Datasheet | SD-WAN
Discover Check Point SD-WAN, combining AI-powered security with optimized connectivity, sub-second failover, and unified SASE management for hybrid networks.

A software blade in our firewalls, Check Point SD-WAN lets you extend market-leading security to optimized internet and network connectivity.
© 2026 Check Point Software Technologies Ltd. All rights reserved.
Secure SD-WAN for AI-Driven Hybrid Mesh Networks As applications move from private data centers to public cloud and SaaS, networking and security are converging to help enterprises securely shift from private WANs to internet-based connectivity. This turns secure branch connectivity into a control point for GenAI use, apps and agents.
By combining multiple types of connections, such as MPLS, broadband, wireless and satellite, SD-WAN connects offices directly to the internet and cloud for optimal speed, uptime, performance and lower costs.
Check Point SD-WAN—SD-WAN Built into the Best Threat Prevention A software blade in all Check Point Firewalls, Check Point SD-WAN unifies the best security with optimized internet and network connectivity. By deploying Check Point SD-WAN right from your hardware or cloud firewalls, network and security teams reap immediate benefits:
Unifying The Best Security With Optimized Connectivity
Check Point SD-WAN Immediate Benefits
• Industry-best catch rate for preventing zero-days, phishing and ransomware
• AI security enforced from the firewall across employees, AI applications, and AI agents
• Auto-enhanced connectivity for 10,000+ apps and users, with subsecond failover
• Complete SASE solution managed from the cloud
• Simple onboarding with step-by-step wizard and automated steering policy
• Scalable, centralized management, link health monitoring and troubleshooting
• Optimize branch connectivity to the internet and cloud over MPLS, broadband, satellite or wireless
• Connect your offices, on-prem, and cloud data centers with a secure and resilient overlay (VPN] network
• Fail-proof your connectivity with sub-second failover for unstable connections, and continuous link health monitoring against predefined thresholds.
• Secure your branch offices with a full enterprise-grade security stack embedded into your wide area branch network, to deliver the highest malware catch rate
• Gain end-to-end monitoring and visibility into network health, including application performance and SLA metrics
• Discover, govern and protect AI usage across the enterprise, preventing data leakage and AI-specific threats
UNIFYING THE BEST SECURITY WITH OPTIMIZED CONNECTIVITY 2
© 2026 Check Point Software Technologies Ltd. All rights reserved.
Check Point SD-WAN Core Capabilities Check Point SD-WAN offers rich SD-WAN capabilities that are critical to a successful SD-WAN deployment. These include:
Multiple WAN Link Support Check Point SD-WAN supports MPLS, broadband, satellite and wireless (LTE/4G/5G) connections with simplified link detection. Advanced link mapping lets you steer traffic to specific links and apply policies across branches easily.
Sub-Second Failover for Unstable Connections Check Point SD-WAN monitors overlay and breakout networks, adapting paths in real time with sub-second failover. This ensures reliable connectivity for latency-sensitive apps like Zoom™, Teams™, VoIP, and remote helpdesk support. It also simplifies site-to-site VPN setup with IPSec tunnels, link redundancy, and dynamic path selection, giving branches secure, resilient access to datacenters and hubs.
Optimized Routing for Users and 10,000+ Apps Thanks to its advanced first-packet application detection engine, pre-configured with 10,000+ apps, Check Point SD-WAN detects applications from the first packet, and features a flexible out-of-the-box steering policy that delivers enhanced connectivity from day 1.
Networking Policy Customization Offering intuitive, granular policy customization, Check Point SD-WAN lets you define the connection source (e.g. users, groups, devices or networks), the target service (10,000+ preconfigured apps) and the behavior that defines how the traffic will be steered, to achieve a configurable SLA for your connection.
Autonomous Dynamic Traffic Steering To optimize each connection in real time, Check Point SD-WAN provides link health monitoring for jitter, latency, and packet loss with autonomous, dynamic path selection based on application, user or group identity and link health. Link aggregation enables utilizing more bandwidth for local breakout and overlay connectivity.
Intuitive Cloud-based Monitoring, Reporting and Management Powered by the Check Point Platform, Check Point’s cloud-based management, Check Point SD- WAN delivers advanced management, monitoring, and analytics. To enable a quick response to burnouts and failures, the solution provides real time visibility into network health, including an overall view, granular health visibility per branch, and network and SLA metrics.
Rich Portfolio of Firewall Form Factors Check Point SD-WAN is supported by Check Point’s entire portfolio of firewall form factors, including SMB firewalls, enterprise and datacenter firewalls, software deployments (Open Server), cloud native firewalls and ruggedized firewalls.
A Complete SASE Solution Integrating with Check Point SASE, Check Point SD-WAN is part of a single-vendor SASE solution, managed from the Check Point portal, with unified monitoring, logging, security operations (Playblocks) and threat intelligence (ThreatCloud AI).
UNIFYING THE BEST SECURITY WITH OPTIMIZED CONNECTIVITY 3
© 2026 Check Point Software Technologies Ltd. All rights reserved.
Third-party SSE Integrations Check Point SD-WAN features certified integrations with 3rd party security service edge (SSE) providers, including Zscaler and Microsoft Entra SSE, providing flexibility for organizations who prefer dual-vendor SASE or need redundancy-supporting infrastructure.
Hybrid Mesh Network Security Architecture Check Point SD-WAN is part of Check Point’s Hybrid Mesh Network Security architecture that offers distributed enforcement across networks, cloud and remote users for optimized performance and cost, unified security management, flexibility deployment options and consistent security.
• Industry-leading threat prevention
• AI-aware protection for GenAI usage, AI applications and autonomous agents
• Fully converged solution • Mature management • Diverse SASE solutions
Why Choose Secure Check Point SD-WAN? Organizations around the globe, from all industries and sectors, have chosen secure SD-WAN from Check Point thanks to our:
Supported Firewalls & Platforms • Check Point Force Firewalls - Including
VSX, ClusterXL, ElasticXL • Maestro Hyperscale • Open Server • Check Point Cloud Firewalls
• Public Clouds - Azure, AWS, Oracle, Google, VMware
• Private and hybrid clouds - VMware, Cisco ACI/ISE, OpenStack, Nutanix, Nuage
SD-WAN Capabilities • Sub-second failover for overlay
and supported applications • Link aggregation • Link prioritization - according to
Latency, Jitter, and Packet loss
• SLA monitoring – Quality of Service (QoS) per application
• Autonomous link swapping • IPSec VPN AES 128/256, IKEv2
Network services • IPv4, IPv6, DNS, DHCP, NAT
Technical Specifications
Core Networking Capabilities
UNIFYING THE BEST SECURITY WITH OPTIMIZED CONNECTIVITY 4
© 2026 Check Point Software Technologies Ltd. All rights reserved.
Security Firewall Models Check Point SD-WAN supports all the latest Check Point Firewalls. To check for support in specific legacy models, please visit the Check Point SD-WAN page on the product catalog, and then click a specific model.
Licensing • Check Point SD-WAN is available
as a subscription • SD-WAN is licensed per firewall
Model Size TP VPN WAN Type # LAN Ports
Spark 2530 Small Branch Office 0.8 Gbps 1 Gbps RJ45 1G/SFP 1G 6x 1G
Spark 2550 Small Branch Office 1 Gbps 1 Gbps RJ45 1G/SFP 1G 6x 1G
Spark 2560 Small Branch Office 2.1 Gbps 4 Gbps RJ45 1G/SFP 10G 8x RJ45 1G / 2xSFP 10G*
Spark 2570 Small Branch Office 2.5 Gbps 4 Gbps RJ45 1G/SFP 10G 8x RJ45 1G / 2xSFP 10G*
Spark 2580 Small Branch Office 3.2 Gbps 4.5 Gbps RJ45 1G/SFP 1G 8x RJ45 1G + 2xRJ45
Force 3920 Small Branch Office 3.2 Gbps 9.5 Gbps RJ45 1G/SFP 1G 8x RJ45 1G + 2xRJ45
Force 3950 Small Branch Office 5.5 Gbps 17.5 Gbps RJ45 1G/RJ45 10G* 8x RJ45 1G + 2xRJ45 2.5G +
Force 3970 Medium Branch Office 4.2 Gbps 13 Gbps RJ45 1G/SFP 1G* 16x RJ45 1G + 2xRJ45
Force 3980 Medium Branch Office 7 Gbps 23 Gbps RJ45 1G/SFP 1G* 16x RJ45 1G + 2xRJ45
Force 9100 Medium Enterprise 6.5 Gbps 22.1 Gbps RJ45 1G/RJ45 1G* 8x RJ45 1G + 8xSFP
Force 9200 Medium Enterprise 8 Gbps 28.6 Gbps RJ45 1G/RJ45 1G* 8x RJ45 1G + 8xSFP
Force 9300 Medium Enterprise 10.5 Gbps 33 Gbps RJ45 1G/RJ45 1G* 8x RJ45 1G + 8xSFP
Force 9400 Medium Enterprise 14 Gbps 40 Gbps RJ45 1G/RJ45 1G* 8x RJ45 1G + 4xSFP
Force 9700 Large Enterprise 20 Gbps 75 Gbps RJ45 1G/RJ45 1G* 4x RJ45 1G + 4xSFP
Force 9800 Large Enterprise 25 Gbps 75 Gbps RJ45 1G/RJ45 1G* 4x RJ45 1G + 4xSFP
5
Worldwide Headquarters 5 Shlomo Kaplan Street, Tel Aviv 6789159, Israel | Tel: +972-3-753-4599
U.S. Headquarters 100 Oracle Parkway, Suite 800, Redwood City, CA 94065 | Tel: 1-800-429-4391
www.checkpoint.com
© 2026 Check Point Software Technologies Ltd. All rights reserved.
UNIFYING THE BEST SECURITY WITH OPTIMIZED CONNECTIVITY
Model Size TP VPN WAN Type # LAN Ports
Force 19100 Large Enterprise 35 Gbps 75.3 Gbps - 8xSFP 1/10/100G X4**
Force 19200 Large Enterprise 44 Gbps 86 Gbps - 8xSFP 1/10/100G X4**
Force 29100 Data Center 60 Gbps 103 Gbps - 8xSFP 1/10/100G X7**
Force 29200 Data Center 75 Gbps 130 Gbps - 8xSFP 1/10/100G X7**
Firewall Models
Figure 1 Check Point SD-WAN Dashboard Figure 2 Check Point SD-WAN Policy Configuration
Learn more Get a demo
https://www.sase.checkpoint.com/demo https://www.checkpoint.com/quantum/sd-wan/ https://pages.checkpoint.com/quantum-sd-wan-demo-request.html