QUANTUM 16600 HYPERSCALE
SECURITY GATEWAY FOR MAESTRO
Check Point Maestro brings scale, agility and elasticity of the cloud on premise with efficient N+1 clustering based on Check Point HyperSync technology, maximizing the capabilities of your existing security gateways. Create your own virtualized private-cloud premise by stacking multiple Check Point security gateways together. Group them by security feature set, policy or the assets they protect and further virtualize them with virtual systems technology. With the Maestro Hyperscale Orchestrator and 16600 Hyperscale security gateways, businesses of all sizes can have cloud-level security on premise.
Integrated with R80 and ThreatCloud to set a new standard of prevention against advanced 5th generation cyber attacks
Threat Prevention that delivers lightning fast SSL-encrypted traffic inspection without compromising up time or scalability
850 Gbps of Gen V
Hyperscale ready, high performance threat prevention hardware for the fastest Gen V security gateway in the industry
|Gen II Security
|Gen III Security
|Gen V Security
Threat Prevention + SandBlast2
|87 Gbps||30 Gbps||17.6 Gbps|
Performance measured with enterprise testing conditions. Additional performance details on page 3.
1: Includes Firewall, Application Control, and IPS.
2: Includes Firewall, Application Control, URL Filtering, IPS, Antivirus, Anti-Bot and SandBlast Zero-Day Protection
Hyperscale Security System
With Maestro, you can start with two gateways and then can grow to up to 52 gateways. For example, when you start with 32.8 Gbps using two 16600HS gateways you can finish with an 850 Gbps security solution that supports over 500 million concurrent connections. Simply by using Check Point Maestro.
Fully Operational within Minutes
When we add a gateway to the system, it gets all the configurations, the policy, even the software version, updated and aligned with the existing deployment, ready to go within 6 minutes.
Hyperscale Orchestrator Connections
When a Security Group is created, an IP address is created for a Single Management Object connection to the security management server. Easily create and assign IP addresses to the internal and external network interfaces. These uplinks are the visible components of the Maestro security solution.
Maestro Traffic Distribution
HyperSync tracks the Active/Standby/Backup state of group members. Sync traffic is limited to only the Active and Standby members handling the connection.
Cost-Efficient N+1 Deployments
Now businesses of all sizes can enjoy cloud-level resiliency and telco-grade technology using the efficient Maestro N+1 clustering design.
Enterprise Test Conditions
RFC 3511, 2544, 2647, 1242 PERFORMANCE (LAB)
1. Includes Firewall, Application Control, URL Filtering, IPS, Antivirus, Anti-Bot and SandBlast Zero-Day Protection. 2. Includes Firewall, Application Control and IPS.
- 2x 100 GbE QSFP28 ports
- 2x CPUs, 24 physical cores, 48 virtual cores
- 1x 480 GB storage
- 2x AC power supplies
- 128 GB memory
First Time Prevention Capabilities
- CPU-level, OS-level and static file analysis
- File disarm and reconstruction via Threat Extraction
- Average emulation time for unknown files that require full sandbox evaluation is under 100 seconds
- Maximal file size for Emulation is 100 MB
- Emulation OS Support: Windows XP, 7, 8.1, 10
- Use 8,000+ pre-defined or customize your own applications
- Accept, prevent, schedule, and apply traffic-shaping
Data Loss Prevention
- Classify 700+ pre-defined data types
- End user and data owner incident handling
Dynamic User-based Policy
- Integrates with Microsoft AD, LDAP, RADIUS, Cisco pxGrid, Terminal Servers and with 3rd parties via a Web API
- Enforce consistent policy for local and remote users on Windows, macOS, Linux, Android and Apple iOS platforms
- Total physical and virtual (VLAN) interfaces per appliance: 1024/4096 (single gateway/with virtual systems)
- 802.3ad passive and active link aggregation
- Layer 2 (transparent) and Layer 3 (routing) mode
- Active/Active L2, Active/Passive L2 and L3
- Session failover for routing change, device and link failure
- CoreXL, SecureXL
Unicast and Multicast Routing (see SK98226)
- OSPFv2, BGP, RIP
- Static routes, Multicast routes
- Policy-based routing
- PIM-SM, PIM-DM, IGMP v2, and v3
- Up to 8 Security Groups
- Up to 31 gateways in a Security Group
- Up to 24 gateways in a Security Group (dual site deployment, 14 from each site)
- 32x 100 GbE ports (MHO 170)
- Single Power Supply rating: 1300W
- Power input: 100 to 240V (47-53Hz), 40~-72VDC
- Power consumption avg/max: AC261W/307W
- Maximum thermal output AC1: 1048 BTU/hr.
- Enclosure: 1RU
- Dimensions (WxDxH): 17.4 x 24 x 1.73 in. (442 x 610 x 44mm)
- Weight: 28.7 lbs. (13 kg)
- Operating: 0° to 40°C, humidity 5% to 95%
- Storage: –20° to 70°C, humidity 5% to 95% at 60°C
- Safety: UL, CB, CE, TUV GS
- Emissions: FCC, CE, VCCI, RCM/C-Tick
- Environmental: RoHS, WEEE, REACH1, ISO140011
1: factory certificate