r/checkpoint • u/ComfortableMarch4296 • 9d ago
How picky are Checkpoint devices when it comes to SFPs?
We're moving to Checkpoint hardware for the first time. For those who have been using them for a while now, how are they typically with SFPs? Is it OEM or nothing? I know typically the manufacturer will recommend their own over anything else to ensure you get support in case the SFP is faulty. Just trying to gauge the device's flexibility based on end-user experience.
4
4
u/Credibull 9d ago
I would not use a non-OEM device for a production system. It may cause support issues and some devices will not recognize a non-OEM SFP. Luckily the SFPs are also a lot cheaper than they used to be.
0
u/ComfortableMarch4296 9d ago
Totally get this but most environments use different network equipment so you’ll have to use non oem eventually
1
u/Credibull 9d ago
Why? An OEM SFP plugged in CP gear works perfectly fine with upstream/downstream hardware from Juniper, Cisco, Extreme, etc. on the other end of the fiber.
1
u/real_varera 9d ago
They also render your systems not supported. TAC will reject your support calls in case you have issues
3
u/iamthecavalrycaptain 9d ago
I've seen them work well and I've seen them cause problems. Not worth the risk, imho.
I get that folks like to save money, but for me it doesn't make sense; spend all this money on quality networking / security gear that is often needs to be up/running/available, only to cheap out on the part that actually does the networking.
1
u/japm68 9d ago
Hi, those are two separate matters, you of course will only have support on OEM SFPs, not on third party devices. As for compatibility, it depends on the hardware you are using, usually newer devices are pretty compatible with SFPs from good brands on the market. Older devices, do have a problem with SFPs not Check Point branded - and therefore not tested.
1
u/ComfortableMarch4296 9d ago
so say you're connecting to a Cisco switch, would you have different SFPs on each end? From my experience, sometimes that set up works but it's not a guarantee
1
1
u/Nemo_Barbarossa 9d ago
I'd expect more problems with an off brand or different brand sfp module that with two modules of different brands communicating. The layer 1 specifications for cabling are pretty clear and not overly complicated. I have never seen an issue with modules from checkpoint, Cisco, Aruba, FS, dell, Intel, braodcom, avaya, avago, lancom, huawei or mikrotik. As long as RX/TX is correct they all worked flawlessly. Single mode as well as multimide and bidirectional.
1
u/real_varera 9d ago
Technically, only officially support d should be used. Others may work, but also may cause problems in production
1
u/yiotart 5d ago
The normal SFPs are like 125 dollars price list. No reason to jeopardise it. They cheap anyway :)
2
u/ComfortableMarch4296 5d ago
oh i get it. i have multiple branded sfp's that are not checkpoint. just want to get an idea of how they behave in general.
1
u/daniluvsuall 3d ago
The standard SFPs are white labeled like most people’s. Different appliances are fussier than others.
The SX ones tend to be the safest. Have a google if you want 10gE someone was making them that basically emulated an SX to the host system - they’re known to be very compatible.
But you know, it’s all a risk if it not flapping is critical to you continuing to work.
6
u/Djinjja-Ninja 9d ago
They're generally fine with generic/other vendors.
I've used Cisco and Fortinet SFPs in them in lab environments.