After an extensive evaluation period for our campus network infrastructure refresh, the security committee has narrowed the primary contender to Check Point Quantum. However, given the critical nature of this deployment—serving approximately 2000 concurrent users, a mix of student residences, research labs, and administrative offices—I am compelled to seek concrete, reproducible data on long-term reliability and performance under sustained load. Marketing materials and feature checklists are insufficient; I require operational metrics from environments of similar scale and complexity.
Our preliminary lab testing, while informative, cannot replicate the heterogeneity and chaos of a live academic network. I am particularly interested in the following dimensions, ideally from institutions that have undergone a full procurement cycle:
* **Stability Metrics:** Mean Time Between Failures (MTBF) for the appliance form-factor (we are considering the 1600/3600 series) and the mean time to recovery after a software update. Anecdotes on problematic R80.x or R81.x releases are welcome, but please provide the exact JHF take number.
* **Performance Degradation Under Sustained Attack Simulation:** We ran a modified Spirent Avalanche test for 72 hours, simulating a mix of volumetric DDoS and low-and-slow application attacks. Our observed throughput drop for Threat Prevention was approximately 22% after the 48-hour mark. Is this within the expected variance for Quantum appliances with all security blades enabled?
* **Management Server (Security Management / Multi-Domain Server) Load:** At 2000 users, we anticipate managing 12-15 gateways with a complex policy set. What are the hardware specifications (vCPU, RAM, storage IOPS) for the management server in your deployment? Have you experienced database bloat or performance lag in the SmartConsole?
* **Comparative Data:** While this is a Check Point forum, if your evaluation included a shortlist with Fortinet FortiGate or Palo Alto Networks PA-Series, a direct comparison of TCP sessions per second and SSL inspection throughput under similar policy densities would be invaluable.
Our test configuration for the primary throughput benchmark was as follows:
```bash
# Spirent Avalanche Script Snippet - Simulated HTTP/HTTPS Campus Traffic
test_profile "campus_mix" {
http_requests_per_sec 45000;
https_connections_per_sec 12000;
imix_ratio { 58% 1500B, 33% 580B, 8% 64B };
attack_simulation "threaded_dos" interval 3600 duration 120;
}
```
I will compile all structured feedback and benchmark results into a comparative analysis document, which I will share with this forum upon completion. The goal is a data-driven decision, moving beyond vendor-provided datasheets.
-- bb42
-- bb42