Security Products

AI-powered next-generation perimeter gateway delivering top-level security and performance
Check Point Nex-Gen Firewall

Check Point Nex-Gen Firewall from Check Point Software Technologies (hereafter “Check Point”) is a next-generation firewall that protects against a wide range of threats, including known and unknown malware, targeted attacks, and zero-day attacks.

Check Point Nex-Gen Firewall leverages an advanced threat intelligence platform that integrates cloud-based security intelligence, a high-performance automated threat response system, and more than 50 AI engines.

It delivers AI-driven threat prevention of up to 1 Tbps and achieved an unparalleled 99.8% malware block rate in the “NGFW Firewall Security Benchmark 2024” conducted by independent testing organization Miercom.

In addition, throughput with next-generation firewall features enabled has been significantly improved. The product is available in a highly scalable lineup, with the latest CPUs and enterprise SSDs across all series and redundant power supply options available.

Features of Check Point Nex-Gen Firewall

  1. Next-generation firewall that addresses a wide variety of threats

    Check Point Nex-Gen Firewall comes with pre-packaged security capabilities called Software Blade that address a wide variety of threats, allowing customers to select the capabilities that meet their security requirements.
    Compared with previous models, threat prevention throughput has more than doubled. In addition to conventional firewall functionality, AI-powered security capabilities provide perimeter protection against the latest threats.

  2. Ultra-high throughput with high-speed 40/100G modules equipped with ASICs

    The expansion slots on Check Point Nex-Gen Firewall support 8-port 10G SFP and 4-port 10/25G SFP28 expansion NICs, as well as ASIC-based 40/100G QSFP SmartNIC modules co-developed with NVIDIA..
    Check Point’s proprietary acceleration technology, SecureXL, improves performance by processing subsequent packets in previously permitted traffic flows on a separate CPU within the appliance. By offloading this processing to the CPU built into the ASIC, Check Point Nex-Gen Firewall delivers a significant increase in firewall throughput.

  3. Latest Hardware and High Scalability
    Check Point Nex-Gen Firewall is equipped with the latest CPUs and enterprise SSDs across all series, with redundant power supply options also available. Its modular components make it easy to add the required accessories.
    Scalability of Check Point Nex-Gen Firewall

Configuration examples

Configuration examples 1

Check Point Nex-Gen Firewall includes a bundled management license, allowing a redundant configuration without requiring a separate management server or additional licenses. Because targeted cyberattack protection capabilities are consolidated into a single appliance, both inbound and outbound protection can be implemented without deploying multiple devices.

UTM

Configuration example 2

Deploying Check Point SandBlast TE Appliance, which provides sandboxing and email content disarm and reconstruction, together with Check Point Nex-Gen Firewall enables advanced security protection. Adding Smart-1, a dedicated security management appliance, enables centralized management and monitoring of security gateways. Smart-1 includes event analysis and reporting capabilities as standard, making it easy to understand the current security status and trends.

Email Sanitization and Sandboxing

Deployment patterns

Deployment pattern 1: Achieving cutting-edge security and cost savings

Use the next-generation firewall “Check Point Nex-Gen Firewall 9700” as the network security gateway.By leveraging multiple security functions on a single platform, you can reduce overall costs.

Utilizing Multiple Security Features as an UTM

Deployment pattern 2: Countermeasures against intrusions and data breaches

Use the next-generation firewall “Check Point Nex-Gen Firewall 19100” as the gateway responsible for preventing unauthorized intrusions and information leaks.

Used as a measure to prevent data leaks