Check Point Quantum 26000 Next Generation Firewalls enables enterprises to deploy the industry’s leading threat prevention capabilities at all points of their infrastructure, scaling security almost infinitely according to their changing business needs. It also dramatically accelerates the efficiency of their security operations. This enables enterprises to prevent and block even the most advanced attacks, before they can disrupt business.

Always Protected
Against Gen V

Highest caliber prevention
with unified security

Security at

On-demand expansion
with hyperscalability


Cut operation management
time by up to 80%


Performance measured with enterprise testing conditions. Additional performance details on page 3.
1: Includes Firewall, Application Control, and IPS.
2: Includes Firewall, Application Control, URL Filtering, IPS, Antivirus, Anti-Bot and SandBlast Zero-Day Protection


Prevent Known and Zero-day Threats

Check Point SandBlast Network is an evasion-resistant sandbox that provides zero-day protection from advanced and unknown threats. SandBlast Threat Extraction (CDR) ensures quick delivery of safe email and web content to users.

All-inclusive Security Solutions

Check Point 26000 security gateways include all security technologies including the SandBlast (sandboxing) software package for one year. Purchase a renewal for NGFW, NGTP or SandBlast (SNBT) for subsequent years as you like.

High Performance Options

Purchase the affordable Plus package and get a base system plus eight 1 Gb ports, twelve 10Gb ports, transceivers, 2x 480 GB SSD drives, Lights-out Management and 96 GB of memory for high connection capacity.

100, 40 and 25 GbE Connectivity

If you’re ready to move from 10 to 25, 40 or 100 GbE, so is the 26000 Next Generation Security Gateway. The 26000 Security Gateway lets you connect your 10 GbE server uplinks to your core network.




Enterprise Test Conditions
Threat Prevention1 (Gbps)
NGFW2 (Gbps)
IPS (Gbps)
Firewall (Gbps)
RFC 3511, 2544, 2647, 1242 PERFORMANCE (LAB)
Firewall 1518B UDP (Gbps)
VPN AES-128 (Gbps)
Concurrent connections3
1: Includes Firewall, Application Control, URL Filtering, IPS, Antivirus, Anti-Bot and SandBlast Zero-Day Protection. 2: Includes Firewall, Application Control and IPS. 3: Performance measured with default/Plus/maximum memory.

Additional Features

  • 2x CPUs, 36 physical cores, 72 virtual cores (total)
  • 1x 1TB HDD or 480GB SSD, (2x SSD in Plus)
  • 3x AC power supplies (DC option)
  • 48, 96 and 128 GB memory options
  • Lights-Out-Management card (optional in Base package)
  • Virtual Systems (base/PLUS/max mem): 125/250/250
Network Expansion Slot Options (4 of 8 slots open)
  • 8x 10/100/1000Base-T RJ45 port card, up to 66 ports
  • 4x 1000Base-F SFP port card, up to 32 ports
  • 4x 10GBase-F SFP+ port card, up to 32 ports
  • 2x 40G QSFP+ port card, up to 16 ports
  • 2x 100/25G QSFP28 port card, up to 16 ports

Content Security

First Time Prevention Capabilities
  • CPU-level, OS-level and static file analysis
  • File disarm and reconstruction via Threat Extraction
  • Average emulation time for unknown files that require full sandbox
  • evaluation is under 100 seconds
  • Maximal file size for Emulation is 100 MB
  • Emulation OS Support: Windows XP, 7, 8.1, 10
  • Use 8,000+ pre-defined or customize your own applications
  • Accept, prevent, schedule, and apply traffic-shaping
Data Loss Prevention
  • Classify 700+ pre-defined data types
  • End user and data owner incident handling
Dynamic User-based Policy
  • Integrates with Microsoft AD, LDAP, RADIUS, Cisco pxGrid, Terminal Servers and with 3rd parties via a Web API
  • Enforce consistent policy for local and remote users on Windows, macOS, Linux, Android and Apple iOS platforms


Network Connectivity
  • Total physical and virtual (VLAN) interfaces per appliance: 1024/4096 (single gateway/with virtual systems)
  • 802.3ad passive and active link aggregation
  • Layer 2 (transparent) and Layer 3 (routing) mode
High Availability
  • Active/Active L2, Active/Passive L2 and L3
  • Session failover for routing change, device and link failure
  • ClusterXL or VRRP
  • NAT66, NAT64, NAT46
  • CoreXL, SecureXL, HA with VRRPv3
Unicast and Multicast Routing (see SK98226)
  • OSPFv2 and v3, BGP, RIP
  • Static routes, Multicast routes
  • Policy-based routing
  • PIM-SM, PIM-SSM, PIM-DM, IGMP v2, and v3


Power Requirements
  • Single Power Supply rating AC: 850W, DC: 1300W
  • Power input: 100 to 240V (47-53Hz), 40~-72VDC
  • Power consumption avg/max1: AC359/443W
  • Maximum thermal output AC1: 1509 BTU/hr.
1. base configuration, up to 1200W/4094 BTU/hr. with max config
  • Enclosure: 3RU
  • Dimensions (WxDxH): 17.4 x 24 x 5.2 in. (442 x 610 x 132mm)
  • Weight: 46.3 lbs. (21 kg)
Environmental Conditions
  • Operating: 0° to 40°C, humidity 5% to 95%
  • Storage: –20° to 70°C, humidity 5% to 95% at 60°C
  • Safety: UL, CB, CE, TUV GS
  • Emissions: FCC, CE, VCCI, RCM/C-Tick
  • Environmental: RoHS, WEEE, REACH1, ISO140011

1: factory certificate


This website uses cookies to ensure you get the best experience. Got it, Thanks! MORE INFO