Check Point Safe@Office UTM appliances deliver proven, best-in-class security with reduced cost and complexity — right out of the box! Small businesses can quickly and easily deploy comprehensive protection, including firewall, IPS and anti-malware. Robust performance, intuitive management and advanced wireless options provide unmatched value in a simple, all-in-one solution.
- Comprehensive, enterprise-class security for SMBs in a single appliance
- Gigabit firewall performance
- Wizard-based management including preset security rules, automatic updates, monitoring and reporting
- Seamless 802.11n WiFi and 3G wireless connectivity
- Quick and easy deployment with minimal IT resources
Best-in-class Integrated Firewall and IPS
Safe@Office UTM appliances include the industry’s most proven firewall technology, based on the same Check Point technologies that secure the Fortune 100. Comprehensive network access control (NAC) allows blocking of unwanted applications such as IM and P2P, while an advanced intrusion prevention system (IPS) ensures protection of remote sites from both known and unknown threats, such as Denial-of-Service, post scans and buffer overflows.
IPSec VPN connectivity secures communications between site-to-site and remote locations. Support for multiple VPN clients - such as Check Point Endpoint Connect, SecureClient, SecuRemote and L2TP - offers flexibility for users.
Anti-malware and Messaging Security
Malware protection is integrated at the gateway, blocking worms and viruses before they enter the network. On-the-fly decompression of unlimited file sizes enables thorough scanning. Check Point Messaging Security blocks spam and provides comprehensive protection for an organizations’ messaging infrastructure.
- IP reputation anti-spam -Checks the sender's reputation against a dynamic database of known-bad IP addresses, blocking spam and malware at the connection level.
- Content-based anti-spam -Blocks known spam by comparing a ’fingerprint’ of each incoming email with a dynamic database containing millions of known spam signatures.
- Block/allow list anti-spam - Blocks email offenders while allowing trusted senders. Can block or allow entire domains.
- Mail antivirus - Blocks worms and viruses at the gateway. Supports standard email protocols (POP3, IMAP, and SMTP), including Web-based email.
- IPS email server protection - Protects against a broad range of threats, including denial-of-service attacks that target the messaging infrastructure itself.
Best-of-breed URL filtering services allow companies to define Web access policies. Access to potentially malicious Web sites containing spyware and viruses, as well as inappropriate Web content can be blocked.
Network Access Control (NAC)
802.1X port-based authentication allows NAC based on user privileges and policy compliance at branch offices. Built-in support for the extended authentication protocol (EAP) enables WPA Enterprise and 802.1X access control without an external RADIUS server. This makes NAC easier to use, even in small networks.
Safe@Office appliances are full-fledged network routers that include a LAN switch, a dedicated DMZ and a WAN port (Ethernet or ADSL). Static and dynamic routing options are available for complete interoperability.
Safe@Office 1000N Series appliances come equipped with superior networking and security capabilities including state-of-the-art hardware acceleration and 6-1Gbps Ethernet ports.
Secure Hot Spot Support
Administrators can easily enable guest access to networks by creating Web-based secure hot spots. User authentication and/or terms-of-use can be required before granting access to corporate resources.
High-availability options ensure that security functions keep pace with business-critical applications and other network activity. Safe@Office UTM appliances support WAN redundancy and load-balancing to ensure persistent connectivity and service availability. Should the broadband connection become unavailable, dialup support can provide a backup Internet connection.
Comprehensive traffic management parameters - such as weighted priorities, bandwidth guarantees and bandwidth limits – can guarantee QoS for business-critical or latency-sensitive traffic over a single Internet connection. Wireless Multimedia QoS allows companies to prioritize traffic from multiple audio, video and voice applications.
By using the Wireless Distribution System (WDS) capability, the network can be extended by interconnecting two or more Safe@Office wireless appliances. This allows wireless clients (e.g. laptops, PDAs) to connect seamlessly to the wireless network without the need to change IP addresses.
Quick and Easy Setup
A simple Web-based management interface allows administrators to secure a small business in minutes. The setup wizard allows the selection of a preset firewall policy, or the creation of a custom security policy. Security rules can be easily modified with a variety of remote management options.
Safe@Office logs information on attempted attacks and displays it in a color-coded report which includes the IP addresses from which the attacks originated. A “Who Is” utility allows administrators to identify an IP address owner, providing Internet “caller ID” capability. Built-in traffic monitoring and packet capture tools enable monitoring and control of inbound/outbound traffic for efficient bandwidth utilization.
Redundant Internet Connectivity
Safe@Office 1000N and 1000NW appliances also provide complete support for PSTN and ISDN, as well as a wide variety of 3G cellular modems. Out-of-bound dial-in is also supported, to ensure access to the appliance even during Internet connection failures.
Optional subscription-based services provide continuous software and antivirus updates, including URL filtering services, periodic security reports, and anti-spam and dynamic DNS services.
Secure Wireless Connectivity
Safe@Office 1000N Series appliances integrate a WiFi access-point (802.11b/g/n) supporting multiple security protocols, including 802.1x, IPSec over WLAN, RADIUS, WEP, WPA and WPA2 authentication. They also have dedicated WLAN interfaces from which you can set specific security rules for WLAN segments. In addition, the wireless interface can be segmented into as many as four virtual access points, each with separate security policies and encryption methods.
Safe@Office 500W Series appliances integrate a WLAN access point that supports the Super-G and Extended Range
(XR) standard, enhancing the range and network speeds of the wireless access point. Additionally, wireless networks can be segmented into multiple virtual access points, each with different security policies and encryption settings. Remote users are authenticated using a variety of authentication standards including WPA2.
Integrated ADSL Modem
Safe@Office appliances are available with integrated, high-speed ADSL modems, eliminating the need for external ADSL modems and providing administrators with simple deployment options. The latest standards, including ADSL v2/2+, Annex A and Annex B are supported.