Datasheet | Cloud Firewall Gateway Performance for VMWare NSX-T

Datasheet | Cloud Firewall Gateway Performance for VMWare NSX-T

Learn how Check Point Cloud Firewall for VMware NSX-T delivers high-performance threat prevention, service chaining, micro-segmentation, and automated cloud security to protect workloads, applications, and data across virtualized environments.

Datasheet | Cloud Firewall Gateway Performance for VMWare NSX-T

© 2026 Check Point Software Technologies Ltd. All rights reserved. [Protected] Non-confidential content

Cloud Firewall Performance for VMWare NSX-T | Datasheet

1

Cloud Firewall, part of the Hybrid Mesh Security platform, provides advanced threat prevention and

automated cloud network security through a virtual security gateway, with unified security management

across all your multi-cloud and on-premises environments.

For public clouds, Cloud Firewall provides automated and elastic public cloud network security to keep assets and data protected while staying aligned to the dynamic needs of public cloud environments.

For private clouds, Cloud Firewall delivers dynamic security within virtual datacenters to prevent the lateral spread of threats while consolidating visibility and management across physical and virtual networks.

Performance: Cloud Firewall (R81) on VMWare NSX-T Notes:

 Next Generation Firewall (NGFW) throughput is measured with FW, IPS, Application Control features

enabled (see table 2 below), using Check Point Enterprise testing conditions.

 Next Generation Threat Prevention (NGTP) throughput is measured with FW, IPS, Application Control, URL

Filter, Anti-Virus, Anti-Bot features enabled (see table 2 below), using Check Point Enterprise testing

conditions.

When using NSX-T, Check Point recommends using Service Chaining for all traffic inspection. The main benefits of this methodology include micro segmentation and scalability.

It is recommended to run additional testing within your environment to ensure your performance requirements are met. For compatibility between VMware NSX-T versions and Cloud Firewall releases, see here.

Service Chaining Performance Table 2 vCPU 4 vCPU 8 vCPU

CPS (connections per second) 34K* 59.5K* 89.3K*

FW Only 6.4Gbps 8.4Gbps 8.4Gbps

FW + IPS 3.4Gbps 5.1Gbps 7.7Gbps

NGFW (FW + IPS + Application Control) 2.4Gbps 3.9Gbps 5.9Gbps

NGTP (NGFW + URL Filter + Anti-Virus + Anti-Bot) 0.9Gbps 1.5Gbps 2.3Gbps *Accuracy range: +/-15% Concurrent Connections depending on the size of the RAM: 204K per 1GB of RAM

Secure Your AI Transformation

Cloud Firewall Gateway Performance for VMWare NSX-T

https://www.checkpoint.com/support-services/hcl/

© 2026 Check Point Software Technologies Ltd. All rights reserved. [Protected] Non-confidential content

Cloud Firewall Performance for VMWare NSX-T | Datasheet

2

Content Security Network

First Time Prevention Capabilities High Availability

 OS-level and static file analysis

 File disarm and reconstruction via Threat Extraction

 Average emulation time for unknown files that require full sandbox evaluation is under 100 seconds

 Maximal file size for Emulation is 100 MB

 Emulation OS Support: Windows XP, 7, 8.1, 10

 Active/Active L2, Active/Passive L2 and L3*

 Session failover for routing change, device and link failure

*Not applicable for cloud service providers usage

IPv6

 NAT66

 CoreXL, SecureXLApplications

 Use 8,000+ pre-defined or customize your own applications

 Accept, prevent, schedule, and apply traffic-shaping

Unicast and Multicast Routing (see SK98226)

 OSPFv2, BGP, RIP

 Static routes, Multicast routes

 Policy-based routing

 PIM-SM, PIM-DM, IGMP v2, and v3

Data Loss Prevention

 Classify 700+ pre-defined data types

 End user and data owner incident handling

Dynamic User-based Policy

 Integrates with Microsoft AD, LDAP, RADIUS, Cisco pxGrid, Terminal Servers and with 3rd parties via a Web API

 Enforce consistent policy for local and remote users on Windows, macOS, Linux, Android and Apple iOS platforms

Check Point Cloud Firewall All-inclusive Security

NGFW NGTP NGTX

Basic access control Prevent known threats Prevent known and zero-day attacks

Firewall   

IPS   

Application Control   

Content Awareness   

URL Filtering  

Anti-Bot  

Anti-Virus  

Anti-Spam  

SandBlast Threat Emulation 

SandBlast Threat Extraction 

Each gateway requires a license for the enabled security feature.

CONTACT US EMAIL: INFO@CHECKPOINT.COM WEB: WWW.CHECKPOINT.COM

Secure Your AI Transformation

mailto:info@checkpoint.com http://www.checkpoint.com/


Item Type: pdf