Check Point Next Generation Firewall for 5900 High Availability
Check Point 5900 Next Generation Firewall for High Availability: The Mid-Size Enterprise Buyer’s Guide
When downtime isn’t an option, a single firewall appliance — no matter how powerful — is a liability. That’s the thinking behind deploying the Check Point 5900 Next Generation Security Gateway in a High Availability (HA) pair: two appliances, one synchronized security policy, and zero single point of failure. In this guide, we break down what the 5900 delivers on paper, what it actually delivers once you factor in real-world traffic, how HA changes the deployment math, and how it stacks up against the Cisco Firepower alternatives IT teams often shortlist alongside it.
Whether you’re refreshing an aging perimeter firewall, consolidating point security products into a single gateway, or building out a data center edge that simply cannot go dark during a failover event, the 5900 is one of Check Point’s most deployed mid-size enterprise appliances — and understanding its HA behavior is the difference between a resilient network and an expensive outage.
Why the 5900 Exists: Positioning in the Check Point Lineup
The 5900 sits at the top of Check Point’s 5000 series, purpose-built for mid-size enterprises and branch consolidation points that need data-center-grade throughput without the footprint or cost of Check Point’s 15000 or 23000 series. It ships as a 1U, rack-mountable appliance with 8 built-in 10/100/1000Base-T copper ports and two expansion slots for additional 1GbE or 10GbE modules, giving network architects flexibility to mix copper and fiber uplinks on the same box.
Under the hood, the 5900 runs Check Point’s unified security architecture, meaning firewall, IPS, application control, URL filtering, antivirus, anti-bot, and SandBlast zero-day sandboxing all operate on the same policy engine instead of bolted-on modules. That consolidation is what makes HA deployments cleaner: there’s a single state table to synchronize between nodes, not a patchwork of independent services each with their own failover behavior.
Quick Take
The 5900 pairs 8x1GbE onboard ports and modular expansion slots with up to 52 Gbps of raw firewall throughput, then relies on ClusterXL or VRRP-based HA to keep that capacity online through hardware failure, software upgrades, or planned maintenance — with sub-second failover in most configurations.
Performance at a Glance: Colorful Spec Blocks
Check Point publishes performance under two conditions: “ideal testing conditions” (lab benchmarks with large packet sizes and minimal blade stacking) and “real-world / production conditions” (mixed traffic, full Threat Prevention stack enabled, smaller packets). Both numbers matter — the first tells you the ceiling, the second tells you what to actually budget for. Here’s the 5900 broken into both:
Firewall Throughput
52 Gbps
ideal / UDP 1518B • 26 Gbps real-world
IPS Throughput
13.5 Gbps
ideal • 4.36 Gbps real-world
NGFW Throughput
11.4 Gbps
ideal • 2.84 Gbps real-world
Threat Prevention
2.7 Gbps
ideal • 1.4 Gbps real-world
VPN Throughput (AES-128)
10.2 Gbps
ideal testing conditions
Concurrent Connections
3.2M / 6.4M
base memory / HPP memory
That gap between “ideal” and “real-world” numbers is exactly why sizing an HA pair correctly matters. If your production traffic profile leans on IPS and full Threat Prevention (the blades most organizations actually run in an “always-on” posture), plan around the real-world figures — 26 Gbps firewall, 2.84 Gbps NGFW, 1.4 Gbps Threat Prevention — not the headline ideal-condition numbers.
Visual Chart: Ideal vs. Real-World Throughput
Throughput comparison (Gbps) — lab conditions vs. production traffic
Top bar (bright) = ideal lab conditions. Bottom bar (dark) = real-world production conditions, scaled against the firewall’s 52 Gbps ceiling.
High Availability: How the 5900 Stays Online
Deploying two 5900 appliances in HA isn’t just about buying a spare box — it changes how the network behaves during failure events. Check Point supports two primary approaches for the 5900:
- ClusterXL (Active/Standby or Active/Active): Check Point’s native clustering technology synchronizes the connection state table between both appliances in real time. If the active gateway fails, the standby takes over existing sessions without dropping them — no re-authentication, no dropped VPN tunnels, no TCP resets for end users.
- VRRP-based HA: A more standards-based approach for environments that need interoperability with third-party HA tooling or simpler Layer 3 failover logic, at the cost of some Check Point-specific state-sync features.
In both models, the HA pair should be treated as a single logical enforcement point in your topology. Each appliance needs its own dedicated sync interface (typically a direct cable or dedicated VLAN between the two units, separate from production traffic) to replicate session state fast enough that failover is imperceptible to users. Most well-configured 5900 HA pairs achieve failover in well under three seconds — often sub-second for pure Layer 3/4 sessions — which is fast enough that TCP connections survive without retransmission timeouts in the vast majority of cases.
HA also changes your capacity planning. A common mistake is sizing a single 5900 to your peak load and assuming the HA partner is “free” headroom. In an Active/Standby pair, the standby unit sits idle from a traffic-processing perspective until failover — so your real capacity is one unit’s worth of throughput, not two. If you need combined capacity under normal conditions, Active/Active clustering distributes load across both nodes, but requires more careful policy and routing design to avoid asymmetric flows.
Design tip: Budget for real-world throughput on a single node in an Active/Standby HA pair, not the combined ideal-condition figure of two appliances. If a single 5900 delivers 26 Gbps of real-world firewall throughput, that’s your usable ceiling during normal operations and during a failover event alike.
Full Data Sheet & Specifications
| Specification | Details |
|---|---|
| Form Factor | 1U, rack-mountable |
| Onboard Ports | 8x 10/100/1000Base-T (RJ-45) copper |
| Expansion Slots | 2 total, supporting additional 1GbE / 10GbE modules |
| Base Memory | 8 GB (HPP and maximum memory configurations available) |
| Storage | SSD storage options available |
| Power | AC power supply standard; DC power and redundant AC configurations available |
| Management | Lights-Out Management (LOM) supported |
| Firewall Throughput (Ideal) | 52 Gbps (UDP 1518-byte packets) |
| Firewall Throughput (Real-World) | 26 Gbps |
| IPS Throughput | 13.5 Gbps ideal / 4.36 Gbps real-world |
| NGFW Throughput | 11.4 Gbps ideal / 2.84 Gbps real-world |
| Threat Prevention Throughput | 2.7 Gbps ideal / 1.4 Gbps real-world |
| VPN Throughput (AES-128) | 10.2 Gbps |
| Connections per Second | 185,000 (64-byte response) |
| Concurrent Connections | 3.2M (base memory) / 6.4M (HPP memory) |
| SecurityPower Units (Real-World) | 2,400 SPU |
| Max Virtual Systems | 10 (base) / 20 (HPP) / 20 (max memory) |
| Security Packages | NGTP (Next Generation Threat Prevention) and NGTX (adds SandBlast Zero-Day Protection) |
| Software Blades Included | Firewall, VPN, Application Control, URL Filtering, IPS, Antivirus, Anti-Bot, Identity Awareness, and optionally SandBlast Threat Emulation/Extraction |
| HA Options | ClusterXL (Active/Standby, Active/Active) and VRRP |
Note: performance figures are Check Point-published benchmarks and can vary based on software version, blade combination, and traffic profile. Always validate sizing against your own traffic mix before finalizing a purchase.
NGTP vs. NGTX: Which Package for an HA Deployment?
Check Point sells the 5900 under two software packages, and the choice matters more in an HA context than people expect, since both nodes need matching licensing and blade configurations to synchronize cleanly.
NGTP
Application Control, URL Filtering, IPS, Antivirus, Anti-Bot, and Email Security — the baseline for most branch and mid-size enterprise deployments.
NGTX
Everything in NGTP, plus SandBlast Zero-Day Protection with Threat Emulation and Threat Extraction — recommended if your HA pair is protecting a data center edge exposed to inbound file traffic.
Both packages, along with the appliance itself, are sold with dedicated HA SKUs — the license and support pricing for a two-node HA pair is typically lower per-appliance than pricing two standalone units independently, since the secondary node’s package is discounted under Check Point’s HA licensing model.
Check Point 5900 HA vs. Cisco Firepower: The Comparison Teams Actually Ask For
If you’re evaluating the 5900 alongside Cisco’s Firepower 2100/4100 series for an HA firewall refresh, the decision usually comes down to three things: unified policy management, throughput-per-dollar at your real traffic profile, and how each vendor’s HA/clustering model fits your existing operations team’s skill set.
- Management model: Check Point’s Smart-1 / Security Management Server centralizes policy across the HA pair and any additional gateways from one console. Cisco’s equivalent is Firepower Management Center (FMC), which many teams find heavier to operate at mid-size scale.
- Failover behavior: ClusterXL’s stateful sync is generally regarded as mature and well-documented; Cisco’s Firepower Threat Defense HA is comparable in capability but historically has had more caveats around feature parity during active/standby transitions.
- Threat Prevention stack: Both vendors bundle IPS, AV, and sandboxing, but licensing structures differ significantly — this is exactly the kind of variable that benefits from a side-by-side quote rather than list-price comparison.
Because Cisco and Check Point pricing, bundle structures, and current promotions change frequently — and because an apples-to-apples comparison depends heavily on your specific throughput and blade requirements — we recommend requesting a direct quote comparison rather than relying on list pricing alone.
Request For Quote
RFQ: Check Point 5900 HA vs. Cisco Firepower — Get a Side-by-Side Quote
Comparing the Check Point 5900 HA pair against a Cisco Firepower alternative for your environment? Send us your current throughput requirements, port count, and Threat Prevention needs, and we’ll return a like-for-like quote covering both vendors — hardware, HA/clustering licensing, and support terms — so you can compare real numbers instead of list price sheets.
Email your RFQ to:
Include site count, required throughput, current firewall model (if replacing), and preferred HA topology for the fastest turnaround.
Deployment Checklist Before You Order
- Confirm real-world throughput needs against the 26 Gbps firewall / 2.84 Gbps NGFW / 1.4 Gbps Threat Prevention figures, not the ideal-condition numbers.
- Decide between Active/Standby and Active/Active ClusterXL based on whether you need combined throughput during normal operations.
- Reserve a dedicated sync interface (or VLAN) between both HA nodes, isolated from production traffic.
- Choose NGTP or NGTX based on whether inbound file-based threats (email attachments, web downloads) are a primary concern.
- Validate expansion slot needs now — retrofitting 10GbE modules later means a maintenance window on a production HA pair.
- Request HA-specific SKUs and pricing rather than pricing two standalone units, since HA licensing is typically discounted.
Final Thoughts
The Check Point 5900 remains one of the more balanced choices for mid-size enterprises that need real Threat Prevention throughput without stepping up to Check Point’s data-center-class hardware. Deployed as an HA pair with ClusterXL, it gives you both the resilience to survive hardware failure without dropping sessions and a straightforward path to centralized management across your broader Check Point estate. The math that matters most is simple: size to real-world throughput, plan your HA topology before you order, and get your Cisco comparison in writing before you commit budget.
Have questions about sizing an HA pair for your specific traffic profile, or want that Cisco Firepower comparison quote? Reach out to [email protected] and we’ll put real numbers in front of you.
