Datasheet | Check Point Cloud Firewall for Microsoft Azure

Datasheet | Check Point Cloud Firewall for Microsoft Azure

Technical overview of Check Point Cloud Firewall for Microsoft Azure, covering architecture, performance, deployment models, automation, threat prevention, cloud integration, scaling, and network security capabilities. Helps organizations secure Azure environments with automated, scalable cyber security controls.

Datasheet | Check Point Cloud Firewall for Microsoft Azure

© 2026 Check Point Software Technologies Ltd. All rights reserved.

About This Document

This document contains a comprehensive technical breakdown of the Check Point

Cloud Firewall (previously known as CloudGuard). The breakdown includes features,

performance, deployment models, automation and scaling mechanisms, and advanced

networking features; All of which are designed to help organizations secure dynamic,

cloud-native environments on Microsoft Azure with maximum flexibility and visibility.

Contents

Check Point Components and Architecture .................................................................................................. 1

Performance ................................................................................................................................................. 2

Deployment ................................................................................................................................................... 2

Management, Visibility, and Monitoring ........................................................................................................ 3

Security ......................................................................................................................................................... 4

Cloud Integration & Automation ................................................................................................................... 4

Network Features ......................................................................................................................................... 5

Check Point Cloud Firewall for Microsoft Azure Architecture, Performance, Features, and Capabilities.

© 2026 Check Point Software Technologies Ltd. All rights reserved.

CHECK POINT CLOUD FIREWALL FOR AZURE

CHECK POINT COMPONENTS AND ARCHITECTURE 1

Check Point Components and Architecture

m t ou centrally manages e erything, interoperable with SmartConsole

deploys gateways using predefined templates

ont o e syncs dynamic ob ects from cloud to policy

Th e t ou A not shown pro ides real time threat intelligence to gateways and collects data from them

m t ou Deployed as a SaaS

ont o e Deployed on the management ser er Smart 1 Cloud or on prem

te s Firewalls irtual or F aaS deployed in Nets, usually as part of Virtual Machine Scale Sets

m t ou

Central Management

ou n ement tension

Synchroni e Policies and ateway Pro isioning

martConsole ni ersal Policies o s ents

Automatic ate a pro isionin Polic pac a e assi nment

Polic pac a es, lo s, ob ect , confi urations, etc.

ou ont o e

Automatic Ad ustment to Cloud Changes

namic polic push Cloud ob ects import

Pro isionin metadata, tunnel

info, etc. eplo ment templates, disco er tri ers

a P updates, deleted assets disco er metadata.

Cloud AP Connector

u ti b i ou s

et to et irtual A , P , As,

ate a s ate a s ate a s

© 2026 Check Point Software Technologies Ltd. All rights reserved.

CHECK POINT CLOUD FIREWALL FOR AZURE

PERFORMANCE 2

Performance h k P ud F w R81.20 – Azu 5 M h

Capability Tested 2 vCPU 4 vCPU 8 vCPU

Firewall only (Gbps) 7.8 11 .0 11 .0

Firewall with Intrusion Prevention (Gbps) 4.1 7.6 11 .0

Firewall with Intrusion Prevention and App Control (Gbps) 2.7 5.8 11 .0

Full Threat Prevention Suite (Gbps) 1.0 2.2 4.4

Firewall with Site-to-Site VPN (Gbps) 2.5 5.0 10.0

Remote access VPN - Concurrent users* (with firewall & IPS) 500 1,000 1,700

Remote access VPN - Concurrent users* (with complete threat

prevention**) 400 750 1,500

N :

• Th ugh u w u d using Check Point Enterprise testing conditions

• F w w h - - VPN was tested using the iPerf tool with UDP traffic and 1300 byte packet

si e under controlled conditions

• Accu c n e ±5%

* At the time of testing, concurrency was limited by A ure to 512K For the latest limitations, please

refer to A ure Virtual Machine Network Throughput and Bandwidth

** h includes access control, threat pre ention known and ero day , IPsec

VPN, Intrusion Pre ention, App Control, Content Awareness, URL Filtering, Anti Bot, and Anti Virus

Deployment • Auto c in uppo t in ic osoft Azu e Supports deployment in A ure VMSS, allowing the Check

Point Cloud Firewall pre iously known as Cloud uard gateways to scale automatically based on

demand, ensuring high a ailability and cost efficient elasticity

• Lifec c e A e Autom tion vi ou n ement tension CME automatically handles

onboarding and decommissioning of gateways during VMSS scale out and scale in e ents It

https://learn.microsoft.com/en-us/azure/virtual-network/virtual-machine-network-throughput

© 2026 Check Point Software Technologies Ltd. All rights reserved.

CHECK POINT CLOUD FIREWALL FOR AZURE

MANAGEMENT, VISIBILITY, AND MONITORING 3

pro isions security configuration, installs a restricti e drop policy, executes post pro isioning scripts

or hotfixes, and finali es with complete policy installation

• Token B se te Re ist tion Secure Internal Communication SIC is established using a

one time token in ected into gateway templates, enabling secure, ero touch onboarding

• Temp te D iven P ovisionin Templates define each gateway’s configuration, including ersion,

software blades, IP 6 support, NAT beha ior, logging settings, initial policy, and custom scripts,

ensuring standardi ed deployments across en ironments

• Autom tic otfi n Jumbo nst tion ateways can be bootstrapped with pre appro ed hotfixes

or umbo packages during deployment, with optional retry logic to ensure compliance

• uppo t fo Azu e te Lo B nce n Vi tu WAN Enables seamless insertion of The

Check Point Cloud Firewall firewalls into A ure traffic flows ia LB or as Network Virtual

Appliances NVAs within A ure Virtual AN architectures

• Ze o Touch e Onbo in Physical or irtual gateways can be automatically disco ered by

Smart 1 Cloud when connected to the network and registered using a portal issued token, requiring

no manual configuration

Management, Visibility, and Monitoring • Unifie ou B se n ement Smart 1 Cloud deli ers ob ect and policy central management

uniformly applying to all gateways, logging, and configurations for the Check Point Cloud Firewall

deployments in A ure en ironments

• ou A e Lo in n T oub eshootin CME logs include detailed metadata such as operation

results, timestamps, data center names, and durations Logs can be filtered by blade and exported

for compliance and forensics

• nte tion n Lo po t ateways can forward logs to up to three external destinations,

supporting Syslog, CEF, LEEF, JSON, and Splunk formats, with support for secure TLS transmission

• Re Time Topo o A eness The Cloud Controller maintains constant isibility into A ure nati e

ob ects and automatically updates changes to gateways, reducing the need for manual sync

operations

• entit h in Ac oss Auto c in te s Auto scaling gateways can recei e user identity

data from designated PDPs, ensuring consistent user based policy enforcement without redundant

integrations

• Pe ont o e Pe fo m nce Tunin Administrators can ad ust scanner inter al, API timeouts, and

other CME settings to accommodate large A ure en ironments and mitigate API rate limiting

concerns

© 2026 Check Point Software Technologies Ltd. All rights reserved.

CHECK POINT CLOUD FIREWALL FOR AZURE

SECURITY 4

Security • F e ib e B e n b ement Templates can acti ate Network Security, Threat Pre ention, HTTPS

Inspection, Identity Awareness, and other blades as part of the pro isioning flow

• Autonomous Th e t P evention fo Azu e Vi tu WAN The Check Point Cloud Firewall NVAs

deployed in A ure Virtual AN can be pro isioned with built in autonomous threat pre ention

capabilities using the CME API

• VPN n entit uppo t Full support for site to site VPN, NAT, and identity aware policy

enforcement powered by deep integration with Microsoft AD, LDAP, RADIUS, Cisco px rid, Terminal

Ser ers, and more, for consistent policy for local and remote users on indows, macOS, Linux,

Android, and Apple iOS platforms

• D op A Fi st Time Po ic fo ecu e Bootst ppin During pro isioning, gateways can apply a

restricti e policy to block unintended traffic particularly useful when inserted ia LBs

• ou N tive entit A eness ateways can enforce user based policies by consuming identity

data from external PDPs, allowing identity enforcement in dynamic, distributed en ironments

• Autom tic NAT n Access Ru e e tion fo App te cen ios hen connected behind A ure

Application ateway, CME can automatically generate NAT and Access rules based on listener tags,

eliminating manual configuration efforts, with additional application control features based on

8,000+ pre defined application signatures i e , not limited to Domain/FQDN filtering

• D n mic Object B se Po ic nfo cement ateways consume real time updates from A ure,

including subnets, tags, Application Security roups AS s , and Pri ate Endpoints, for use in access

policies without hardcoded IPs

• oss ou Po ic Abst ctions Dynamic Data Center Query Ob ects enable creation of policy rules

that combine A ure assets with ob ects from other cloud en ironments, using logical operators

Cloud ntegration & Automation • N tive Azu e nte tion CME and Cloud Controller integrate directly with A ure APIs to disco er

and synchroni e ob ects such as VNets, subnets, NS s, AS s, tags, and Pri ate Endpoints, meaning

nati e cloud elements turn into dynamic policy ob ects

• u tip e Onbo in etho s A ure en ironments can be connected using Ser ice Principal

credentials or managed identity, allowing secure and flexible integration

• Autom tion ith AP s, L , n Te fo m The full pro isioning lifecycle can be controlled ia

RESTful APIs, the autoprov\_cfg CLI utility, or through the Check Point Cloud Firewall VNet ateway

Module Terraform, offering powerful automation options for De Ops and platform teams

https://registry.terraform.io/modules/CheckPointSW/cloudguard-network-security/azure/latest/submodules/single_gateway_new_vnet

© 2026 Check Point Software Technologies Ltd. All rights reserved.

CHECK POINT CLOUD FIREWALL FOR AZURE

NETWORK FEATURES 5

• As nch onous AP uppo t ith Request T ckin CME APIs pro ide async operation handling with

request IDs for tracking pro isioning status of templates, policies, ingress rules, and hotfix

installations

• Temp te Leve Def u ts n nhe it nce lobal defaults can be defined and applied automatically

to all new gateway templates, streamlining policy enforcement and consistency

• u ti Ten nt n u ti ubsc iption ove n nce Supports mapping A ure subscriptions and

en ironments to separate management domains, enabling secure and scalable control of complex

A ure estates

Network Features • Bui t n Pv6 uppo t IP 6 can be enabled during onboarding ia template attributes, allowing dual

stack deployments across A ure en ironments

• A v nce VPN uppo t Includes support for IPSec site to site VPN and remote access scenarios

Configuration flexibility includes manual topology setup, external interface tagging, and NAT rule

management

• NAT onfi u tion t Temp te Leve Templates allow pre configuration of NAT settings, supporting

consistent deployment of hide NAT and other rules aligned with A ure requirements

• T ffic nse tion vi Azu e LB Allows the Check Point Cloud Firewall gateways to inspect East

est or North South traffic transparently by sitting inline with A ure’s nati e LB

• ecu e nte n ommunic tion All communication between gateways and Smart 1 Cloud is

secured using Check Point’s SIC protocol, automatically established during deployment

• n ess n ement fo Azu e Vi tu WAN CME APIs allow full pro isioning of A ure NVAs in

Virtual AN, including creation of NS rules and Load Balancer configuration for secure and

scalable ingress traffic control

• Po ic A e Bootst ppin To ensure reliable A ure health probe responses and secure traffic

handling, a restricti e default policy is applied during gateway bootstrap and automatically replaced

upon full pro isioning

R d about Check Point Cloud Firewall for public clouds

M k Firewall & Threat Pre ention and Check Point Cloud Firewall for A ure Virtual AN

Wo i e e qu te s

5 Shlomo Kaplan Street, Tel A i 6789159, Israel | Tel +972 3 753 4599

U. . e qu te s

100 Oracle Parkway, Suite 800, Redwood City, CA 94065 | Tel 1 800 429 4391

.checkpoint.com

© 2026 Check Point Software Technologies Ltd All rights reser ed

https://www.checkpoint.com/cloudguard/cloud-network-security/iaas-public-cloud-security/ https://azuremarketplace.microsoft.com/en-us/marketplace/apps/checkpoint.vsec?tab=Overview https://azuremarketplace.microsoft.com/en-us/marketplace/apps/checkpoint.cp-vwan-managed-app?tab=Overview


Item Type: pdf