Safe@Office UTM Appliances

Overview
Check Point Safe@Office UTM appliances deliver proven, best-in-class security with reduced cost and complexity — right out of the box! Small businesses can quickly and easily deploy comprehensive protection, including firewall, IPS and anti-malware, starting at just $299. Robust performance, intuitive management and advanced wireless options provide unmatched value in a simple, all-in-one solution.
Key Benefits
- Comprehensive, enterprise-class security for SMBs in a single appliance
- Gigabit firewall performance starting at $750
- Wizard-based management including preset security rules, automatic updates, monitoring and reporting
- Seamless 802.11n WiFi and 3G wireless connectivity
- Quick and easy deployment with minimal IT resources
Features
SECURITY
- Best-in-class Integrated Firewall and IPS
- Secure Connectivity
- Anti-malware and Messaging Security
- Web Filtering
- Network Access Control
Best-in-class Integrated Firewall and IPS
Safe@Office UTM appliances include the industry’s most proven firewall technology, based on the same Check Point technologies that secure the Fortune 100. Comprehensive network access control (NAC) allows blocking of unwanted applications such as IM and P2P, while an advanced intrusion prevention system (IPS) ensures protection of remote sites from both known and unknown threats, such as Denial-of-Service, post scans and buffer overflows.
Secure Connectivity
IPSec VPN connectivity secures communications between site-to-site and remote locations. Support for multiple VPN clients - such as Check Point Endpoint Connect, SecureClient, SecuRemote and L2TP - offers flexibility for users.
Anti-malware and Messaging Security
Malware protection is integrated at the gateway, blocking worms and viruses before they enter the network. On-the-fly decompression of unlimited file sizes enables thorough scanning. Check Point Messaging Security blocks spam and provides comprehensive protection for an organizations’ messaging infrastructure.
IP reputation anti-spam |
Checks the sender's reputation against a dynamic database of known-bad IP addresses, blocking spam and malware at the connection level. |
Content-based anti-spam |
Blocks known spam by comparing a ’fingerprint’ of each incoming email with a dynamic database containing millions of known spam signatures. |
Block/allow list anti-spam |
Blocks email offenders while allowing trusted senders. Can block or allow entire domains. |
Mail antivirus |
Blocks worms and viruses at the gateway. Supports standard email protocols (POP3, IMAP, and SMTP), including Web-based email. |
IPS email server protection |
Protects against a broad range of threats, including denial-of-service attacks that target the messaging infrastructure itself. |
Web Filtering
Best-of-breed URL filtering services allow companies to define Web access policies. Access to potentially malicious Web sites containing spyware and viruses, as well as inappropriate Web content can be blocked.
Network Access Control (NAC)
802.1X port-based authentication allows NAC based on user privileges and policy compliance at branch offices. Built-in support for the extended authentication protocol (EAP) enables WPA Enterprise and 802.1X access control without an external RADIUS server. This makes NAC easier to use, even in small networks.
NETWORKING
- High-Performance Networking
- Secure Hot Spot Support
- High-Availability
- Quality-of-Service
- Wireless Roaming
High-Performance Networking
Safe@Office appliances are full-fledged network routers that include a LAN switch, a dedicated DMZ and a WAN port (Ethernet or ADSL). Static and dynamic routing options are available for complete interoperability.
Safe@Office 1000N Series appliances come equipped with superior networking and security capabilities including state-of-the-art hardware acceleration and 6-1Gbps Ethernet ports.
Secure Hot Spot Support
Administrators can easily enable guest access to networks by creating Web-based secure hot spots. User authentication and/or terms-of-use can be required before granting access to corporate resources.
High-Availability
High-availability options ensure that security functions keep pace with business-critical applications and other network activity. Safe@Office UTM appliances support WAN redundancy and load-balancing to ensure persistent connectivity and service availability. Should the broadband connection become unavailable, dialup support can provide a backup Internet connection.
Quality–of–Service (QoS)
Comprehensive traffic management parameters - such as weighted priorities, bandwidth guarantees and bandwidth limits – can guarantee QoS for business-critical or latency-sensitive traffic over a single Internet connection. Wireless Multimedia QoS allows companies to prioritize traffic from multiple audio, video and voice applications.
Wireless Roaming
By using the Wireless Distribution System (WDS) capability, the network can be extended by interconnecting two or more Safe@Office wireless appliances. This allows wireless clients (e.g. laptops, PDAs) to connect seamlessly to the wireless network without the need to change IP addresses.

MANAGEMENT
Quick and Easy Setup
A simple Web-based management interface allows administrators to secure a small business in minutes. The setup wizard allows the selection of a preset firewall policy, or the creation of a custom security policy. Security rules can be easily modified with a variety of remote management options.
Network Monitoring
Safe@Office logs information on attempted attacks and displays it in a color-coded report which includes the IP addresses from which the attacks originated. A “Who Is” utility allows administrators to identify an IP address owner, providing Internet “caller ID” capability. Built-in traffic monitoring and packet capture tools enable monitoring and control of inbound/outbound traffic for efficient bandwidth utilization.
Redundant Internet Connectivity
Safe@Office 1000N and 1000NW appliances also provide complete support for PSTN and ISDN, as well as a wide variety of 3G cellular modems. Out-of-bound dial-in is also supported, to ensure access to the appliance even during Internet connection failures.
Updates
Optional subscription-based services provide continuous software and antivirus updates, including URL filtering services, periodic security reports, and anti-spam and dynamic DNS services.
HARDWARE OPTIONS
Secure Wireless Connectivity
Safe@Office 1000N Series appliances integrate a WiFi access-point (802.11b/g/n) supporting multiple security protocols, including 802.1x, IPSec over WLAN, RADIUS, WEP, WPA and WPA2 authentication. They also have dedicated WLAN interfaces from which you can set specific security rules for WLAN segments. In addition, the wireless interface can be segmented into as many as four virtual access points, each with separate security policies and encryption methods.
Safe@Office 500W Series appliances integrate a WLAN access point that supports the Super-G and Extended Range
(XR) standard, enhancing the range and network speeds of the wireless access point. Additionally, wireless networks can be segmented into multiple virtual access points, each with different security policies and encryption settings. Remote users are authenticated using a variety of authentication standards including WPA2.
Integrated ADSL Modem
Safe@Office appliances are available with integrated, high-speed ADSL modems, eliminating the need for external ADSL modems and providing administrators with simple deployment options. The latest standards, including ADSL v2/2+, Annex A and Annex B are supported.
Specifications
| Safe@Office 1000N | 1000N |
1000NW |
|---|---|---|
| Firmware Version | Embedded NGX 8.1 | |
| Concurrent Users | 25/Unlimited | |
1000N |
1000NW |
|
| Hardware Features | ||
| Firewall Throughput (Mbps) | 1,000 | |
| VPN Throughput (Mbps) | 200 | |
| Concurrent Firewall Connections | 60,000 | |
| LAN Switch | 4 Ports, 10/100/1000 Mbps | |
| WAN Port | 10/100/1000 Mbps | |
| DMZ/WAN2 Port | 10/100/1000 Mbps | |
| USB Ports | 0 | 2 |
| Console Port (Serial) | ||
| Connectivity | 3G | |
| Wall Mounting Kit | ||
1000N |
1000NW |
|
| Firewall & Security Features | ||
| Check Point Patented Stateful Inspection Firewall | ||
| Application Intelligence (IPS) | ||
| Instant Messenger and P2P Blocking/Monitoring | ||
| Port-based and Tag-based VLAN | ||
| Network Access Control (802.1x) | ||
| Integrated RADIUS Server | ||
| Secure HotSpot (Guest Access) | ||
1000N |
1000NW |
|
| Add-on Services** | ||
| Gateway Antivirus | ||
| Antivirus Supported Protocols | HTTP, FTP, NBT, POP3, IMAP, SMTP User-defined TCP and UDP ports | |
| On the fly decompression | ||
| Embedded Antispam | ||
| Web Filtering | ||
1000N |
1000NW |
|
| VPN | ||
| Remote Access Client Software | Check Point VPN-1® SecuRemote™ (included)/L2TP IPSec VPN client, Endpoint Connect VPN client | |
| Site-to-site VPN | ||
| Remote Access VPN | ||
| VPN Tunnels | 400 (with management) | |
| Remote Access VPN Profiles | 5/Unlimited* | |
| Site-to-site VPN Profiles | 2/Unlimited* | |
| IPSec Features | Hardware accelerated DES, 3DES, AES, MD5, SHA-1, Hardware Random Number Generator (RNG), Internet Key Exchange (IKE), Perfect Forward Secrecy (PFS), IPSec Compression, IPSec NAT Traversal (NAT-T) | |
| L2TP VPN Server | ||
1000N |
1000NW |
|
| Networking | ||
| Supported Standards | Static IP, DHCP, PPPoE, PPTP, Telstra | |
| Backup ISP and Load Balancing | ||
| Dialup Backup | Serial | USB, Serial |
| Traffic Shaper (QoS) | Basic/Advanced* | |
| Automatic Gateway Failover (HA) | ||
| Dynamic Routing | OSPF, BGP* | |
| Print Server | n/a | |
1000N |
1000NW |
|
| Management | ||
| HTTP / HTTPS / SSH / SNMP / SMP / SMP On-Demand | ||
| Local Diagnostic Tools | Ping, WHOIS, Packet Sniffer, VPN Tunnel Monitor, Connection Table Monitor, Network Monitor, Active Computers Display, Local Logs, Traffic Monitor | |
1000N |
1000NW |
|
| Wireless Specifications*** | ||
| Wireless Protocols | 802.11b (11Mbps), 802.11g (54Mbps), 802.11n (300Mbps) |
|
| Wireless Security | VPN over Wireless, WEP, WPA2 (802.11i), WPA-PSK, 802.1x |
|
| Wireless Range (Standard Mode) | Up to 100 m indoors and 300 m outdoors (וnder optimal conditions) | |
| Wireless Range (XR Mode) | Up to 300 m indoors and 1 km outdoors (וnder optimal conditions) | |
| Wireless Distribution System (WDS) | ||
| Multiple Access Points | ||
* Requires Power Pack upgrade
** Additional services might be needed
*** Environmental factors may lower actual range
| Hardware Specifications | |
|---|---|
| Physical Dimensions (W x H x D) | Safe@Office 1000N: 200 x 33 x 122 mm |
| Temperature | -5ºC ~ 80º C (Storage/Transport), 0ºC ~ 40ºC (Operation) |
| Weight | 1.45 Kg (3.197lbs) |
| Regulatory Compliance | FCC Part 15 Class B, CE |
| Environmental Standards | RoHS, WEEE |
| Warranty | One Year Hardware |
THE TECHNOLOGY INSIDE
Safe@Office is based on Embedded NGX™ with Application Intelligence technology, which incorporates Check Point's market-leading Firewall-1® and VPN-1® software, optimized for embedded platforms. Embedded NGX is developed by SofaWare Technologies, a Check Point company.
| Safe@Office 500 | 500 |
500W |
500 ADSL |
500W ADSL |
|---|---|---|---|---|
| Firmware Version | Embedded NGX 8.1 | |||
| Concurrent Users | 5/25/Unlimited | |||
500 |
500W |
500 ADSL |
500W ADSL |
|
| Hardware Features | ||||
| Firewall Throughput (Mbps) | 190 | |||
| VPN Throughput (Mbps) | 35 | |||
| Concurrent Firewall Connections | 8,000 | |||
| LAN Switch | 4 Ports, 10/100 Mbps | |||
| WAN Port | 10/100 Mbps | ADSL2+ | ||
| DMZ/WAN2 Port | 10/100Mbps | |||
| Console Port (Serial) | ||||
| Wall Mounting Kit | ||||
500 |
500W |
500 ADSL |
500W ADSL |
|
| Firewall & Security Features | ||||
| Check Point Patented Stateful Inspection Firewall | ||||
| Application Intelligence (IPS) | ||||
| Instant Messenger and P2P Blocking/Monitoring | ||||
| Port-based and Tag-based VLAN | ||||
| Network Access Control (802.1x) | ||||
| Integrated RADIUS Server | ||||
| Secure HotSpot (Guest Access) | ||||
500 |
500W |
500 ADSL |
500W ADSL |
|
| Add-on Services** | ||||
| Gateway Antivirus | ||||
| Antivirus Supported Protocols | HTTP, FTP, NBT, POP3, IMAP, SMTP User-defined TCP and UDP ports | |||
| On the fly decompression | ||||
| Embedded Antispam | ||||
| Web Filtering | ||||
500 |
500W |
500 ADSL |
500W ADSL |
|
| VPN | ||||
| Remote Access Client Software | Check Point VPN-1® SecuRemote™ (included)/L2TP IPSec VPN client, Endpoint Connect VPN client | |||
| Site-to-site VPN | ||||
| Remote Access VPN | ||||
| VPN Tunnels | 100 (with management) | |||
| Remote Access VPN Profiles | 5/25* | |||
| Site-to-site VPN Profiles | 2/15* | |||
| IPSec Features | Hardware accelerated DES, 3DES, AES, MD5, SHA-1, Hardware Random Number Generator (RNG), Internet Key Exchange (IKE), Perfect Forward Secrecy (PFS), IPSec Compression, IPSec NAT Traversal (NAT-T) | |||
| L2TP VPN Server | ||||
500 |
500W |
500 ADSL |
500W ADSL |
|
| Networking | ||||
| Supported Standards | Static IP, DHCP, PPPoE, PPTP, Telstra | Static IP, DHCP, PPPoE, PPTP, Telstra, EoA, PPPoA | ||
| Backup ISP and Load Balancing | ||||
| Dialup Backup | Serial | USB, Serial | USB, Serial | USB |
| Traffic Shaper (QoS) | Basic/Advanced* | |||
| Automatic Gateway Failover (HA) | ||||
| Dynamic Routing | OSPF, BGP* | |||
| Print Server | ||||
500 |
500W |
500 ADSL |
500W ADSL |
|
| Management | ||||
| HTTP / HTTPS / SSH / SNMP / SMP / SMP On-Demand | ||||
| Local Diagnostic Tools | Ping, WHOIS, Packet Sniffer, VPN Tunnel Monitor, Connection Table Monitor, Network Monitor, Active Computers Display, Local Logs, Traffic Monitor | |||
500 |
500W |
500 ADSL |
500W ADSL |
|
| ADSL Modem Specifications | ||||
| Supported Standards | ADSL2, ADSL2+, T.1413 G.DMT (G.992.1) G.Lite (G.992.2) ANNEX A (ADSL over POTS), ANNEX B (ADSL over ISDN) |
|||
500 |
500W |
500 ADSL |
500W ADSL |
|
| Wireless Specifications*** | ||||
| Wireless Protocols | 802.11b (11Mbps), 802.11g (54Mbps), Super-G (108Mbps) |
|||
| Wireless Security | VPN over Wireless, WEP, WPA2 (802.11i), WPA-PSK, 802.1x |
|||
| Wireless Range (Standard Mode) | Up to 100 m indoors and 300 m outdoors (וnder optimal conditions) | |||
| Wireless Range (XR Mode) | Up to 300 m indoors and 1 km outdoors (וnder optimal conditions) | |||
| Wireless Distribution System (WDS) | ||||
| Multiple Access Points | ||||
* Requires Power Pack upgrade
** Requires additional purchase of service
*** Super-G and XR mode only available with select wireless network adapters. Actual ranges are subject to change in different environments
| Hardware Specifications | |
|---|---|
| Physical Dimensions (W x H x D) | Safe@Office 500/ Safe@Office 500 |
| Temperature | -5ºC ~ 80º C (Storage/Transport), 0ºC ~ 40ºC (Operation) |
| Weight | 1.45 Kg (3.197lbs) |
| Regulatory Compliance | FCC Part 15 Class B, CE |
| Environmental Standards | RoHS, WEEE |
| Warranty | One Year Hardware |
THE TECHNOLOGY INSIDE
Safe@Office is based on Embedded NGX™ with Application Intelligence technology, which incorporates Check Point's market-leading Firewall-1® and VPN-1® software, optimized for embedded platforms. Embedded NGX is developed by SofaWare Technologies, a Check Point company.
Support & Warranty
Safe@Office support packages are provided by select service providers and SofaWare, a Check Point company. To locate a service provider near you, please use the Service Provider Locator.
SofaWare provided support plans include the Basic AV & IPS plans as well as a Web filtering plan. You can learn more about SofaWare support plans by visiting SofaWare – Security Services.
Purchase Safe@Office support from a Check Point Small Business Reseller or directly from SofaWare today.
Safe@Office appliances include a 1-year hardware warranty and 90 day software subscription. Safe@Office is developed by SofaWare Technologies, a Check Point company.
