testing this model since end of August as locally and SMP managed device. Looks rather good to me - but i was not able to test management by SMS yet...
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
There are good features but it is not what I expected. I will wait for the central management support and then give them a try. I am also more interested in 1590. Any idea what is the hardware there ?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
The issue is more likely that a patch is likely required on management to push policy to these devices.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
When will the 1400s go end of sale?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
This has not yet been announced - see http://www.checkpoint.com/support-services/support-life-cycle-policy for details about the usual life spans of products !
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Now the EOS is published 5/20/2020: https://www.checkpoint.com/press/2019/check-point-revamps-small-and-medium-businesses-security-to-pr...
For all except the VDSL ones.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
This patch will be included in next R80.30 Jumbo Take (will take about a week from now) and in R80.40 GA.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Central management for 15x0 appliances is available now using R80.30 Jumbo Hotfix Accumulator - New Ongoing Take #107 and, in fact, SmartConsole R80.30 (GA Build 36) released !
Look at the new Advanced Settings for Central Managed 1550:
Additional Management Settings - Move temporary policy files to storage | bool | false | Indicates whether the temporary policy installation files will be saved to the storage partition |
Administrators RADIUS authentication - Local authentication (RADIUS inaccessible) | bool | false | Perform local administrator authentication only if RADIUS server is not configured or is inaccessible. |
Anti ARP Spoofing - Anti ARP Spoofing mode | options | Off | Mode for Anti ARP spoofing protection. The protection can be turned off, on or in detect only mode |
Anti ARP Spoofing - Detection window time to indicate attack | int | 180 | Time period (in seconds) during which IP addresses, assigned to the same MAC address, indicate an ARP spoofing attack |
Anti ARP Spoofing - Number of IP addresses to indicate attack | int | 3 | The number of IP addresses assigned to the same MAC address during the Detection window time that will indicate an ARP spoofing attack |
Anti ARP Spoofing - Suspicious MAC block period | int | 1800 | Time period (in seconds) during which suspicious MAC addresses are kept in the blocked list |
DHCP relay - Use internal IP addresses as source | bool | false | Indicates if DHCP relay packets from the appliance will originate from internal IP addresses |
Hotspot - Enable portal | options | Enabled | Select 'Disabled' to disable the hotspot feature entirely |
Hotspot - Prevent simultaneous log-in | bool | false | The same user will not be allowed to login via hotspot portal from more than one machine in parallel |
Internet - Reset Sierra USB on LSI error | bool | true | Indicates whether Sierra type USB modems will be reset when they send an Invalid LSI signal |
MAC Filtering settings - Log blocked MAC addresses | options | Enabled | Indicates if blocked MAC addresses should be logged or not |
MAC Filtering settings - Log suspension | int | 1 | Indicates the suspension time (in seconds) between logs for blocked MAC addresses |
Report Settings - Max period | options | Weekly | Maximum period to collect and monitor data in central management. You must reboot your appliance to apply changes. |
Serial port - Enable serial port | options | Enabled | Indicates if the serial port is enabled |
Serial port - Flow control | options | RTS/CTS | Indicates the method of data flow control to and from the serial port |
Serial port - Mode | options | Console | Indicates if the serial port is used to connect to the appliance's console, a remote telnet server or allow a remote telnet connection to the device connected to the serial port. |
Serial port - Port speed | options | 115200 | Indicates the port speed (Baud Rate) of the serial connection |
USB modem watchdog - Interval | int | 5 | Indicates how often the USB modem watchdog probes the internet |
USB modem watchdog - Mode | options | Disabled | Indicates if the USB modem watchdog is enabled when internet probing is enabled, and the reset type (either hard-reset to shut down the power for the USB modem or gateway-reset to reboot the gateway itself). |
USB modem watchdog - USB only | bool | false | Monitor only USB modem connection |
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Still a lot of errors in new dashboard when inside the 1550 object:
IPS is flagged red and shows it is not working:
Error: IPS is not responding. verify that IPS is installed on the gateway
AV / ABOT look good , also TE:
But in TP rules, only TE counts the 1550 in:
According to the enabled Blades, there are 5 GWs with TE, AV and IPS enabled and 4 GWs have the ABOT enabled also...
In the 1550 WebGUI i can see that IPS updates are unreachable...
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Device&Lic Info in SmartConsole has never been working properly for me. Like the device uptime is off by 2 hours (not respecting local time), Remote Users count is always 0, IPS and A/V update status is often not available at all, etc. Not that it bothers me 🙂
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I have successfully reconnected the SMB to my SMS - in between, it did believe to run 80.20SP ! Now the IPS issue is resolved as status and shown version are correct - only that Dashboard still only shows the GW in TE updates More Details... section - the More Details... list for ABOT, AV and IPS does not include the 1550.
Next day update: Issue is here again, IPS is flagged although ips stat on SMB GW shows newest its update is installed.
And what we also have: SmartUpdate seems incapable of showing SW version as it did with 1200R, see details after Get Gateway Data !
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello did you test it with Identity awareness blade, we had some issue with 910 gateways , the device had high cpu usage because of the Identity blade.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
No - but if you do enable all blades, you will mostly get some issues - resources are rather low here...
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I was thinking to install the 1590 for a 45 Mbps Internet and 110 Users with 100 devices. Could it handle it ?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hard to say, depends on:
- Traffic mix
- TP blades enabled
- https inspection
According to specs, it has NGTX performance - 660 Mbps (CPEnt) with 10x 1GbE Copper: See the Data Sheet 1500 Appliances Datasheet.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
1590 and 910 are not really comparable..
I have to add here that latest 14xx firmware I run is very stable and performance is surprisingly good. I have 100MBit/s WAN and more than 100 hosts behind it and it handles it very well. With some tweaks here and there of course 🙂
