CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Miscellaneous > Check Point Resellers
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-10-20
Junior Member
 
Join Date: 2006-10-20
Posts: 1
Rep Power: 0
JamieDoherty has an average reputation (10+)
Default UTM Comparisons

I am an original FW-1 user, and it seems with each new version I have let the licensing options slip from my mind more and more. I am proposing a new solution and I am unsure which route to go. The solution is relatively simple, 2 firewalls in an Active/Passive cluster environment. Those firewalls are protecting application servers (less than 10 IP addresses). I am trying to figure out if I could get away with UTM as opposed to UTM Power. Can I purchase a UTM Management and Gateway bundle for 50 users, one additional UTM Gateway for Load Sharing and 2 ClusterXL licenses to accomplish the same? Is there a datasheet that compares UTM to UTM Power?

Jamie
Reply With Quote
  #2 (permalink)  
Old 2006-10-21
Senior Member
 
Join Date: 2006-01-26
Location: Moscow, Russia
Posts: 706
Rep Power: 3
kva.kva has an average reputation (10+)
Default Re: UTM Comparisons

UTM is new name for products Express and Express CI.
UTM includes firewall, VPN, SmartDefense Service, IPS, web application security, and antivirus protection.
Power is new name for FW-1/VPN-1 Pro. It includes all UTM features without AV and it includes extra features - FloodGate and SecureXL.
UTM Power includes all UTM and Power features.

If you want UTM cluster, I think, you need license for managment, license for gateway, license for secondary gateway for high availability and one Cluster XL license for load sharing.
Reply With Quote
  #3 (permalink)  
Old 2006-10-27
Senior Member
 
Join Date: 2006-01-25
Posts: 895
Rep Power: 3
melipla has an average reputation (10+)
Default Re: UTM Comparisons

Quote:
Originally Posted by JamieDoherty View Post
Is there a datasheet that compares UTM to UTM Power?
I too would like one.

I also inquired about VPN-1 Power with my CP Sales rep, he gave me the impression that there weren't any solid numbers comparing VPN-1 Power to VPN-1. He only said that if we were seeing performance problems with VPN-1 that we should consider upgrading our license to VPN-1 Power.
__________________
Its all in the documentation.
Reply With Quote
  #4 (permalink)  
Old 2006-12-20
Member
 
Join Date: 2006-12-20
Posts: 83
Rep Power: 2
NickBrandson has an average reputation (10+)
Default Re: UTM Comparisons

VPN-1 UTM gateways provide firewall, VPN, SmartDefense Service, IPS, web application security, and antivirus protection on an all-in-one platform. Prices include software only.

VPN-1 Power gateways provide blazing fast security for the most demanding environments providing best-of-breed firewall, VPN, SmartDefense Service IPS, and web application security. Prices include software only.

VPN-1 UTM Power gateways are a combination of performance and simplicity- an all-in-one platform that includes the VPN-1 UTM features with the acceleration provided by the VPN-1 Power line. Prices include software only.

** Please advise that the annual subscription for SmartDefense & Antivirus is required if you want SmartDefense Services provide ongoing, real-time updates and configuration advisories for defenses and security policies. SmartDefense Services are licensed annually. The Anti-Virus signature update component of SmartDefense Services is also licensed annually.

For Active-Standby configuration, Cluster-XL for LoadSharing is NOT required.

Just Simply go to check point web site and click on "How to Buy" -> "Price List", then you'll see what components are included in the products/bundles.
Reply With Quote
  #5 (permalink)  
Old 2007-07-16
Member
 
Join Date: 2006-08-22
Posts: 58
Rep Power: 3
mylove142 has an average reputation (10+)
Default Re: UTM Comparisons

Hi all,

My project will buy Checkpoint VPN-1 Pro but Checkpoint VPN-1 Pro is end of sale. Now, I am going to bye Checkpoint VPN-1 UTM to replace VPN-1 Pro. I want to ask everyone: the function of VPN-1 UTM and VPN-1 Pro is the same or VPN-1 Pro is better than VPN-1 UTM?

I will put VPN-1 UTM in datagram

DMZ - VPN-1 UTM - Router gateway - ISP

Please answer me early. Thank you very much.

Duy Khang
Reply With Quote
  #6 (permalink)  
Old 2007-07-16
Senior Member
 
Join Date: 2007-06-04
Posts: 1,062
Rep Power: 3
mcnallym has an average reputation (10+)
Default Re: UTM Comparisons

Check Point VPN-1 Pro includes Floodgate/QoS, the UTM includes Anti-Virus and URL filtering. UTM equates to the old ExpressCI

If you were looking to use QoS on the firewalls then you will need VPN-1 Power.

Not sure if it will make any difference to you but R55 SMARTCenter can read the license for VPN-1 Power but the UTM license will require NGX R60 HFA-02, or later so if still on R55 and not looking to upgrade then go with Power.
Reply With Quote
  #7 (permalink)  
Old 2007-08-14
Member
 
Join Date: 2006-12-20
Posts: 83
Rep Power: 2
NickBrandson has an average reputation (10+)
Default Re: UTM Comparisons

Is it a new purchase or an upgrade?

UTM bundle is required as it contains one gateway and one management server. As stated by mcnallym, Power will have QoS which is upon your requirement.


Quote:
Originally Posted by mylove142 View Post
Hi all,

My project will buy Checkpoint VPN-1 Pro but Checkpoint VPN-1 Pro is end of sale. Now, I am going to bye Checkpoint VPN-1 UTM to replace VPN-1 Pro. I want to ask everyone: the function of VPN-1 UTM and VPN-1 Pro is the same or VPN-1 Pro is better than VPN-1 UTM?

I will put VPN-1 UTM in datagram

DMZ - VPN-1 UTM - Router gateway - ISP

Please answer me early. Thank you very much.

Duy Khang
Reply With Quote
  #8 (permalink)  
Old 2007-08-14
Senior Member
 
Join Date: 2007-01-18
Location: London
Posts: 375
Rep Power: 2
MarioL has an average reputation (10+)
Default Re: UTM Comparisons

I always use this page when I want to check exactly what each part number gives you, in terms of licenses:
https://pricelist.checkpoint.com/pri...tions/main.jsp

And from there I usually go:
https://pricelist.checkpoint.com/pri...enerallist.jsp

It has list price, modules included and now it even has pictures :)

BTW for Active/Passive you don't need a ClusterXL license, just like Nick pointed out.
Reply With Quote
  #9 (permalink)  
Old 2007-11-26
Junior Member
 
Join Date: 2006-03-23
Location: Harrow, London, UK
Posts: 8
Rep Power: 0
hdharmaraja has an average reputation (10+)
Default Re: UTM Comparisons

I assume the license for VPN-1 UTM is sold as bundle or is it possible to purchase a single license just for the gateway and manage it by my existing smartcenter. Hence not pay extra money for management license.
Reply With Quote
  #10 (permalink)  
Old 2007-11-26
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,660
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: UTM Comparisons

Both bundled and un-bundled. See:

https://pricelist.checkpoint.com/pri...=VPN-1Software
Reply With Quote
  #11 (permalink)  
Old 2007-11-27
Senior Member
 
Join Date: 2007-07-16
Posts: 603
Rep Power: 2
Thorpuse has an average reputation (10+)
Default Re: UTM Comparisons

It's really important to note that the UTM-1 Device does not provide a management license that can be installed on a seperate machine i.e. the UTM-1 must run management and module. There used to be an exception for Clustered setups, but I'm not sure that this is still supported.

Also worth noting is the Management license on a UTM-1 is NOT the same from a feature perspective as a SmartCenter UTM license. UTM-1 license also includes a SNX-5 license and a cut-down Eventia license, as well as SmartView Monitor. What sucks big time is that you get less functionality when you pay more to get a proper distributed setup. Another beautiful quirk of Check Point licensing....

Another example of Check Point succeeding despite their best efforts and crazy licensing choices...
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 08:30.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0