Datasheet | Cloud Firewall Gateway Performance for KVM-Based Cloud Infrastructure

Datasheet | Cloud Firewall Gateway Performance for KVM-Based Cloud Infrastructure

Learn how Check Point Cloud Firewall for KVM-based cloud environments delivers high-performance firewall protection, advanced threat prevention, VPN connectivity, and automated security to protect applications, data, and hybrid cloud infrastructure.

Datasheet | Cloud Firewall Gateway Performance for KVM-Based Cloud Infrastructure

Cloud Firewall Performance for KVM | Datasheet

©2026 Check Point Software Technologies Ltd. All rights reserved | P. 1

Cloud Firewall, part of the Hybrid Mesh Security platform, provides advanced threat prevention and

automated cloud network security through a virtual security gateway, with unified security

management across all your multi-cloud and on-premises environments.

For public clouds, Cloud Firewall provides automated and elastic public cloud network security to

keep assets and data protected while staying highly secure in dynamic environments.

For private clouds, Cloud Firewall delivers automated security within virtual datacenters to prevent the

lateral spread of threats while consolidating visibility & management across physical & virtual

networks.

Performance: Cloud Firewall (R81.20) on KVM-Based Cloud I/S Notes:

• Next Generation Firewall (NGFW) throughput is measured with FW, IPS, Application Control features enabled

(see table 2 below), using Check Point Enterprise testing conditions.

• Next Generation Threat Prevention (NGTP) throughput is measured with FW, IPS, Application Control, URL

Filter, Anti-Virus, Anti-Bot features enabled (see table 2 below), using Check Point Enterprise testing conditions.

• Testing conducted on Intel(R) Xeon(R) Gold 6209U CPU @ 2.10GHz, Testing RAM size was 8GB, Network

Interface: Intel Ethernet X710 for 10GbE SFP+

It is recommended to run additional testing within your environment to ensure your performance requirements are met. Your performance may vary depending on underlying cloud vendor infrastructure performance.

2 vCPU 4 vCPU 8 vCPU

Concurrent Connections 200K Per GB RAM*

FW Only 7.8Gbps** 11Gbps** 11Gbps**

FW + IPS 4.1Gbps 7.6Gbps 11Gbps

NGFW (FW + IPS + Application Control) 2.7Gbps 5.8Gbps 11Gbps

NGTP (NGFW + URL Filter + Anti-Virus + Anti-Bot) 1Gbps 2.2Gbps 4.4Gbps

Remote access VPN Concurrent Connections (NGFW) 500 1000 1700

Remote access VPN Concurrent Connections (NGTP) 400 750 1500

Accuracy range: +/-5% *Concurrent Connections may be limited by cloud provider **Total Throughput may be limited by cloud provider

Cloud Firewall Gateway Performance for KVM-Based Cloud Infrastructure

Secure Your AI Transformation

©2026 Check Point Software Technologies Ltd. All rights reserved | P. 2

Content Security Network

First Time Prevention Capabilities High Availability

• OS-level and static file analysis

• File disarm and reconstruction via Threat Extraction

• Average emulation time for unknown files that require full sandbox evaluation is under 100 seconds

• Maximal file size for Emulation is 100 MB

• Emulation OS Support: Windows XP, 7, 8.1, 10

• Active/Active L2, Active/Passive L2 and L3*

• Session failover for routing change, device and link failure

*Not applicable for cloud service providers usage

IPv6

• NAT66

• CoreXL, SecureXLApplications

• Use 8,000+ pre-defined or customize your own applications

• Accept, prevent, schedule, and apply traffic-shaping

Unicast and Multicast Routing (see

SK98226)

• OSPFv2, BGP, RIP

• Static routes, Multicast routes

• Policy-based routing

• PIM-SM, PIM-DM, IGMP v2, and v3

Data Loss Prevention

• Classify 700+ pre-defined data types

• End user and data owner incident handling

Dynamic User-based Policy

• Integrates with Microsoft AD, LDAP, RADIUS, Cisco pxGrid, Terminal Servers and with 3rd parties via a Web API

• Enforce consistent policy for local and remote users on Windows, macOS, Linux, Android and Apple iOS platforms

Check Point Cloud Firewall All-inclusive Security

NGFW NGTP NGTX

Basic access control Prevent known threats Prevent known and zero-day

attacks

Firewall ✓ ✓ ✓

VPN (IPsec) ✓ ✓ ✓

IPS ✓ ✓ ✓

Application Control ✓ ✓ ✓

Content Awareness ✓ ✓ ✓

URL Filtering ✓ ✓

Anti-Bot ✓ ✓

Anti-Virus ✓ ✓

Anti-Spam ✓ ✓

SandBlast Threat Emulation ✓

SandBlast Threat Extraction ✓

Each gateway requires a license for the enabled security feature.

CONTACT US EMAIL: INFO@CHECKPOINT.COM WEB: WWW.CHECKPOINT.COM

Secure Your AI Transformation

mailto:info@checkpoint.com http://www.checkpoint.com/


Item Type: pdf