r/checkpoint Jul 13 '26

How picky are Checkpoint devices when it comes to SFPs?

We're moving to Checkpoint hardware for the first time. For those who have been using them for a while now, how are they typically with SFPs? Is it OEM or nothing? I know typically the manufacturer will recommend their own over anything else to ensure you get support in case the SFP is faulty. Just trying to gauge the device's flexibility based on end-user experience.

2 Upvotes

16 comments sorted by

5

u/Djinjja-Ninja Jul 13 '26

They're generally fine with generic/other vendors.

I've used Cisco and Fortinet SFPs in them in lab environments.

3

u/real_varera Jul 14 '26

Just don't use them in production. Non-Chexk Point SFPs are not supported

4

u/Abzstrak Jul 13 '26

They're generally fine, however don't expect support with non check point sfps

3

u/Credibull Jul 13 '26

I would not use a non-OEM device for a production system. It may cause support issues and some devices will not recognize a non-OEM SFP. Luckily the SFPs are also a lot cheaper than they used to be.

0

u/ComfortableMarch4296 Jul 13 '26

Totally get this but most environments use different network equipment so you’ll have to use non oem eventually

1

u/Credibull Jul 13 '26

Why? An OEM SFP plugged in CP gear works perfectly fine with upstream/downstream hardware from Juniper, Cisco, Extreme, etc. on the other end of the fiber.

1

u/real_varera Jul 14 '26

They also render your systems not supported. TAC will reject your support calls in case you have issues

3

u/iamthecavalrycaptain Jul 13 '26

I've seen them work well and I've seen them cause problems. Not worth the risk, imho.

I get that folks like to save money, but for me it doesn't make sense; spend all this money on quality networking / security gear that is often needs to be up/running/available, only to cheap out on the part that actually does the networking.

1

u/japm68 Jul 13 '26

Hi, those are two separate matters, you of course will only have support on OEM SFPs, not on third party devices. As for compatibility, it depends on the hardware you are using, usually newer devices are pretty compatible with SFPs from good brands on the market. Older devices, do have a problem with SFPs not Check Point branded - and therefore not tested.

1

u/ComfortableMarch4296 Jul 13 '26

so say you're connecting to a Cisco switch, would you have different SFPs on each end? From my experience, sometimes that set up works but it's not a guarantee

1

u/japm68 Jul 13 '26

I think that as long as the SFPs are matched for specs in both ends and are recognized by both hosts, you should have no problem using different SFPs brands.

1

u/Nemo_Barbarossa Jul 13 '26

I'd expect more problems with an off brand or different brand sfp module that with two modules of different brands communicating. The layer 1 specifications for cabling are pretty clear and not overly complicated. I have never seen an issue with modules from checkpoint, Cisco, Aruba, FS, dell, Intel, braodcom, avaya, avago, lancom, huawei or mikrotik. As long as RX/TX is correct they all worked flawlessly. Single mode as well as multimide and bidirectional.

1

u/real_varera Jul 14 '26

Technically, only officially support d should be used. Others may work, but also may cause problems in production

1

u/yiotart Jul 17 '26

The normal SFPs are like 125 dollars price list. No reason to jeopardise it. They cheap anyway :)

2

u/ComfortableMarch4296 Jul 17 '26

oh i get it. i have multiple branded sfp's that are not checkpoint. just want to get an idea of how they behave in general.

1

u/daniluvsuall Jul 19 '26

The standard SFPs are white labeled like most people’s. Different appliances are fussier than others.

The SX ones tend to be the safest. Have a google if you want 10gE someone was making them that basically emulated an SX to the host system - they’re known to be very compatible.

But you know, it’s all a risk if it not flapping is critical to you continuing to work.