I like the Checkpoint appliance it would be configured in an Active/Passive HA config and the application control and IPS policy creation look really easy to manage however the throughput figures from the sales blurb 'look' over exagerrated and possibly don't reflect a live network environment and I'm not convinced that they are capable of detecting AETs (Advanced Evasion Techniques)