The Check Point Security Gateway is a network security device that provides stateful firewalling, network address translation (NAT), and enforces centrally managed security policies. It inspects network traffic to identify and control applications, categorize websites, and block malicious files, exploit attempts, and bot communications. The gateway can decrypt and inspect SSL/TLS traffic, scan for malware, and use sandboxing (threat emulation) and file sanitization (threat extraction) to counter zero-day threats. It enforces network segmentation, manages bandwidth allocation, and prevents the unauthorized transmission of sensitive data by associating traffic with user identities. The device also establishes encrypted VPN tunnels for both site-to-site and remote user connections and forwards logs of traffic and security events to a central management system.