The Internet secures your future. We secure the Internet.

    PRODUCT COMPONENTS AND FUNCTIONALITY AREAS

Software Solutions:

  1. VPN-1 SecureServer provides the following security enforcement capabilities for a single server: access control, client and session authentication, network address translation and auditing. Also provides encryption and UserAuthority Gateway capabilities. Multiple options are provided based on the strength of the encryption algorithm.

  2. FireWall-1 SecureServer SecureServer that protects a single machine. Provides a subset of FireWall-1 Module capabilities. Includes UserAuthority Gateway capabilities. Requires either an Enterprise Product or an Enterprise Management Console.

  3. VPN-1 SecureClient Network security protection, consisting of access controls and security configuration verification, for client desktops. Requires a VPN-1 Module and management product (Enterprise or Single Gateway). Enables the use of one VPN-1 Module as a SecureClient Policy Server.

  4. SecureClient – Policy Server Enables additional VPN-1 Module(s) to be used as SecureClient Policy Server. All licensed SecureClient users can utilize this additional Policy Server.

  5. SecuRemote communicates with FireWall-1 Encryption Modules, VPN-1 Modules and VPN-1 SecureServers to enable client-to-module encryption. SecuRemote, the encryption client for Windows ’95, Windows ’98 and Windows NT systems, is included free with VPN-1/FireWall-1.

  6. Macintosh VPN Client Provides an IPSEC/IKE VPN client for specified number of users. Requires a VPN-1 Module and management product (Enterprise or Single Gateway).

  7. Enterprise Management Consoles Distributed Management Console for managing an unlimited number of VPN-1, FireWall-1 or FloodGate-1 Modules, with or without a VPN Module. Includes SecureUpdate License management for an unlimited number of modules.

  8. Motif GUI for Solaris for Enterprise Management Console or Gateway products.

  9. Real-Time Monitoring provides traffic and performance monitoring per VPN-1/FireWall-1 Gateway. RTM is included, at no charge, in SVN Bundles and FloodGate-1 Modules.

  10. SecureUpdate SecureUpdate provides centralized software management and licensing for Check Point products. The installation of service packs and addition of new products can be performed from a central GUI. There is no charge for the central license management capability of SecureUpdate. SecureUpdate licenses are additive.

  11. Visual Policy Editor Enhanced management capabilities allowing the visualization and editing of security policies and objects through an automatically generated topological view of the network. Note: The single enforcement point option can only be used with a single management console (CPFW-FIG/CPVP-VIG) and cannot be used with an Enterprise Management Console.

  12. Open Security Extension provides for the centralized management of access control lists and related security parameters for third-party routers and security devices. Open Security Extension is available in multiple options based on the number of security devices that can be centrally managed.

  13. Reporting Module provides the ability to consolidate and filter log entries from Check Point log files, and subsequently create textual and graphical reports that can be distributed automatically. Currently, it is available for a Windows NT platform only and requires a minimum of VPN-1/FireWall-1 4.0 SP2 or higher on the management server as well as on the enforcement point.

  14. Account Management Module enables LDAP client functionality in FireWall-1 and provides the ability to access and manage VPN-1/FireWall-1 users that are defined on an LDAP server. A GUI is provided for Windows ‘95, Windows ’98 and Windows NT, Solaris, AIX and HP-UX.

  15. Meta IP Manager Service Each Meta IP Manager Service manages the purchased number of Meta IP DNS and DHCP services for a specified IP Address count (e.g. a customer with a DNS server, a DHCP server, and 1,000 nodes will be manage those services for up to the 1,00 nodes with a MS1 module. Features of the Manager Service include a dynamic LDAP data-store, Service Configuration Wizards, and DNS Service Manager Clients. For redundancy of Management, purchase of an additional Service Manger is required.

  16. Meta IP Domain Name System is the leading commercial grade BIND 8.2.3 DNS server. Pricing based on the number of servers needed. Requires Meta IP Manager Service for full configuration and operation.

  17. Meta IP Dynamic Host Configuration Protocol is a fully programmable DHCP engine with lease filtering. Pricing based on the number of servers needed. Requires Meta IP Manager Service for full configuration and operation.

  18. Meta IP Client License for total number of users captured or mapped in UserAuthority.

  19. VPN-1 Modules combine the capabilities of a FireWall-1 Module and an Encryption Module into one component. Multiple options are provided based on the number of IP addresses protected and strength of the encryption algorithm.

  20. UserAuthority server module for capturing security and IP mapping information for users authenticating remotely, via a VPN-1session, SR/SC session, and/or a Windows NT/ Windows 2000 LAN Authentication.

  21. UserAuthority User License Licensed based on the total number of LAN, SecureRemote, Secure Client, or RADIUS users accessing the UserAuthority Gateway. License required for usage of the UserAuthority solution and includes UserAuthority GUI for viewing of UA data including dynamic views of all user and security data.

  22. FireWall-1 Modules provide a super-set of the security enforcement capabilities provided by SecureServer: access control, client and session authentication, network address translation, auditing, user authentication, content security and multiple firewall synchronization. Multiple options are provided based on the number of IP addresses protected.

  23. Add-on VPN Modules enable both firewall-to-firewall encryption and client-to-firewall encryption. Each VPN module includes all available algorithms of lesser strength. Multiple options are provided based on the number of IP addresses protected by the underlying FireWall-1 Module.

  24. FloodGate-1 Modules provide a set of bandwidth management capabilities and are available in multiple options based on the number of IP addresses managed. FloodGate-1 Modules can be deployed either standalone or as an add-on (integrated) to VPN-1/FireWall-1 Modules and can be managed by Enterprise Management Consoles.

  25. ConnectControl Modules enable increased quality of service via automatic application server load balancing. ConnectControl Modules are available for VPN-1 and FireWall-1.

  26. High Availability Module for VPN-1/FireWall-1. Enables transparent failover of two or more modules. Licensed per VPN-1/FireWall-1 module. Requires a minimum of two enforcement points and an Enterprise Management Console.

  27. Management Station Replication enables high availability for VPN-1/FireWall-1 Enterprise Management Consoles. Backup stations are automatically synchronized, ensuring constant availability. Note that this feature enables replication, but does not include an additional Management Console license.

  28. Multi-CPU Support Description - Enables the use of VPN-1/FireWall-1 with multi processor systems. Applicable for use with VPN or Security Servers.

  29. VPN-1 Accelerator Card II Very high performance encryption acceleration for 3DES, IPSec with the Internet Key Exchange (IKE) VPN-1 deployments. Requires a licensed copy of 3DES VPN-1/FireWall-1 version 4.1 SP3 or higher software. Supported OSs’ are: NT 4.0, Solaris 2.6 and 2.7, Redhat LINUX 6.0, 6.1 and 6.2. The card requires an available PCI slot on the Gateway Server.

  30. VPN-1 Accelerator Card High performance encryption acceleration for VPNs when using IPSec with the Internet Key Exchange (IKE). Requires a licensed copy of 3DES VPN-1/FireWall-1 version 4.0, or higher software, and either an Intel machine with PCI bus running NT 4.0 SP3, or a Solaris/SPARC machine with PCI bus running Solaris 2.6 or higher Software updates necessary to VPN-1/FireWall-1 are included with the Accelerator Card.

  31. VPN-1 SmallOffice includes firewall and VPN capabilities for the small office. Provides access control, client and session authentication, network address translation, auditing and supports IPSec / IKE encryption . Used standalone via a local management or centrally managed by an Enterprise Management Console. For Platform support please see the Platform Support tab.

  32. FireWall-1 SmallOffice includes firewall capabilities for the small office. Provides access control, client and session authentication, network address translation and auditing. Used standalone via a local management or centrally managed by an Enterprise Management Console. For platform support please see the Platform Support tab.

  33. Add-on VPN Module for SmallOffice Solutions adds IPSec / IKE encryption to FireWall-1 SmallOffice products of the same size and version.

 

Subscription Program Options:

Legacy Subscription  Provides customers with the ability to bring Software Subscription current and be eligible to receive the latest shipping product version. Legacy Subscription is required for existing customers who purchased product more than twelve months ago (without annual Subscription). Legacy Subscription is approximately 40% of the product list price and includes subscription for one year.
   
Software Subscription 

For Software Solutions: Includes version upgrades, service packs and hot fixes for one year. It is approximately 15% of the product price. Subscription is a prerequisite to purchasing any of the support options listed below.

Software Subscription will start on the license date of the product or, in cases of renewal, on the last date of previous Software Subscription. The one year term commences on the license date as defined by the User Center or 90 days following the book date of the order, whichever comes first.

   
Check Point Secure Care

For SmallOffice Products, includes Software Subscription, access to product support resources in SecureKnowledge, and e-mail based support 24 hours a day during normal business days, for one full year. Response time on all issues is one business day.

Note: Enterprise Customers (with either an Enterprise Management Center or Provider-1 under Subscription/Support) who already have Gold, Gold Plus or Platinum Support Programs can purchase corresponding Gold, Gold Plus, or Platinum programs for their VPN-1/FireWall-1 SmallOffice products. Normal Software Subscription, pricing percentages and service levels will apply.

Support Program Options:

Gold Support  Includes phone & email support during regular business hours ( 6-6 local time for the Americas, and 8-8 International) and a 4 hour response time. It is approximately 15% of the product price.
   
Gold Plus Support Includes phone & email support with response time within 4 hours, 24x7. It is approximately 35% of the product price.
   
Platinum Support

Includes phone & email support with dedicated account experts and response time within 30 minutes, 24x7. It is approximately 50% of the product price.

Support will start on the license date of the product or, in cases of renewal, on the last date of previous Support. The one year term commences on the license date as defined by the User Center or 90 days following the book date of the order, whichever comes first.

Note: Gold, Gold Plus and Platinum Support are calculated separately from Software Subscription.

Partner Support Options:

Certified Support Partner Program (CSP)

The Certified Support Partner Program is designed to recognize partners who provide world class support on Check Point products and offer consistent technical support to customers. To join this program a partner must select one of the CSP backline support options listed below and apply for admittance to the program.

These support options enable partners to contact Check Point directly for Level Two and Level Three assistance on their customers' technical support issues. These options are only available to partners who have been approved for the Certified Support Partner Program. For details on applying to the program, partners should contact their Channel Manager. Additional information is available at http://www.checkpoint.com/partners/service/csp.html

    
Basic Support Basic Support is a back-line technical support option for partners who are not part of the Certified Support Partner Program. This support option grants partners access to SecureKnowledge. Under this program, partners pay an up front fee for the option which includes five (5) tickets. Additional tickets can be purchased. Incident packs of 5, 10 and 25 can be purchased.

Education Services:

Courseware Check Point develops courseware on Check Point products and the technologies on which they are based. Courseware is intended to be an in-class training guide as well as an on the job reference manual. Courseware is listed here under and is only available to Authorized Training Centers (ATCs) for purchase. All courseware items are listed as CPTS-DOC. courseware order form is available at:   http://www.checkpoint.com/services/education/atc/courseware/courseware_form.html
   
Training Check Point delivers courses through a network of Authorized Training Centers. To locate an Authorized Training Center, visit the training locator at: http://www.checkpoint.com/services/education/atcprogram/atc_locations/locations.html

Most courses provide education on how to implement and configure Check Point products and include hands-on lab sessions where appropriate. These courses are based on courseware developed by Check Point and prepare students to take Check Point certification exams. All training courses are listed as CPTS-ATC. Courses are available from Check Point directly only by special request. To request direct training contact: training@ts.checkpoint.com

   
Certification Exams Check Point offers certifications that serve to help individuals increase their overall marketability as security professionals. These certifications are achieved by passing certification exams and meeting additional established prerequisites. Certification exams must be taken from a certified testing center or from Check Point directly.

Professional Services:

Check Point offers network security consulting services through its Professional Services team. This group of consultants is highly skilled in internetworking as well as network security and each consultant is a Check Point Certified Security Engineer. Services available include network security analysis, design, configuration and implementation of Check Point based solutions. Orders for Professional Services should be coordinated and scheduled with Check Point Professional Services Group at : proserv@checkpoint.com.

Daily rates cover normal business hours on normal business days (8am to 5pm local time). Fees for all other times will be determined on a project by project basis. Purchaser is responsible for all travel and expenses incurred by Professional Services personnel engaged in a project.

Return to Top