We're reviewing our perimeter security for next year. Current setup is an aging pair of Check Point 6000 appliances. Support renewal is coming up, and the quote is... significant. It's got me wondering if we're paying a premium for a brand name that no longer delivers a unique advantage.
Our core needs are pretty standard:
* ~200 users, mostly remote via SSL-VPN.
* Two critical healthcare applications hosted in a colo.
* Strict compliance (HIPAA) requirements for logging and inspection.
* Throughput needs are modest—maybe 500 Mbps sustained, 1 Gbps peaks.
My main concern is **latency and throughput under threat prevention**. Our current gateways add 3-5ms of latency with all security blades enabled, which is acceptable, but I've seen benchmarks where newer NGFWs from Fortinet and Palo Alto handle similar rule sets with sub-1ms adds.
Specific questions for the community:
* Has anyone recently benchmarked Check Point's Threat Prevention performance against, say, a FortiGate 600E or PA-440?
* How is their management (SmartConsole) holding up? It feels heavy compared to modern web UIs.
* For a shop of our size, is the complexity of their three-tier management (GUI, CLI, MDS) overkill?
The alternative would be a migration. I'm not inherently against Check Point, but the value proposition seems blurred. If the main advantage is their historic reputation in stateful inspection, but competitors now match or exceed on application control and threat detection latency, it's hard to justify the cost delta.
Would love to hear from anyone in similar-sized orgs, especially in regulated verticals. What are you seeing in real-world throughput with IPS and SSL inspection turned on?
ms matters