Checkpoint introduced Application control policies in their R75 version recently, while traditional firewalls like ASA and SRX perform control based on protocols, ports and IP, the new next generation firewalls in addition provides granular control by application and users using these applications.
The only other vendor doing this in the security space is a new company called Paloalto networks which appears to have initiated this concept for good.
The checkpoint App wiki is a great resource to see what application controls are possible.
Warning, performing the below actions will do a cpstop & cpstart.
Using CLI
> Login to the Checkpoint Nokia appliance
> Type ‘cpconfig’
> Select ‘SNMP Extension’
> Select ‘y’ to activate the SNMP daemon
> Exit
Using Voyager
> Login > Configuration > SNMP
Use the command below to gracefully failover Checkpoint Splat firewalls in cluster.
clusterXL_admin <up|down>
To install Eventia Reporter on an already installed checkpoint system,
> run the command sysconfig.
> Select option ‘Product Installation’
This option is not available using the browser. Note that you will need to have a license to use this feature and its licensed per gateway.