Avantec AG
Zug
Check Point SD-WAN in its Infancy – Tec-Bite IT Security
- 08 August 2026
- 100%
- Permanent position
- Zug
About the job
SD-WAN is finally becoming a topic at the security vendor with the new pink logo. Until now, Check Point held the position that SD-WAN should be operated separately from the firewall. SD-WAN was supposed to be done with the classic SD-WAN manufacturers like Cisco, VMware, Versa, Aruba. However, there are of course also competitors who have been successfully offering SD-WAN and security for years and thus bring corresponding experience.Sleeping on the JobIn my opinion, Check Point has slept on the topic and therefore lost one or two projects. After all, it is simply compelling not to have to buy from two manufacturers and to be able to operate SD-WAN integrated on the firewall.Early AvailabilityThere is currently an Early Availability (EA) programme running, which should be coming to a close soon. So far, mid-2022 has always been communicated for the General Availability (GA) release. The GA code is to be integrated in R81.10 via Jumbo Hotfix.Reality CheckWe repeatedly registered for the EA programme but unfortunately did not get a chance. Check Point only wanted to conduct their programme with real, productive customer environments. Lab environments were apparently too little reality-based. Speaking of which – which sensible IT manager, concerned with trouble-free operation, would agree to such an EA programme? I mean, who would risk sabotaging or impairing their internet access with unfinished software? I do not know. In any case, I did not dare to ask any of our customers with a clear conscience.Lively ExchangeAt least Check Point is keen on lively exchange with us and other partners. Already in October 2021, there was a meeting where we could review a mock-up of their SD-WAN solution and provide feedback on what was shown. At the end of June, there was another meeting where we were asked for our opinion. We were happy to provide information, including about our experience with Fortinet, which Check Point took great interest in. In the meantime, they even met with the PM in Spreitenbach and in Tel Aviv.FeaturesWhat I have learned so far is of course without guarantee. Features shown in an EA programme can still be dropped and others not shown can still be added. Here are the features that should be included in the first GA release:Multiple WAN link support – which is the minimum, without it there is no SD-WAN.Application & Identity based routingMulti Path OrchestrationHub and Spoke Overlay (+MEP)Autonomous traffic steeringBandwidth aggregationHigh AvailabilitySD-WAN Monitoring, Logging & AnalyticsFull Threat Prevention CapabilitiesThe management of SD-WAN is controlled via the Infinity Portal. Objects and logs can be exchanged with the on-premise SmartCenter.RoadmapThe roadmap includes the following topics:Quantum Spark (SMB) supportSelf-healing WANFull Mesh OverlayHarmony Connect (SASE)QoSAdditional Platforms (VSX, Maestro)Large scale managementDiverse Connectivity: WLAN, 4G/5G, DSLlicensingRumour has it that there could be a separate licence. In my opinion, however, this should be included as a basic function in the FW blade or bundled with NGFW. SD-WAN usually requires AppControl anyway to be able to control SD-WAN based on applications.Best AppControlBy the way, Check Point’s AppControl is said to support more applications than any other SD-WAN manufacturer. For SD-WAN, however, the usual suspects such as Teams, O365, Google Workspace, Webex, GotoMeeting, Salesforce and other SaaS services will probably suffice. Other applications will probably be used more for exotic use cases.PricingPrices are of course not yet known. Let us hope that Check Point does not want to make the development of SD-WAN prohibitively expensive. However, I still remember that if you wanted to use 3DES in the VPN, an extra licence was also required back then.PromisingAll in all, the course that Check Point has taken seems promising to me. Check Point now has the chance as a laggard to learn from the competition. It will probably take another year or two until the product reaches maturity to be used productively. Check Point has a lot to catch up on, but I certainly trust that Check Point can do it.The article Check Point SD-WAN in its Infancy first appeared on Tec-Bite.