Report | CyberRatings Cloud Firewall Test Results Q1, 2025
This report details CyberRatings.org's evaluation of Check Point CloudGuard Network Security (R81.20) on AWS. The firewall achieved a perfect 100% in security effectiveness, exploit blocking, evasion resistance, and false positive accuracy—one of only two products to do so. Read the full report for key insights into its top-tier cloud protection.

Q1 2025 | CNFW
In Q1 2025, CyberRatings.org conducted independent evaluations of leading cloud firewall solutions using the Cloud Firewall Test Methodology v3.0. These assessments included offerings from Cloud Service Providers (CSPs) and third-party security vendors, typically available through CSP marketplaces.
This report outlines the findings from CyberRatings’ testing of Check Point’s Cloud Network Firewall solution. The evaluation covered key performance metrics: exploit block rate, evasion effectiveness, false positive management, TLS/SSL 1.2 and 1.3 support, and system stability under adverse conditions. The firewall was tested using real- world attack scenarios, enterprise-grade workloads, and adversarial evasion techniques to measure its resilience, reliability, and performance.
© 2025 CyberRatings.org. All rights reserved.
Authors: Thomas Skybakmoen, Ahmed Basheer, Tim Otto, Vikram Phatak
Check Point CloudGuard Network Security Next-Gen Firewall with Threat Prevention
R81.20 Jumbo Hotfix Take 89 c6i.xlarge
TEST REPORT
2
Q1 2025 | CLOUD NETWORK FIREWALL
Table of Contents Executive Summary . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3
Overview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 4
Test Topology . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 4
How We Tested . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 4
Security Effectiveness . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .5
Routing & Access Control . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .5
TLS/SSL Support . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .6
False Positive Accuracy . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 7
Exploits . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .8
Evasions . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10
Performance . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12
Rated Throughput . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12
Maximum Capacity . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 13
HTTP Capacity . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 14
HTTPS Capacity . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 15
Delta between HTTP and HTTPS Capacity & Throughput . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 17
Stability & Reliability . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 18
Blocking Under Extended Attack . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 18
Behavior of the State Engine Under Load . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 18
Cost of Tested Configuration . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 19
Understanding Cloud Deployment Costs . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 19
Price Per Protected Mbps . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 20
Cost Calculation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 20
Scorecard . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 21
Special Thanks . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .25
Q1 2025 | CLOUD NETWORK FIREWALL
3
Executive Summary The CloudGuard Network Security Next-Gen Firewall with Threat Prevention (R81.20 Jumbo Hotfix Take 89), running on AWS c6i.xlarge, was tested using CyberRatings.org Cloud Network Firewall methodology version 3.0.
Our testing determined that the Check Point CloudGuard provides excellent exploit and evasion detection, TLS/ SSL inspection, and reliability while generating no false positives. Consequently, CyberRatings assesses that it is an excellent choice for organizations seeking strong protection for their cloud deployments.
Key Findings • Security Effectiveness: 100.00%
• One of only two products achieving 100%.
• Exploit Block Rate: 100.00%
• Evasion Effectiveness: 100.00%
• Successfully identified and mitigated 2,500 attacks across 27 categories of evasion techniques from network layer 3 to layer 7.
• TLS/SSL Support: 100.00%
• False Positive Accuracy: 100.00%
• Rated Throughput: 390 Mbps
Q1 2025 | CLOUD NETWORK FIREWALL
4
How We Tested • False Positives: 2,760 samples from various business-critical files and applications, ensuring security
measures did not disrupt legitimate traffic.
• Exploits: 2,028 attack samples from widely exploited vulnerabilities in enterprise environments.
• Evasion Techniques: 2,500 attacks spanning 27 evasion techniques tested across multiple network layers to bypass firewall defenses.
• Performance Metrics: 46 different stress and capacity tests under diverse workloads.
• Stability & Reliability: Seven extended tests simulating prolonged real-world attack and operational scenarios.
These comprehensive benchmarks highlight the effectiveness of the cloud firewall in delivering reliable threat prevention, operational stability, and minimal disruption to legitimate traffic. Organizations can utilize these results to make informed decisions when selecting a cloud network firewall for modern enterprise environments.
The CNFW was evaluated in the following areas:
• Routing & Access Control
• TLS/SSL Decryption
• Threat Prevention (false positives, exploits, evasions)
• Performance Under Load
• Stability & Reliability
Overview Organizations securing cloud infrastructure must evaluate Cloud Network Firewalls (CNFWs) based on integration, security capabilities, operational needs, billing, and cost. A firewall’s effectiveness directly impacts an organization’s ability to defend against cyber threats. Therefore, objective testing is essential to ensure firewalls provide the expected protection.
This test compared firewalls from Cloud Service Providers (CSPs) and third-party security vendors. Third-party firewalls were deployed on Amazon Web Services (AWS). Each product met specific baseline security requirements and adhered to best practices. Testing focused on real-world attack methodologies, validating both security and performance claims. This test prioritized security over performance.
Test Topology The figure below illustrates the testing topology used for this round of testing.
Figure 1 — Cloud Network Firewall (CNFW) Test Topology
Q1 2025 | CLOUD NETWORK FIREWALL
5
Security Effectiveness Security effectiveness tests verified how effectively the firewall protected network access, applications, and users while preventing threats (exploits and evasions), blocking malicious traffic under extended load, and remaining resistant to false positives.
Routing & Access Control Firewalls must support stateful inspection, enforce security policies, and prevent unauthorized access across network segments. Proper network segmentation is crucial for preventing lateral movement by attackers. This test ensured that security policies were correctly enforced.
Network Segmentation Results
Unrestricted Traffic Test (Allow All) Pass
Segmented Traffic Test Pass
Access Control Results
Simple Policies Pass
Complex Multi-Zone Policies Pass
Figure 2 — Routing & Access Control Results
The testing approach started with a baseline configuration and gradually increased complexity to simulate real- world scenarios. First, we verified that traffic could pass through the firewall when no restrictions were applied. We also verified that transmitted traffic reached the intended segment and no others. Lastly, we verified that only approved traffic could reach a network segment. Then we determined whether all transmitted traffic adhering to simple or complex policies reached its intended destination and whether all transmitted traffic violating policies were blocked.
6
Q1 2025 | CLOUD NETWORK FIREWALL
TLS/SSL Support TLS/SSL encryption is now the standard for secure communication but can also conceal malicious traffic. Let’s Encrypt statistics show that as of December 2024, over 80% of web traffic was sent over HTTPS.1
While CyberRatings believes encryption is beneficial, TLS/SSL is susceptible to various security attacks at multiple network communication levels. Attacks have been observed in the handshake protocol, record protocol, application data protocol, and Public Key Infrastructure (PKI).
To address the rising threat of sophisticated attacks hidden within encrypted traffic, we evaluated the capabilities of cloud network firewalls in supporting a wide range of cipher suites and effectively inspecting encrypted payloads.
100.00%
Figure 3 — TLS/SSL Support (I)
We validated the system’s ability to correctly decrypt and inspect TLS/SSL traffic containing prohibited content previously blocked during testing in clear text.
Then, we tested whether we could allow a conditional bypass of decryption, which might be necessary to preserve privacy for regulatory or other considerations.
Additionally, we evaluated the firewall’s ability to optimize performance through TLS session reuse. This comprehensive approach ensures firewalls provide robust visibility and security in encrypted environments.
Decryption Validation Supported
Top 5 Cipher Suite Support 5/5
Decryption Bypass Exceptions Supported
TLS 1.2 Session Reuse - Session Tickets Supported
TLS 1.2 Session Reuse - Session IDs Supported
Figure 4 — TLS/SSL Support (II)
Top 5 Cipher Suite Support
The DUT is expected to support a wide range of commonly used cipher suites to provide visibility into potential threats encrypted using TLS/SSL. Cipher suites are selected based on the published current frequency of use2 and security status.3 Tested cipher suites were selected based on the frequency of use and security recommendations from reputable sources; see table below.
Cipher Version Cipher Suite Description Frequency of Use (%)
TLS 1.3 TLS_AES_256_GCM_SHA384 (0x13, 0x02) 69%
TLS 1.3 TLS_AES_128_GCM_SHA256 (0x13, 0x01) 11%
TLS 1.2 TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (0xC0, 0x30) 9%
TLS 1.2 TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 (0xC0, 0x2F) 7%
TLS 1.3 TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256 (0xCC, 0xA8) 1%
Figure 5 — Top 5 Cipher Suite Support
1 Let’s Encrypt Stats (https://letsencrypt.org/stats/) 2 Published international daily cipher suite usage can be found at https://crawler.ninja/files/ciphers.txt 3A list of cipher suites and associated attributes including security ratings can be found at https://ciphersuite.info/cs/
Q1 2025 | CLOUD NETWORK FIREWALL
7
False Positive Accuracy False positives can have significant operational consequences, forcing teams to disable security features and reducing overall protection. Additionally, they create unnecessary workloads for security teams, leading to “alert fatigue” and increasing the risk of real threats being overlooked. This test measured how well the firewall distinguished between legitimate and malicious traffic.
We began by testing both inbound and outbound traffic to determine if the device was applying blanket restrictions. Next, we assessed standard ports (80, 443) and alternative ports (30080, 30443) to ensure that legitimate connections, including those necessary for system updates, were not blocked unnecessarily. Disruptions can leave devices vulnerable to unpatched security flaws. We then moved on to file-based testing, starting with system files and executables and then productivity- related formats, compressed files, and media files.
100.00%
Figure 6 — False Positive Accuracy
The CyberRatings false positive repository contains ~100,000 samples, including URLs, file transfers, and application flows relevant to enterprises. Software cracks, game cheats, crypto wallets, mining software, and adware-bundled freeware are excluded.
The false positive test comprised of two categories:
• High Impact: False positives can have significant operational consequences, forcing teams to disable security features and reducing overall protection. Additionally, they create unnecessary workloads for security teams, leading to “alert fatigue” and increasing the risk of real threats being overlooked.
• Low Impact: Tested traffic with minimal business consequences.
Figure 7 shows how the product blocked false positives in the abovementioned categories.
False Positive Categories Impact False Positive Accuracy
System Files (.dll, .lib, etc.) High 100.00%
Executables (.exe,.msi, etc) High 100.00%
Productivity (.sh,.json, .xlsx, etc.) High 100.00%
Compressed Files (.zip, .gz, .cab, .tar, etc.) High 100.00%
Media (.png, ico , etc.) High 100.00%
Other files Low 100.00%
Figure 7 — False Positives (II)
Since firewalls may dynamically adjust settings using machine learning, false positives were checked before, during, and after threat testing. A sample was classified as a false positive if it was blocked at any point during the testing window.
8
Q1 2025 | CLOUD NETWORK FIREWALL
Exploits This test verified the firewall’s ability to detect and block exploits targeting known vulnerabilities. An exploit is an attack that takes advantage of a vulnerability in a protocol, product, operating system, or server application.
The CyberRatings exploit repository is a collection of internal, third-party, in-the-wild, and public exploits encompassing a wide range of protocols and applications. It is based on the Common Vulnerabilities and Exposures (CVEs) publicly listed in the MITRE CVE and NIST NVD databases.4
The subset of exploits selected for this test includes, but is not limited to:
• Recent vulnerabilities (last 5-10 years)
• CISA’s Known Exploited Vulnerabilities
• Vulnerabilities with a high Common Vulnerability Scoring System (CVSS) score (version 3.x)
100.00%
Figure 8 — Exploit Effectiveness
4 cve.org: https://www.cve.org/; NIST NVD: https://nvd.nist.gov/vuln/search
Coverage by CVE & Date
The figure below provides insight into whether a vendor is actively phasing out protection signatures to maintain performance levels and indicates whether a product lags in addressing the latest vulnerabilities. CyberRatings reports exploits by individual years for the past decade. Additionally, we can observe how the vendor offers exploit protection for CVEs rated critical and high, which encompasses most of our testing.
2014 2015 2016 2017 2018 2019 2020 2021 2022 2023 H1 2024
CVE Critical Classification 100.0% 100.0% 100.0% 100.0% 100.0% 100.0% 100.0% 100.0% 100.0% 100.0% 100.0%
CVE High Classification 100.0% 100.0% 100.0% 100.0% 100.0% 100.0% 100.0% 100.0% 100.0% 100.0% 100.0%
Overall Block Rate 100.0% 100.0% 100.0% 100.0% 100.0% 100.0% 100.0% 100.0% 100.0% 100.0% 100.0%
0%
20%
40%
60%
80%
100%
E xp
lo it
B lo
ck R
at e
p er
Y ea
r
Figure 9 — Exploit Block Rate per Year / CVE Category Critical or High
Q1 2025 | CLOUD NETWORK FIREWALL
9
Coverage by Target Vendor
Exploits within the CyberRatings exploit library target many protocols and applications. The figure below shows how the product under test offers exploit protection for ten top vendors targeted in this test. This is a good metric in assessing if your environment is protected by the vendors signatures.
100.0% 100.0% 100.0% 100.0% 100.0% 100.0% 100.0% 100.0% 100.0% 100.0%
0%
20%
40%
60%
80%
100%
Adobe Advantech Apache IBM Cisco HPE Microsoft Oracle Solarwinds VMware
Figure 10 — Coverage by Target Vendor
Q1 2025 | CLOUD NETWORK FIREWALL
10
Evasions This test verified the firewall’s ability to detect and block known evasion techniques.
Firewalls should detect and mitigate evasion techniques, have the ability to normalize evasion traffic and provide accurate alerts for original threats. Threat actors use evasion techniques to disguise and modify attacks at the point of delivery to avoid detection by security products. Therefore, a firewall must correctly handle evasions since just one successful technique can enable an attacker to bypass systems undetected.
Missing a type of evasion means a hacker can use an entire class of exploits to circumvent the security product. CyberRatings used multiple exploits for each evasion technique to see how each product defended against these combinations.
100.00%
Figure 11 — Evasion Effectiveness
The CyberRatings exploit repository is a collection of internal, third party, in-the-wild, and public exploits covering a wide range of protocols. CyberRatings utilizes a proprietary repository of evasion techniques, layering these techniques to create several thousand unique scenarios.
By employing multiple techniques across various protocols, we evaluated the firewall’s capacity to normalize traffic and identify threats in complex, real-world scenarios, ensuring a robust defense against evolving attack vectors.
This test aimed to determine whether an evasion technique could bypass the firewall. We designed our tests to cover a broad 27 categories of evasion techniques and several baseline exploits, resulting in 2,500 total attempts.
First, we confirmed that the firewall detected and blocked a range of baseline exploits. Next, we applied evasion techniques to the baseline exploits and verified the execution of the exploit’s payload delivery. Whenever possible, the firewall was expected to effectively normalize the evaded traffic to provide an accurate alert regarding the original attack instead of alerting solely on anomalous traffic detected due to the evasion technique.
Scoring Evasions
We adjusted scoring for evasions by assessing their overall impact on exploit effectiveness. Specifically, we prioritized evasions that could be broadly applied across multiple attack vectors. For example, TCP-based evasions generally have a wider range of applications than HTTP-based evasions. This is because TCP evasions operate at a lower level in the network stack, allowing attackers to obfuscate traffic in ways that can affect thousands of exploits across different protocols. In contrast, HTTP evasions are typically constrained to application-layer attacks, limiting their applicability to a smaller subset of exploits.
We tested multiple exploit samples for each evasion technique to ensure a comprehensive evaluation. This approach allowed us to observe how the firewall responded to different evasion combinations. By analyzing these results, we gained deeper insights into how effectively the product mitigates evasion tactics and where vulnerabilities may still exist. For details on how scoring works, see table below.
.
Q1 2025 | CLOUD NETWORK FIREWALL
11
Evasion Technique Category OSI Level
Evasion Technique
Score Impact
Max Impact
IP Fragmentation : Non-Overlapping L3 Pass 50.0%
100%
IP Fragmentation : Overlapping L3 Pass 50.0%
IP Header : Checksum L3 Pass 50.0%
IP Header : Options L3 Pass 50.0%
IP Header : Protocol L3 Pass 50.0%
IP Header : Time to Live L3 Pass 50.0%
TCP Header : Checksum L4 Pass 20.0%
60%
TCP Header : Data Offset L4 Pass 20.0%
TCP Header : Options : Timestamps L4 Pass 20.0%
TCP Header : Sequence Number L4 Pass 20.0%
TCP Segmentation : Non-Overlapping Segments L4 Pass 20.0%
TCP Segmentation : Overlapping Segments L4 Pass 20.0%
TCP Transfer Control Block : Flags L4 Pass 20.0%
TCP Transfer Control Block : Resync Sequence Numbers L4 Pass 20.0%
TCP Transfer Control Block : Retransmission L4 Pass 20.0%
HTTP Content Encoding : Identity L7 Pass 1.0%
10%
HTTP Content Encoding : Identity,HTTP Transfer Encoding : Chunked L7 Pass 1.0%
HTTP Headers : Bogus Content Encoding L7 Pass 1.0%
HTTP Headers : Bogus HTTP/1.0 Declaration L7 Pass 1.0%
HTTP Headers : Bogus Transfer Encoding L7 Pass 1.0%
HTTP Headers : Eicar L7 Pass 1.0%
HTTP Headers : Padding L7 Pass 1.0%
HTTP Headers : X-Forwarded-For L7 Pass 1.0%
HTTP Transfer Encoding : Chunked L7 Pass 1.0%
HTTP Transfer Encoding : Chunked : Alternative Chunk-Size Value L7 Pass 1.0%
HTTP Transfer Encoding : Identity L7 Pass 1.0%
Content JSON : Unicode Escaped Strings L7 Pass 1.0%
Figure 12 — Evasion Details
12
Q1 2025 | CLOUD NETWORK FIREWALL
Performance The cloud network firewall’s performance was evaluated under various traffic conditions, providing metrics for real-world performance. Individual implementations may differ based on usage; however, these quantitative metrics serve as a gauge for determining whether a specific firewall is suitable for a given environment. Please note that performance testing and baselines were limited to a ceiling matching the documented committed network performance (not burst performance) limit for the cloud instance type selected for testing.5
Rated Throughput To establish a rated throughput that would be easy to measure for all firewalls, we measured performance to determine the sustained throughput of the cloud network firewall over time for a range of packet sizes and connections per second, capturing the firewall’s performance curves for HTTP and HTTPS.
The “Plain Text Rated Throughput,” “TLS/SSL Rated Throughput,” and the combined “Rated Throughput” are good benchmarks for what an enterprise can expect the firewall instance to achieve consistently (over time) when deployed in the cloud. The Rated Throughput is 80% for TLS/SSL and 20% for Plain Text.
Performance Test Mbps
Plain Text Rated Throughput (Average of HTTP Capacity tests) 821
TLS/SSL Rated Throughput (Average of HTTPS Capacity tests) 282
Rated Throughput 390
Figure 13 — Rated Throughput (Mbps)
For Cloud Service Provider firewalls, there is only one deployment option available. For third-party security vendor firewall solutions that were deployed and tested on AWS infrastructure, the following applied:
AWS offers a variety of instance types with both baseline and burst bandwidth. Choosing the right AWS instance type is crucial for application performance, as it determines the allocation of computing resources such as CPU cores, memory, and network bandwidth. Each instance type is designed to optimize specific workloads—for example, compute-optimized instances for CPU-intensive tasks, memory-optimized instances for extensive data processing or database operations, and GPU-optimized instances for graphics rendering or machine learning.
Selecting the appropriate instance type ensures optimal performance by aligning resource allocation with the application’s requirements. For instance, high-performance computing tasks benefit from instances with many CPU cores and high network speeds, while database-heavy workloads require memory-optimized instances to reduce disk I/O. Likewise, GPU optimized instances are essential for training deep learning models. Failing to align the instance type with the application’s needs can result in performance bottlenecks or failures. When selecting an instance type, consider the application’s CPU, memory, and network requirements, assess the cost-performance ratio, and ensure scalability to accommodate changing demands effectively.
We selected the vendor’s recommended instance type. This instance was utilized to establish baseline control and was later re-evaluated with the firewall configured identically for exploits and evasions.
5 As an example, AWS uses the term “Baseline” to indicate the committed network performance rate (non-bursting performance) in their Instance Network Specifications documentation. CyberRatings’ testing of a selected AWS instance type will be limited to a ceiling matching the AWS instance type’s network performance “Baseline” (e.g. 0.75 Gbps for m5.large instance type).
Q1 2025 | CLOUD NETWORK FIREWALL
13
Maximum Capacity The goal was to stress the firewall and determine how it handles high volumes of connections per second, HTTP transactions per second, and concurrent open connections. All packets contained valid payload and address data, and these tests provided an excellent measurement of maximum connection rates and concurrency (simultaneous users/traffic).
7,910
1,756 1,125
18,216
0
2,000
4,000
6,000
8,000
10,000
12,000
14,000
16,000
18,000
20,000
Max HTTP TPS Max HTTP CPS Max HTTPS CPS (0x13-0x02) Max HTTPS CPS (0xC0-0x30)
T P
S /C
P S
Figure 14 — HTTP Connections & Transactions per Second
Note that in all tests, the following critical “breaking points” – where the final measurements are taken – are used:
• Excessive concurrent HTTP connections – Latency within the firewall caused an excessive delay and increased response time.
• Unsuccessful HTTP/S transactions – Normally, there should be zero unsuccessful transactions. Once these appeared, it is an indication that excessive latency within the firewall is causing connections to time out.
• Maximum HTTP Connections per Second – This test is designed to determine the HTTP connection rate of the firewall with a one-byte response size.
• Maximum HTTP Transactions per Second – This test is designed to determine the maximum HTTP transaction rate of the device with a one-byte HTTP response size.
• Maximum HTTPS Connections per Second – This test is designed to determine the maximum HTTPS connection rate of the firewall with a one-byte response size.
The response size defines the number of bytes contained in the body, excluding any bytes associated with the HTTP/S header. A one-byte response size is designed to provide theoretical maximum connections/transactions per second rate.
Q1 2025 | CLOUD NETWORK FIREWALL
14
HTTP Capacity The goal was to stress the HTTP detection engine and determine how the device copes with network loads of varying average packet sizes and varying connections per second. By creating genuine session-based traffic with varying session lengths, the device was forced to track valid TCP sessions, thus ensuring a higher workload than simple packet-based background traffic. This provided a test environment as close to real-world conditions as possible in a lab while ensuring absolute accuracy and repeatability.
2.7 KB Response 6.4 KB Response 13.5 KB Response 28.0 KB Response 57.4 KB Response 115.6 KB Response
CheckPoint Tested Throughput (CPS) 6,157 6,012 4,868 3,699 2,522 1,562
AWS Max Throughput (CPS) 49,984 24,992 12,496 6,248 3,124 1,562
CheckPoint Tested Throughput (Mbps) 192 376 609 925 1,261 1,562
6,157 6,012 4,868
3,699 2,522 1,562
49,984
24,992
12,496
6,248
3,124 1,562
0
200
400
600
800
1,000
1,200
1,400
1,600
1,800
0
10,000
20,000
30,000
40,000
50,000
60,000
M b
p s
C o
n n
e c ti
o n
s p
e r
S e
c o
n d
Figure 15 — HTTP Capacity
Each transaction consisted of a single HTTP GET request, and there were no delays (i.e., the webserver responded immediately to all requests). All packets contained valid payload (a mix of binary and ASCII objects) and address data. Testing determined the maximum rate the firewall was able to process HTTP packets of multiple sizes and its efficiency of forwarding packets quickly to provide the highest level of network performance with the lowest latency. The results were recorded at each response size at a load level of 95% of the maximum throughput, just before latency increased (which indicates the throughput is not sustainable).
Q1 2025 | CLOUD NETWORK FIREWALL
15
HTTPS Capacity The goal was to stress the HTTPS engine and determine how the device coped with network loads of varying average packet sizes and varying connections per second.
0.2 KB Response 3.9 KB Response 11.2 KB Response 25.7 KB Response 54.9 KB Response 113.8 KB Response
CheckPoint Tested Throughput (CPS) 1,497 1,377 1,311 1,196 1,001 745
AWS Max HTTPS Throughput (CPS) 49,900 24,992 12,496 6,248 3,124 1,562
CheckPoint Tested Throughput (Mbps) 47 86 164 299 501 745
1,497
1,377
1,311 1,196 1,001 745
49,900
24,992
12,496
6,248
3,124 1,562
0
100
200
300
400
500
600
700
800
0
10,000
20,000
30,000
40,000
50,000
60,000
M b
p s
C o
n n
e c ti
o n
s p
e r
S e
c o
n d
Figure 16 — HTTPS Capacity for TLS 1.3 (TLS_AES_256_GCM_SHA384 [0x13, 0x02])
0.2 KB Response 3.9 KB Response 11.2 KB Response 25.7 KB Response 54.9 KB Response 113.8 KB Response
CheckPoint Tested Throughput (CPS) 1,519 1,474 1,397 1,260 1,010 777
AWS Max HTTPS Throughput (CPS) 49,848 24,992 12,496 6,248 3,124 1,562
CheckPoint Tested Throughput (Mbps) 47 92 175 315 505 777
1,519
1,474
1,397 1,260 1,010 777
49,848
24,992
12,496
6,248
3,124 1,562
0
100
200
300
400
500
600
700
800
900
0
10,000
20,000
30,000
40,000
50,000
60,000
M b
p s
C o
n n
e c ti
o n
s p
e r
S e
c o
n d
Figure 17 — HTTPS Capacity for TLS 1.3 (TLS_AES_128_GCM_SHA256 [0x13, 0x01])
By creating session-based traffic with varying session lengths, the device was forced to track valid TCP sessions, thus ensuring a higher workload than simple packet-based background traffic. Encrypting the traffic using TLS/SSL with varying algorithms forced the device to decrypt traffic before inspection, increasing the workload further. This provided a test environment that is as close to real-world conditions as possible to achieve in a lab environment (albeit biased towards HTTPS traffic) while ensuring accuracy and repeatability. Tests were performed similarly to HTTP with one HTTPS transaction per connection. Testing determined the maximum rate the firewall was able to process HTTPS traffic of various sizes and its efficiency at forwarding packets quickly to provide the highest level of network performance with the lowest latency. The results were recorded at each response size at a load level of 95% of the maximum throughput, just before latency increased (which indicates the throughput is not sustainable).
Q1 2025 | CLOUD NETWORK FIREWALL
16
1.4 KB Response 5.0 KB Response 12.3 KB Response 27.0 KB Response 56.3 KB Response 115.0 KB Response
CheckPoint Tested Throughput (CPS) 1,118 1,070 1,021 938 785 634
AWS Max HTTPS Throughput (CPS) 47,467 24,992 12,496 6,248 3,124 1,562
CheckPoint Tested Throughput (Mbps) 35 67 128 235 393 634
1,118
1,070
1,021 938 785 634
47,467
24,992
12,496
6,248
3,124 1,562
0
100
200
300
400
500
600
700
0
5,000
10,000
15,000
20,000
25,000
30,000
35,000
40,000
45,000
50,000
M b
p s
C o
n n
e c ti
o n
s p
e r
S e
c o
n d
Figure 18 — HTTPS Capacity for TLS 1.2 (TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 [0xC0, 0x30])
1.4 KB Response 5.0 KB Response 12.3 KB Response 27.0 KB Response 56.3 KB Response 115.0 KB Response
CheckPoint Tested Throughput (CPS) 1,114 1,130 1,023 944 822 655
AWS Max HTTPS Throughput (CPS) 46,957 24,992 12,496 6,248 3,124 1,562
CheckPoint Tested Throughput (Mbps) 35 71 128 236 411 655
1,114
1,130
1,023 944 822 655
46,957
24,992
12,496
6,248
3,124 1,562
0
100
200
300
400
500
600
700
0
5,000
10,000
15,000
20,000
25,000
30,000
35,000
40,000
45,000
50,000
M b
p s
C o
n n
e c ti
o n
s p
e r
S e
c o
n d
Figure 19 — HTTPS Capacity for TLS 1.2 (TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 [0xC0, 0x2F])
Q1 2025 | CLOUD NETWORK FIREWALL
17
Delta between HTTP and HTTPS Capacity & Throughput How did the encryption overhead affect the bandwidth for the provided payloads? And how does the size of what is being transferred impact performance?
0.2 KB Response 3.9 KB Response 11.2 KB Response 25.7 KB Response 54.9 KB Response 113.8 KB Response
CheckPoint HTTP Throughput (CPS) 7,535 6,519 5,023 3,898 2,524 1,562
CheckPoint HTTPS Throughput (CPS) 1,497 1,377 1,311 1,196 1,001 745
CheckPoint HTTP Throughput (Mbps) 235 407 628 975 1,262 1,562
CheckPoint HTTPS Throughput (Mbps) 47 86 164 299 501 745
7,535
6,519
5,023
3,898
2,524
1,5621,497 1,377
1,311 1,196
1,001 745
0
200
400
600
800
1,000
1,200
1,400
1,600
1,800
0
1,000
2,000
3,000
4,000
5,000
6,000
7,000
8,000
M b
p s
C o
n n
e c ti
o n
s p
e r
S e
c o
n d
Figure 20 — Delta betweeb HTTP and HTTPS Capacity & Throughput
The purpose of these tests was to measure the amount of overhead added to each payload based on the cipher suite used. This test used HTTP without any TLS and then we tested the same payload using TLS 1.3 (TLS_AES_256_GCM_SHA384 [0x13, 0x02]). Each transaction consisted of a single HTTPS GET request with no transaction delays (i.e., the web server responds immediately to all requests). All traffic contains valid payloads.
Q1 2025 | CLOUD NETWORK FIREWALL
18
Stability & Reliability Long-term stability is essential for a firewall, where failure can produce network outages. These tests verified the firewall’s stability and ability to maintain security effectiveness while under normal load and while passing malicious traffic. Products that could not sustain legitimate traffic (or that crash) while under hostile attack did not pass.
The product was required to remain operational and stable throughout these tests and to block 100% of previously blocked traffic, raising an alert for each instance. If any policy-forbidden traffic passed—either due to a high volume of traffic or because the product failed open for any reason—this resulted in a fail.
Stability and Reliability Result
Blocking under Extended Attack
Blocking with Minimal Load Pass
Blocking Under Load Pass
Behavior of the State Engine under Load
Attack Detection/Blocking – Normal Load Pass
State Preservation – Normal Load Pass
Pass Legitimate Traffic – Normal Load Pass
State Preservation – Maximum Exceeded Pass
Drop Traffic – Maximum Exceeded Pass
Figure 21 — Stability & Reliability
Blocking Under Extended Attack These tests indicated the ability of the firewall to remain operational and stable (i.e., block violations and raise associated alerts) throughout an extended attack
Behavior of the State Engine Under Load These tests determined if the device could preserve its state across numerous open connections over an extended period. At various stages throughout the test (including after the maximum was reached), it was confirmed that the device could inspect and block traffic that violated the currently enforced security policy while ensuring that legitimate traffic was not blocked.
Q1 2025 | CLOUD NETWORK FIREWALL
19
Cost of Tested Configuration To assess the overall value of a firewall solution, security effectiveness should be evaluated alongside its cost. Implementation of security solutions can be complex, with several factors affecting the overall cost of deployment, maintenance, and upkeep.
For this report, we have estimated the cost of:
• 1 month of product usage (assuming 730 hours)
• 10 TB of data transfer per month to the internet
Understanding Cloud Deployment Costs The cost of deploying products in the cloud varies based on the use case and deployment model. Some cost components apply universally, while others depend on the specific service and how it is utilized. Below are common categories of cloud-related costs:
Product or Endpoint Costs (May Apply Depending on the Service)
Some cloud-based products have a fixed cost per instance, endpoint, or subscription. Others may be billed based on metered usage, such as the number of protected endpoints in a security solution or the amount of storage consumed.
Data Processing Costs (Typically Applies)
Many cloud services incur a cost for processing data, which can vary based on compute power, memory usage, or the complexity of operations performed on the data. For example, a firewall inspecting network traffic or a machine learning model analyzing logs will generate processing costs.
Data Transfer Costs (Product-Specific) (May Apply Depending on the Product)
Some cloud products charge for the volume of data they handle internally, such as log ingestion, telemetry, or large-scale data analysis. These costs can differ based on whether the data is transferred between cloud services or within the same service.
Cloud Provider Data Transfer Costs (Egress Fees) (Typically Applies When Data Leaves the Cloud)
Data that leaves the cloud provider’s infrastructure—such as from an EC2 instance to the public internet—incurs egress fees, usually charged per TB transferred. These costs can be a significant factor, especially for services that require large data transfers, such as content delivery, backups, or analytics.
Q1 2025 | CLOUD NETWORK FIREWALL
20
Price Per Mbps One way to consider value is in the context of price/performance, or, in this case, Price/Mbps. We have previously calculated each product’s rated throughput. Please see the performance section for more details. Using this formula, we can normalize data and account for wide-ranging price differences and product performance.
Price per Mbps = Total Cost (1-Month) / Rated Throughput (Mbps)
Figure 22 — Price per Mbps Formula
Cost Calculation The pricing was collected from Check Point’s product page on the AWS Marketplace:
• CloudGuard Network Security Next-Gen Firewall with Threat Prevention R81.20 Jumbo Hotfix Take 89: c6i- xlarge (Instance) = $664.30
If a customer opts to use the CloudGuard Network Security Next-Gen Firewall with Threat Prevention pay-as-you- go license with the c6i-xlarge in AWS (North Virginia), at an hourly cost of $0.17, the calculation would be as follows:
• Data Processing Cost: $0.17 * 730 hours = $124.10
• Data Transfer Cost: $0.09 * 10 TB (EC2) = $921.60
• Total Cost for one month: $1,710.00
1 Month Cost Tested Throughput (Mbps) Price per Mbps
$1,710 390 $4.38
Figure 23 — Price per Mbps Calculation
21
Q1 2025 | CLOUD NETWORK FIREWALL
Scorecard Summary
Vendor CheckPoint
Cloud Service Provider AWS
Instance Type (AWS or Native) c6i.xlarge
Version R81.20 Jumbo Hotfix Take 89
IPS Version 635250610
vCPU 4
Memory 8
False Positives Result
System Files (.dll, .lib, etc.) 100.00%
Executables (.exe,.msi, etc) 100.00%
Productivity (.sh,.msi,.json, .xlsx, etc.) 100.00%
Compressed Files (.zip, .gz, .cab, .tar, etc.) 100.00%
Media (.png, ico , etc.) 100.00%
Other files 100.00%
Routing Functionality Result
Unrestricted Traffic Test Pass
Segmented Traffic Test Pass
Access Control Result
Simple Policies Pass
Complex Multi-Zone Policies Pass
TLS/SSL Support
Cipher Suites Prevalence Version Result
TLS_AES_256_GCM_SHA384 (0x13, 0x02) 69% TLS 1.3 PASS
TLS_AES_128_GCM_SHA256 (0x13, 0x01) 11% TLS 1.3 PASS
TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (0xC0, 0x30) 9% TLS 1.2 PASS
TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 (0xC0, 0x2F) 7% TLS 1.2 PASS
TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256 (0xCC, 0xA8) 1% TLS 1.3 PASS
Decryption Validation Supported
Decryption Bypass Exceptions Supported
TLS Session Reuse - Session Tickets Supported
TLS Session Reuse - Session IDs Supported
22
Q1 2025 | CLOUD NETWORK FIREWALL
Exploits Block Rate
Exploits 100.00%
Evasion Effectiveness Result
IP Fragmentation : Non-Overlapping Pass
IP Fragmentation : Overlapping Pass
IP Header : Checksum Pass
IP Header : Options Pass
IP Header : Protocol Pass
IP Header : Time to Live Pass
TCP Header : Checksum Pass
TCP Header : Data Offset Pass
TCP Header : Options : Timestamps Pass
TCP Header : Sequence Number Pass
TCP Segmentation : Non-Overlapping Segments Pass
TCP Segmentation : Overlapping Segments Pass
TCP Transfer Control Block : Flags Pass
TCP Transfer Control Block : Resync Sequence Numbers Pass
TCP Transfer Control Block : Retransmission Pass
HTTP Content Encoding : Identity Pass
HTTP Content Encoding : Identity,HTTP Transfer Encoding : Chunked Pass
HTTP Headers : Bogus Content Encoding Pass
HTTP Headers : Bogus HTTP/1.0 Declaration Pass
HTTP Headers : Bogus Transfer Encoding Pass
HTTP Headers : Eicar Pass
HTTP Headers : Padding Pass
HTTP Headers : X-Forwarded-For Pass
HTTP Transfer Encoding : Chunked Pass
HTTP Transfer Encoding : Chunked : Alternative Chunk-Size Value Pass
HTTP Transfer Encoding : Identity Pass
Content JSON : Unicode Escaped Strings Pass
Performance
Maximum Capacity CPS TPS
Max HTTP CPS 7,910 N/A
Max HTTP TPS N/A 18,216
Max HTTPS (0x13-0x02) 1,756 N/A
Max HTTPS (0x13-0x01) 1,125 N/A
23
Q1 2025 | CLOUD NETWORK FIREWALL
HTTP Capacity (without transaction delay) CPS Throughput (Mbps)
Response Time (ms)
1,000 Connections per Second - 115.6 KB Response 1,562 1,562 186.40
2,000 Connections per Second - 57.4 KB Response 2,522 1,261 109.64
4,000 Connections per Second - 28.0 KB Response 3,699 925 87.55
8,000 Connections per Second - 13.5 KB Response 4,868 609 44.49
16,000 Connections per Second - 6.4 KB Response 6,012 376 30.32
32,000 Connections per Second - 2.7 KB Response 6,157 192 24.43
HTTPS Capacity (0x13, 0x02) CPS Throughput (Mbps)
Response Time (ms)
1,000 Connections per Second - 113.8 KB Response 745 745 260.50
2,000 Connections per Second - 54.9 KB Response 1,001 501 158.11
4,000 Connections per Second - 25.7 KB Response 1,196 299 114.02
8,000 Connections per Second - 11.2 KB Response 1,311 164 57.44
16,000 Connections per Second - 3.9 KB Response 1,377 86 19.28
32,000 Connections per Second - 0.2 KB Response 1,497 47 0.01
HTTPS Capacity (0x13, 0x01) CPS Throughput (Mbps)
Response Time (ms)
1,000 Connections per Second - 113.8 KB Response 777 777 209.53
2,000 Connections per Second - 54.9 KB Response 1,010 505 147.81
4,000 Connections per Second - 25.7 KB Response 1,260 315 83.44
8,000 Connections per Second - 11.2 KB Response 1,397 175 49.06
16,000 Connections per Second - 3.9 KB Response 1,474 92 18.13
32,000 Connections per Second - 0.2 KB Response 1,519 47 0.01
HTTPS Capacity (0xC0, 0x30) CPS Throughput (Mbps)
Response Time (ms)
1,000 Connections per Second - 115.0 KB Response 634 634 368.65
2,000 Connections per Second - 56.3 KB Response 785 393 166.04
4,000 Connections per Second - 27.0 KB Response 938 235 96.77
8,000 Connections per Second - 12.3 KB Response 1,021 128 67.09
16,000 Connections per Second - 5.0 KB Response 1,070 67 16.93
32,000 Connections per Second - 1.4 KB Response 1,118 35 0.01
HTTPS Capacity (0xC0, 0x2F) CPS Throughput (Mbps)
Response Time (ms)
1,000 Connections per Second - 115.0 KB Response 655 655 313.87
2,000 Connections per Second - 56.3 KB Response 822 411 175.40
4,000 Connections per Second - 27.0 KB Response 944 236 108.12
8,000 Connections per Second - 12.3 KB Response 1,023 128 78.26
Q1 2025 | CLOUD NETWORK FIREWALL
24
16,000 Connections per Second - 5.0 KB Response 1,130 71 31.30
32,000 Connections per Second - 1.4 KB Response 1,114 35 0.01
HTTP and HTTPS Delta (Using same packet size)
HTTP Capacity (without transaction delay) CPS Throughput (Mbps)
Response Time (ms)
1,000 Connections per Second - 113.8 KB Response 1,562 1,562 324.22
2,000 Connections per Second - 54.9 KB Response 2,524 1,262 206.19
4,000 Connections per Second - 25.7 KB Response 3,898 975 87.58
8,000 Connections per Second - 11.2 KB Response 5,023 628 33.22
16,000 Connections per Second - 3.9 KB Response 6,519 407 32.86
32,000 Connections per Second - 0.2 KB Response 7,535 235 0.00
HTTPS Capacity (0x13, 0x02) CPS Throughput (Mbps)
Response Time (ms)
1,000 Connections per Second - 113.8 KB Response 745 745 260.50
2,000 Connections per Second - 54.9 KB Response 1,001 501 158.11
4,000 Connections per Second - 25.7 KB Response 1,196 299 114.02
8,000 Connections per Second - 11.2 KB Response 1,311 164 57.44
16,000 Connections per Second - 3.9 KB Response 1,377 86 19.28
32,000 Connections per Second - 0.2 KB Response 1,497 47 0.01
Stability and Reliability Result
Blocking under Extended Attack
Blocking with Minimal Load Pass
Blocking Under Load Pass
Behavior of the State Engine under Load
Attack Detection/Blocking – Normal Load Pass
State Preservation – Normal Load Pass
Pass Legitimate Traffic – Normal Load Pass
State Preservation – Maximum Exceeded Pass
Drop Traffic – Maximum Exceeded Pass
Q1 2025 | CLOUD NETWORK FIREWALL
25
Special Thanks We want to issue a special thank you to Keysight for providing their CyPerf and BreakingPoint tools for us to test the performance, TLS functionality, and stability of Cloud Network Firewalls.
Authors Thomas Skybakmoen, Ahmed Basheer, Tim Otto, Vikram Phatak
Contact Information CyberRatings.org
515 South Capital of Texas Highway
Suite 225
Austin, TX 78746
info@cyberratings.org
www.cyberratings.org
© 2025 CyberRatings. All rights reserved. No part of this publication may be reproduced, copied/scanned, stored on a retrieval system, emailed, or otherwise disseminated or transmitted without the express written consent of CyberRatings (“us” or “we”).
Please read the disclaimer in this box because it contains important information that binds you. If you do not agree to these conditions, you should not read the rest of this report but should instead return the report immediately to us. “You” or “your” means the person who accesses this report and any entity on whose behalf he/she has obtained this report.
1. The information in this report is subject to change by us without notice, and we disclaim any obligation to update it.
2. The information in this report is believed by us to be accurate and reliable at the time of publication but is not guaranteed. All use of and reliance on this report are at your sole risk. We are not liable or responsible for any damages, losses, or expenses of any nature whatsoever arising from any error or omission in this report.
3. NO WARRANTIES, EXPRESS OR IMPLIED ARE GIVEN BY US. ALL IMPLIED WARRANTIES, INCLUDING IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, AND NON-INFRINGEMENT, ARE HEREBY DISCLAIMED AND EXCLUDED BY US. IN NO EVENT SHALL WE BE LIABLE FOR ANY DIRECT, CONSEQUENTIAL, INCIDENTAL, PUNITIVE, EXEMPLARY, OR INDIRECT DAMAGES, OR FOR ANY LOSS OF PROFIT, REVENUE, DATA, COMPUTER PROGRAMS, OR OTHER ASSETS, EVEN IF ADVISED OF THE POSSIBILITY THEREOF.
4. This report does not constitute an endorsement, recommendation, or guarantee of any of the products (hardware or software) tested or the hardware and/or software used in testing the products. The testing does not guarantee that there are no errors or defects in the products or that the products will meet your expectations, requirements, needs, or specifications, or that they will operate without interruption.
5. This report does not imply any endorsement, sponsorship, affiliation, or verification by or with any organizations mentioned in this report.
6. All trademarks, service marks, and trade names used in this report are the trademarks, service marks, and trade names of their respective owners.