White Paper | Check Point Cloud Firewall for Amazon Web Services
Learn how Check Point Cloud Firewall for Amazon Web Services secures cloud-native environments with advanced threat prevention, automated security orchestration, centralized management, cloud integration, scalable architecture, and unified visibility for AWS cyber security.

© 2025 Check Point Software Technologies Ltd. All rights reserved.
About This Document
With Check Point Cloud Firewall on AWS, customers gain advanced threat prevention,
unified management, and automated protection that scales seamlessly with their cloud
workloads. This document outlines the key features and capabilities of Check Point Cloud Firewall on AWS and its native integration with Amazon Web Services (AWS),
providing a comprehensive breakdown of deployment models, security functions,
automation and scaling mechanisms, content security, monitoring, and advanced
networking features, designed to help organizations secure dynamic, cloud-native
environments with maximum flexibility and visibility.
Contents
Check Point Cloud Firewall Components and Architecture ........................................................................... 1
Performance ................................................................................................................................................. 2
Deployment ................................................................................................................................................... 3
Management, Visibility, and Monitoring ........................................................................................................ 3
Security ......................................................................................................................................................... 4
Cloud Integration & Automation ................................................................................................................... 5
Network Features ......................................................................................................................................... 5
Check Point Cloud Firewall for Amazon Web Services
Architecture, Performance, Features, and Capabilities.
© 2025 Check Point Software Technologies Ltd. All rights reserved.
CHECK POINT CLOUD FIREWALL FOR AWS
CHECK POINT COMPONENTS AND ARCHITECTURE 1
Check Point Cloud Firewall Components and Architecture
m t ou
Central Management
Check Point ou Firewall Configurator Synchroni e Policies and Gateway Pro isioning
martConsole ni ersal Policies o s ents
Automatic ate a pro isionin Polic pac a e assi nment
Policy packages, logs, object DB, configs, etc.
Check Point Dynamic Policy Enabler Automatic Ad ustment to Cloud Changes
namic polic push Cloud ob ects import
Pro isionin metadata, tunnel
info, etc. eplo ment templates, disco er tri ers
a P updates, deleted assets disco er metadata.
Cloud A Connector
u ti b i ou s
PC to PC ransit ate a , ate a oad alancer, Cloud A
ate a s ate a s ate a s
© 2025 Check Point Software Technologies Ltd. All rights reserved.
CHECK POINT CLOUD FIREWALL FOR AWS
PERFORMANCE 2
erformance Check Point Cloud Firewall R81.20 – AWS C6in VMs
Capability Tested 2 vCPU 4 vCPU 8 vCPU 16 vCPU
New connections handled per second 815,527 1,847,153 3,957,108 8,048,880
Maximum simultaneous connections (Firewall only) 42,700 67,300 140,000 150,000
Firewall with Intrusion Prevention (Gbps) 8.30 11.00 14.70 20.00
Firewall with Intrusion Prevention and App Control
(Gbps) 3.40 7.40 13.80 19.50
Full Threat Prevention Suite (Gbps) 2.50 5.30 11.20 19.50
Encrypted HTTPS with Firewall and IPS only (Gbps) 1.00 2.00 4.40 8.90
Encrypted HTTPS with Threat Prevention (Gbps) 0.60 1.20 2.40 5.40
Remote access VPN* - Simultaneous users (with
firewall & IPS) 500 1,000 1,700 2,900
Remote access VPN* - Simultaneous users (with
complete threat prevention) 400 750 1,500 2,500
N :
• F w w h I u P d A throughput is measured using Check
Point enterprise testing conditions
• Th fu Th P u includes firewall, intrusion pre ention, application control, URL
filtering, anti irus protection, and anti bot protection
• E d ff f is measured for HTTPS traffic using the same inspection profiles
• R VPN u is estimated based on ideal lab conditions and may ary in real
world deployments
• F w w h - - VPN was tested using the iPerf tool with UDP traffic and 1300 byte packet
si e under controlled conditions
• Accu c n e ±3% For items marked with *, the accuracy range is ±15%
© 2025 Check Point Software Technologies Ltd. All rights reserved.
CHECK POINT CLOUD FIREWALL FOR AWS
DEPLOYMENT 3
Deployment • Auto c in uppo t in AW Supports Auto Scaling Groups, pro isioning or terminating Check
Point Gateways based on demand, ensuring elasticity and cost efficiency
• Auto c in nte tion vi Check Point Cloud Firewall Configurator Keeps track of auto scale e ents, ensuring new instances are disco ered and decommissioned ones are remo ed from
management
• te Dep o ment n Onbo in vi Token Gateways use a one time SIC token embedded in
templates for secure registration with the management ser er
• A v nce Temp te B se P ovisionin Templates define the gateway configuration, including
software blades, policies, and custom scripts, ensuring consistency across deployments
• Autom tic otfi Dep o ment Installs pre appro ed hotfix packages during pro isioning to ensure
gateways are fully patched from the start
• uppo t fo AW T nsit te n te Lo B nce Enables integration with ad anced
AWS networking constructs like TGW and GWLB for scalable, centrali ed traffic inspection
Management, Visibility, and Monitoring • ent ize ou B se n ement Smart 1 Cloud pro ides unified, cloud hosted security
management for all gateways and policies
• ecu it Po ic n ement n m t onso e Access Offers full featured policy and ob ect
management through SmartConsole, with web, desktop, and streamed access options
• nu Pe missions n A nte tion fo AW Uses IAM roles, STS Assume Role, or
credentials for secure, cloud nati e authentication and authori ation
• Re Time Up tes n TTL pi tion ont o Cloud ob ects ha e configurable TTLs to pre ent
stale data; the system refreshes information regularly
• Limit tions to Note Certain legacy features e g , VSX, SmartPro isioning, LEA are excluded from
cloud based management
• Lo Retention n po t to Supports log forwarding in multiple formats Syslog, LEEF, etc
to SIEMs like Splunk, QRadar, and ArcSight
• onito in , Lo in , n nte tion ith AW ecu it ub Sends threat detection logs and
findings to AWS Security Hub for centrali ed isibility and incident response
• Lo Visibi it n T oub eshootin nh ncements Logs include rich metadata such as scan times
and ob ect names for better debugging and forensics
© 2025 Check Point Software Technologies Ltd. All rights reserved.
CHECK POINT CLOUD FIREWALL FOR AWS
SECURITY 4
Security • tensive B e uppo t vi Temp tes Gateways can be pro isioned with a wide range of blades,
including Intrusion Pre ention, VPN, HTTPS Inspection, Application Control, and more
• Autonomous Th e t P evention Deli ers smart threat pre ention without needing fine tuned rule
definitions, ideal for dynamic en ironments
• uppo t fo VPN, NAT, n entit A eness Full support for secure tunneling, address
translation, and user identity based policy enforcement
• entit h in fo Auto c in te s Auto Scaling instances can recei e user identity data
from static PDPs, enabling consistent enforcement
• Use of T s in ecu it Po icies Enables tag based policies that automatically follow the lifecycle
of cloud resources e g , en =prod, role=db
• Po ic Objects ith D t ente Que ies Dynamic ob ects can be queried across cloud pro iders
and used in policies without hardcoding IPs
• Net o k oup Objects e te Pe c e et Automatically created and updated ob ects group all
members of an auto scaling set for use in policy rules
• Autom tic NAT n Access Ru e e tion Dynamically generates NAT and access rules based on
tags and listener configuration, reducing manual effort
• D n mic Use B se Po ic Enforces user and role based access control by integrating with
Microsoft Acti e Directory, LDAP, RADIUS, Cisco pxGrid, Terminal Ser ices, or third party identity
sources ia Web API Supports consistent policy enforcement across Windows, macOS, Linux,
Android, and iOS platforms
• Fi st Time P evention p bi ities Includes OS le el and static file analysis, file saniti ation ia
Threat Extraction, and full sandbox emulation for unknown files under 100 seconds on a erage
• App ic tion ont o Includes tens of thousands pre defined application signatures and allows
custom definitions Administrators can accept, block, schedule, or apply bandwidth shaping to
application traffic
• D t Loss P evention DLP Identifies and classifies o er 700 pre defined data types, enabling
sensiti e data protection Includes mechanisms for end user alerts and data owner escalation
workflows
© 2025 Check Point Software Technologies Ltd. All rights reserved.
CHECK POINT CLOUD FIREWALL FOR AWS
CLOUD INTEGRATION & AUTOMATION 5
Cloud ntegration & Automation • AW Object nte tion VP s, ubnets, nst nces, T s, n o e Automatically disco ers and
synchroni es AWS nati e ob ects such as EC2 instances, subnets, security groups, and tags, making
them a ailable as dynamic ob ects in the policy layer
• n ement n onito in ith AP s, Te fo m, n m t onso e Offers complete lifecycle
control ia REST APIs and Terraform for De Ops teams while pro iding intuiti e GUI access through
SmartConsole for security operations and analysts
• uppo t fo u ti Account n u ti Re ion AW nvi onments Enables centrali ed management
across multiple AWS accounts and regions through Check Point Cloud Firewall Configurator and role based access, ensuring secure and scalable cloud deployments
tools like autopro _cfg, cme_menu, and Check Point Dynamic Policy Enabler REST API, enabling powerful customi ation and scripting
• oss P tfo m entit n Po ic nte tion Integrates with Microsoft AD, LDAP, RADIUS, pxGrid,
and other third party identity sources, enabling consistent policy enforcement across cloud nati e,
hybrid, and remote user scenarios
Network Features • A v nce Net o kin p bi ities Supports Acti e/Acti e Layer 2, Acti e/Passi e Layer 2, and
Layer 3 configurations non applicable to CSPs with session failo er across routing changes, de ice
failures, and link disruptions
• Pv6 uppo t Includes NAT66 and performance optimi ation features such as CoreXL and SecureXL
• Routin u tic st Supports dynamic and static routing protocols, including OSPF 2, BGP, RIP,
policy based routing, and multicast protocols such as PIM SM, PIM DM, and IGMP 2/ 3
Read more about Check Point Cloud Firewall for public clouds
Find the deployment that's right for you on AWS Marketplace
Wo i e e qu te s
5 Shlomo Kaplan Street, Tel A i 6789159, Israel | Tel +972 3 753 4599
U. . e qu te s
100 Oracle Parkway, Suite 800, Redwood City, CA 94065 | Tel 1 800 429 4391
.checkpoint.com
© 2026 Check Point Software Technologies Ltd All rights reser ed
Fin Us On
• Configuration Tools: Supports flexible provisioning and automation workflows using
https://www.checkpoint.com/cloudguard/cloud-network-security/ https://aws.amazon.com/marketplace/pp/prodview-3xp7nph2367yc