Report | CyberRatings Cloud Firewall Test Results Q1, 2025

Report | CyberRatings Cloud Firewall Test Results Q1, 2025

This report details CyberRatings.org's evaluation of Check Point CloudGuard Network Security (R81.20) on AWS. The firewall achieved a perfect 100% in security effectiveness, exploit blocking, evasion resistance, and false positive accuracy—one of only two products to do so. Read the full report for key insights into its top-tier cloud protection.

Report | CyberRatings Cloud Firewall Test Results Q1, 2025

Q1 2025 | CNFW

In Q1 2025, CyberRatings.org conducted independent evaluations of leading cloud firewall solutions using the Cloud Firewall Test Methodology v3.0. These assessments included offerings from Cloud Service Providers (CSPs) and third-party security vendors, typically available through CSP marketplaces.

This report outlines the findings from CyberRatings’ testing of Check Point’s Cloud Network Firewall solution. The evaluation covered key performance metrics: exploit block rate, evasion effectiveness, false positive management, TLS/SSL 1.2 and 1.3 support, and system stability under adverse conditions. The firewall was tested using real- world attack scenarios, enterprise-grade workloads, and adversarial evasion techniques to measure its resilience, reliability, and performance.

© 2025 CyberRatings.org. All rights reserved.

Authors: Thomas Skybakmoen, Ahmed Basheer, Tim Otto, Vikram Phatak

Check Point CloudGuard Network Security Next-Gen Firewall with Threat Prevention

R81.20 Jumbo Hotfix Take 89 c6i.xlarge

TEST REPORT

2

Q1 2025 | CLOUD NETWORK FIREWALL

Table of Contents Executive Summary . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3

Overview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 4

Test Topology . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 4

How We Tested . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 4

Security Effectiveness . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .5

Routing & Access Control . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .5

TLS/SSL Support . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .6

False Positive Accuracy . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 7

Exploits . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .8

Evasions . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10

Performance . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12

Rated Throughput . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12

Maximum Capacity . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 13

HTTP Capacity . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 14

HTTPS Capacity . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 15

Delta between HTTP and HTTPS Capacity & Throughput . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 17

Stability & Reliability . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 18

Blocking Under Extended Attack . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 18

Behavior of the State Engine Under Load . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 18

Cost of Tested Configuration . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 19

Understanding Cloud Deployment Costs . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 19

Price Per Protected Mbps . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 20

Cost Calculation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 20

Scorecard . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 21

Special Thanks . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .25

Q1 2025 | CLOUD NETWORK FIREWALL

3

Executive Summary The CloudGuard Network Security Next-Gen Firewall with Threat Prevention (R81.20 Jumbo Hotfix Take 89), running on AWS c6i.xlarge, was tested using CyberRatings.org Cloud Network Firewall methodology version 3.0.

Our testing determined that the Check Point CloudGuard provides excellent exploit and evasion detection, TLS/ SSL inspection, and reliability while generating no false positives. Consequently, CyberRatings assesses that it is an excellent choice for organizations seeking strong protection for their cloud deployments.

Key Findings • Security Effectiveness: 100.00%

• One of only two products achieving 100%.

• Exploit Block Rate: 100.00%

• Evasion Effectiveness: 100.00%

• Successfully identified and mitigated 2,500 attacks across 27 categories of evasion techniques from network layer 3 to layer 7.

• TLS/SSL Support: 100.00%

• False Positive Accuracy: 100.00%

• Rated Throughput: 390 Mbps

Q1 2025 | CLOUD NETWORK FIREWALL

4

How We Tested • False Positives: 2,760 samples from various business-critical files and applications, ensuring security

measures did not disrupt legitimate traffic.

• Exploits: 2,028 attack samples from widely exploited vulnerabilities in enterprise environments.

• Evasion Techniques: 2,500 attacks spanning 27 evasion techniques tested across multiple network layers to bypass firewall defenses.

• Performance Metrics: 46 different stress and capacity tests under diverse workloads.

• Stability & Reliability: Seven extended tests simulating prolonged real-world attack and operational scenarios.

These comprehensive benchmarks highlight the effectiveness of the cloud firewall in delivering reliable threat prevention, operational stability, and minimal disruption to legitimate traffic. Organizations can utilize these results to make informed decisions when selecting a cloud network firewall for modern enterprise environments.

The CNFW was evaluated in the following areas:

• Routing & Access Control

• TLS/SSL Decryption

• Threat Prevention (false positives, exploits, evasions)

• Performance Under Load

• Stability & Reliability

Overview Organizations securing cloud infrastructure must evaluate Cloud Network Firewalls (CNFWs) based on integration, security capabilities, operational needs, billing, and cost. A firewall’s effectiveness directly impacts an organization’s ability to defend against cyber threats. Therefore, objective testing is essential to ensure firewalls provide the expected protection.

This test compared firewalls from Cloud Service Providers (CSPs) and third-party security vendors. Third-party firewalls were deployed on Amazon Web Services (AWS). Each product met specific baseline security requirements and adhered to best practices. Testing focused on real-world attack methodologies, validating both security and performance claims. This test prioritized security over performance.

Test Topology The figure below illustrates the testing topology used for this round of testing.

Figure 1 — Cloud Network Firewall (CNFW) Test Topology

Q1 2025 | CLOUD NETWORK FIREWALL

5

Security Effectiveness Security effectiveness tests verified how effectively the firewall protected network access, applications, and users while preventing threats (exploits and evasions), blocking malicious traffic under extended load, and remaining resistant to false positives.

Routing & Access Control Firewalls must support stateful inspection, enforce security policies, and prevent unauthorized access across network segments. Proper network segmentation is crucial for preventing lateral movement by attackers. This test ensured that security policies were correctly enforced.

Network Segmentation Results

Unrestricted Traffic Test (Allow All) Pass

Segmented Traffic Test Pass

Access Control Results

Simple Policies Pass

Complex Multi-Zone Policies Pass

Figure 2 — Routing & Access Control Results

The testing approach started with a baseline configuration and gradually increased complexity to simulate real- world scenarios. First, we verified that traffic could pass through the firewall when no restrictions were applied. We also verified that transmitted traffic reached the intended segment and no others. Lastly, we verified that only approved traffic could reach a network segment. Then we determined whether all transmitted traffic adhering to simple or complex policies reached its intended destination and whether all transmitted traffic violating policies were blocked.

6

Q1 2025 | CLOUD NETWORK FIREWALL

TLS/SSL Support TLS/SSL encryption is now the standard for secure communication but can also conceal malicious traffic. Let’s Encrypt statistics show that as of December 2024, over 80% of web traffic was sent over HTTPS.1

While CyberRatings believes encryption is beneficial, TLS/SSL is susceptible to various security attacks at multiple network communication levels. Attacks have been observed in the handshake protocol, record protocol, application data protocol, and Public Key Infrastructure (PKI).

To address the rising threat of sophisticated attacks hidden within encrypted traffic, we evaluated the capabilities of cloud network firewalls in supporting a wide range of cipher suites and effectively inspecting encrypted payloads.

100.00%

Figure 3 — TLS/SSL Support (I)

We validated the system’s ability to correctly decrypt and inspect TLS/SSL traffic containing prohibited content previously blocked during testing in clear text.

Then, we tested whether we could allow a conditional bypass of decryption, which might be necessary to preserve privacy for regulatory or other considerations.

Additionally, we evaluated the firewall’s ability to optimize performance through TLS session reuse. This comprehensive approach ensures firewalls provide robust visibility and security in encrypted environments.

Decryption Validation Supported

Top 5 Cipher Suite Support 5/5

Decryption Bypass Exceptions Supported

TLS 1.2 Session Reuse - Session Tickets Supported

TLS 1.2 Session Reuse - Session IDs Supported

Figure 4 — TLS/SSL Support (II)

Top 5 Cipher Suite Support

The DUT is expected to support a wide range of commonly used cipher suites to provide visibility into potential threats encrypted using TLS/SSL. Cipher suites are selected based on the published current frequency of use2 and security status.3 Tested cipher suites were selected based on the frequency of use and security recommendations from reputable sources; see table below.

Cipher Version Cipher Suite Description Frequency of Use (%)

TLS 1.3 TLS_AES_256_GCM_SHA384 (0x13, 0x02) 69%

TLS 1.3 TLS_AES_128_GCM_SHA256 (0x13, 0x01) 11%

TLS 1.2 TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (0xC0, 0x30) 9%

TLS 1.2 TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 (0xC0, 0x2F) 7%

TLS 1.3 TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256 (0xCC, 0xA8) 1%

Figure 5 — Top 5 Cipher Suite Support

1 Let’s Encrypt Stats (https://letsencrypt.org/stats/) 2 Published international daily cipher suite usage can be found at https://crawler.ninja/files/ciphers.txt 3A list of cipher suites and associated attributes including security ratings can be found at https://ciphersuite.info/cs/

Q1 2025 | CLOUD NETWORK FIREWALL

7

False Positive Accuracy False positives can have significant operational consequences, forcing teams to disable security features and reducing overall protection. Additionally, they create unnecessary workloads for security teams, leading to “alert fatigue” and increasing the risk of real threats being overlooked. This test measured how well the firewall distinguished between legitimate and malicious traffic.

We began by testing both inbound and outbound traffic to determine if the device was applying blanket restrictions. Next, we assessed standard ports (80, 443) and alternative ports (30080, 30443) to ensure that legitimate connections, including those necessary for system updates, were not blocked unnecessarily. Disruptions can leave devices vulnerable to unpatched security flaws. We then moved on to file-based testing, starting with system files and executables and then productivity- related formats, compressed files, and media files.

100.00%

Figure 6 — False Positive Accuracy

The CyberRatings false positive repository contains ~100,000 samples, including URLs, file transfers, and application flows relevant to enterprises. Software cracks, game cheats, crypto wallets, mining software, and adware-bundled freeware are excluded.

The false positive test comprised of two categories:

• High Impact: False positives can have significant operational consequences, forcing teams to disable security features and reducing overall protection. Additionally, they create unnecessary workloads for security teams, leading to “alert fatigue” and increasing the risk of real threats being overlooked.

• Low Impact: Tested traffic with minimal business consequences.

Figure 7 shows how the product blocked false positives in the abovementioned categories.

False Positive Categories Impact False Positive Accuracy

System Files (.dll, .lib, etc.) High 100.00%

Executables (.exe,.msi, etc) High 100.00%

Productivity (.sh,.json, .xlsx, etc.) High 100.00%

Compressed Files (.zip, .gz, .cab, .tar, etc.) High 100.00%

Media (.png, ico , etc.) High 100.00%

Other files Low 100.00%

Figure 7 — False Positives (II)

Since firewalls may dynamically adjust settings using machine learning, false positives were checked before, during, and after threat testing. A sample was classified as a false positive if it was blocked at any point during the testing window.

8

Q1 2025 | CLOUD NETWORK FIREWALL

Exploits This test verified the firewall’s ability to detect and block exploits targeting known vulnerabilities. An exploit is an attack that takes advantage of a vulnerability in a protocol, product, operating system, or server application.

The CyberRatings exploit repository is a collection of internal, third-party, in-the-wild, and public exploits encompassing a wide range of protocols and applications. It is based on the Common Vulnerabilities and Exposures (CVEs) publicly listed in the MITRE CVE and NIST NVD databases.4

The subset of exploits selected for this test includes, but is not limited to:

• Recent vulnerabilities (last 5-10 years)

• CISA’s Known Exploited Vulnerabilities

• Vulnerabilities with a high Common Vulnerability Scoring System (CVSS) score (version 3.x)

100.00%

Figure 8 — Exploit Effectiveness

4 cve.org: https://www.cve.org/; NIST NVD: https://nvd.nist.gov/vuln/search

Coverage by CVE & Date

The figure below provides insight into whether a vendor is actively phasing out protection signatures to maintain performance levels and indicates whether a product lags in addressing the latest vulnerabilities. CyberRatings reports exploits by individual years for the past decade. Additionally, we can observe how the vendor offers exploit protection for CVEs rated critical and high, which encompasses most of our testing.

2014 2015 2016 2017 2018 2019 2020 2021 2022 2023 H1 2024

CVE Critical Classification 100.0% 100.0% 100.0% 100.0% 100.0% 100.0% 100.0% 100.0% 100.0% 100.0% 100.0%

CVE High Classification 100.0% 100.0% 100.0% 100.0% 100.0% 100.0% 100.0% 100.0% 100.0% 100.0% 100.0%

Overall Block Rate 100.0% 100.0% 100.0% 100.0% 100.0% 100.0% 100.0% 100.0% 100.0% 100.0% 100.0%

0%

20%

40%

60%

80%

100%

E xp

lo it

B lo

ck R

at e

p er

Y ea

r

Figure 9 — Exploit Block Rate per Year / CVE Category Critical or High

Q1 2025 | CLOUD NETWORK FIREWALL

9

Coverage by Target Vendor

Exploits within the CyberRatings exploit library target many protocols and applications. The figure below shows how the product under test offers exploit protection for ten top vendors targeted in this test. This is a good metric in assessing if your environment is protected by the vendors signatures.

100.0% 100.0% 100.0% 100.0% 100.0% 100.0% 100.0% 100.0% 100.0% 100.0%

0%

20%

40%

60%

80%

100%

Adobe Advantech Apache IBM Cisco HPE Microsoft Oracle Solarwinds VMware

Figure 10 — Coverage by Target Vendor

Q1 2025 | CLOUD NETWORK FIREWALL

10

Evasions This test verified the firewall’s ability to detect and block known evasion techniques.

Firewalls should detect and mitigate evasion techniques, have the ability to normalize evasion traffic and provide accurate alerts for original threats. Threat actors use evasion techniques to disguise and modify attacks at the point of delivery to avoid detection by security products. Therefore, a firewall must correctly handle evasions since just one successful technique can enable an attacker to bypass systems undetected.

Missing a type of evasion means a hacker can use an entire class of exploits to circumvent the security product. CyberRatings used multiple exploits for each evasion technique to see how each product defended against these combinations.

100.00%

Figure 11 — Evasion Effectiveness

The CyberRatings exploit repository is a collection of internal, third party, in-the-wild, and public exploits covering a wide range of protocols. CyberRatings utilizes a proprietary repository of evasion techniques, layering these techniques to create several thousand unique scenarios.

By employing multiple techniques across various protocols, we evaluated the firewall’s capacity to normalize traffic and identify threats in complex, real-world scenarios, ensuring a robust defense against evolving attack vectors.

This test aimed to determine whether an evasion technique could bypass the firewall. We designed our tests to cover a broad 27 categories of evasion techniques and several baseline exploits, resulting in 2,500 total attempts.

First, we confirmed that the firewall detected and blocked a range of baseline exploits. Next, we applied evasion techniques to the baseline exploits and verified the execution of the exploit’s payload delivery. Whenever possible, the firewall was expected to effectively normalize the evaded traffic to provide an accurate alert regarding the original attack instead of alerting solely on anomalous traffic detected due to the evasion technique.

Scoring Evasions

We adjusted scoring for evasions by assessing their overall impact on exploit effectiveness. Specifically, we prioritized evasions that could be broadly applied across multiple attack vectors. For example, TCP-based evasions generally have a wider range of applications than HTTP-based evasions. This is because TCP evasions operate at a lower level in the network stack, allowing attackers to obfuscate traffic in ways that can affect thousands of exploits across different protocols. In contrast, HTTP evasions are typically constrained to application-layer attacks, limiting their applicability to a smaller subset of exploits.

We tested multiple exploit samples for each evasion technique to ensure a comprehensive evaluation. This approach allowed us to observe how the firewall responded to different evasion combinations. By analyzing these results, we gained deeper insights into how effectively the product mitigates evasion tactics and where vulnerabilities may still exist. For details on how scoring works, see table below.

.

Q1 2025 | CLOUD NETWORK FIREWALL

11

Evasion Technique Category OSI Level

Evasion Technique

Score Impact

Max Impact

IP Fragmentation : Non-Overlapping L3 Pass 50.0%

100%

IP Fragmentation : Overlapping L3 Pass 50.0%

IP Header : Checksum L3 Pass 50.0%

IP Header : Options L3 Pass 50.0%

IP Header : Protocol L3 Pass 50.0%

IP Header : Time to Live L3 Pass 50.0%

TCP Header : Checksum L4 Pass 20.0%

60%

TCP Header : Data Offset L4 Pass 20.0%

TCP Header : Options : Timestamps L4 Pass 20.0%

TCP Header : Sequence Number L4 Pass 20.0%

TCP Segmentation : Non-Overlapping Segments L4 Pass 20.0%

TCP Segmentation : Overlapping Segments L4 Pass 20.0%

TCP Transfer Control Block : Flags L4 Pass 20.0%

TCP Transfer Control Block : Resync Sequence Numbers L4 Pass 20.0%

TCP Transfer Control Block : Retransmission L4 Pass 20.0%

HTTP Content Encoding : Identity L7 Pass 1.0%

10%

HTTP Content Encoding : Identity,HTTP Transfer Encoding : Chunked L7 Pass 1.0%

HTTP Headers : Bogus Content Encoding L7 Pass 1.0%

HTTP Headers : Bogus HTTP/1.0 Declaration L7 Pass 1.0%

HTTP Headers : Bogus Transfer Encoding L7 Pass 1.0%

HTTP Headers : Eicar L7 Pass 1.0%

HTTP Headers : Padding L7 Pass 1.0%

HTTP Headers : X-Forwarded-For L7 Pass 1.0%

HTTP Transfer Encoding : Chunked L7 Pass 1.0%

HTTP Transfer Encoding : Chunked : Alternative Chunk-Size Value L7 Pass 1.0%

HTTP Transfer Encoding : Identity L7 Pass 1.0%

Content JSON : Unicode Escaped Strings L7 Pass 1.0%

Figure 12 — Evasion Details

12

Q1 2025 | CLOUD NETWORK FIREWALL

Performance The cloud network firewall’s performance was evaluated under various traffic conditions, providing metrics for real-world performance. Individual implementations may differ based on usage; however, these quantitative metrics serve as a gauge for determining whether a specific firewall is suitable for a given environment. Please note that performance testing and baselines were limited to a ceiling matching the documented committed network performance (not burst performance) limit for the cloud instance type selected for testing.5

Rated Throughput To establish a rated throughput that would be easy to measure for all firewalls, we measured performance to determine the sustained throughput of the cloud network firewall over time for a range of packet sizes and connections per second, capturing the firewall’s performance curves for HTTP and HTTPS.

The “Plain Text Rated Throughput,” “TLS/SSL Rated Throughput,” and the combined “Rated Throughput” are good benchmarks for what an enterprise can expect the firewall instance to achieve consistently (over time) when deployed in the cloud. The Rated Throughput is 80% for TLS/SSL and 20% for Plain Text.

Performance Test Mbps

Plain Text Rated Throughput (Average of HTTP Capacity tests) 821

TLS/SSL Rated Throughput (Average of HTTPS Capacity tests) 282

Rated Throughput 390

Figure 13 — Rated Throughput (Mbps)

For Cloud Service Provider firewalls, there is only one deployment option available. For third-party security vendor firewall solutions that were deployed and tested on AWS infrastructure, the following applied:

AWS offers a variety of instance types with both baseline and burst bandwidth. Choosing the right AWS instance type is crucial for application performance, as it determines the allocation of computing resources such as CPU cores, memory, and network bandwidth. Each instance type is designed to optimize specific workloads—for example, compute-optimized instances for CPU-intensive tasks, memory-optimized instances for extensive data processing or database operations, and GPU-optimized instances for graphics rendering or machine learning.

Selecting the appropriate instance type ensures optimal performance by aligning resource allocation with the application’s requirements. For instance, high-performance computing tasks benefit from instances with many CPU cores and high network speeds, while database-heavy workloads require memory-optimized instances to reduce disk I/O. Likewise, GPU optimized instances are essential for training deep learning models. Failing to align the instance type with the application’s needs can result in performance bottlenecks or failures. When selecting an instance type, consider the application’s CPU, memory, and network requirements, assess the cost-performance ratio, and ensure scalability to accommodate changing demands effectively.

We selected the vendor’s recommended instance type. This instance was utilized to establish baseline control and was later re-evaluated with the firewall configured identically for exploits and evasions.

5 As an example, AWS uses the term “Baseline” to indicate the committed network performance rate (non-bursting performance) in their Instance Network Specifications documentation. CyberRatings’ testing of a selected AWS instance type will be limited to a ceiling matching the AWS instance type’s network performance “Baseline” (e.g. 0.75 Gbps for m5.large instance type).

Q1 2025 | CLOUD NETWORK FIREWALL

13

Maximum Capacity The goal was to stress the firewall and determine how it handles high volumes of connections per second, HTTP transactions per second, and concurrent open connections. All packets contained valid payload and address data, and these tests provided an excellent measurement of maximum connection rates and concurrency (simultaneous users/traffic).

7,910

1,756 1,125

18,216

0

2,000

4,000

6,000

8,000

10,000

12,000

14,000

16,000

18,000

20,000

Max HTTP TPS Max HTTP CPS Max HTTPS CPS (0x13-0x02) Max HTTPS CPS (0xC0-0x30)

T P

S /C

P S

Figure 14 — HTTP Connections & Transactions per Second

Note that in all tests, the following critical “breaking points” – where the final measurements are taken – are used:

• Excessive concurrent HTTP connections – Latency within the firewall caused an excessive delay and increased response time.

• Unsuccessful HTTP/S transactions – Normally, there should be zero unsuccessful transactions. Once these appeared, it is an indication that excessive latency within the firewall is causing connections to time out.

• Maximum HTTP Connections per Second – This test is designed to determine the HTTP connection rate of the firewall with a one-byte response size.

• Maximum HTTP Transactions per Second – This test is designed to determine the maximum HTTP transaction rate of the device with a one-byte HTTP response size.

• Maximum HTTPS Connections per Second – This test is designed to determine the maximum HTTPS connection rate of the firewall with a one-byte response size.

The response size defines the number of bytes contained in the body, excluding any bytes associated with the HTTP/S header. A one-byte response size is designed to provide theoretical maximum connections/transactions per second rate.

Q1 2025 | CLOUD NETWORK FIREWALL

14

HTTP Capacity The goal was to stress the HTTP detection engine and determine how the device copes with network loads of varying average packet sizes and varying connections per second. By creating genuine session-based traffic with varying session lengths, the device was forced to track valid TCP sessions, thus ensuring a higher workload than simple packet-based background traffic. This provided a test environment as close to real-world conditions as possible in a lab while ensuring absolute accuracy and repeatability.

2.7 KB Response 6.4 KB Response 13.5 KB Response 28.0 KB Response 57.4 KB Response 115.6 KB Response

CheckPoint Tested Throughput (CPS) 6,157 6,012 4,868 3,699 2,522 1,562

AWS Max Throughput (CPS) 49,984 24,992 12,496 6,248 3,124 1,562

CheckPoint Tested Throughput (Mbps) 192 376 609 925 1,261 1,562

6,157 6,012 4,868

3,699 2,522 1,562

49,984

24,992

12,496

6,248

3,124 1,562

0

200

400

600

800

1,000

1,200

1,400

1,600

1,800

0

10,000

20,000

30,000

40,000

50,000

60,000

M b

p s

C o

n n

e c ti

o n

s p

e r

S e

c o

n d

Figure 15 — HTTP Capacity

Each transaction consisted of a single HTTP GET request, and there were no delays (i.e., the webserver responded immediately to all requests). All packets contained valid payload (a mix of binary and ASCII objects) and address data. Testing determined the maximum rate the firewall was able to process HTTP packets of multiple sizes and its efficiency of forwarding packets quickly to provide the highest level of network performance with the lowest latency. The results were recorded at each response size at a load level of 95% of the maximum throughput, just before latency increased (which indicates the throughput is not sustainable).

Q1 2025 | CLOUD NETWORK FIREWALL

15

HTTPS Capacity The goal was to stress the HTTPS engine and determine how the device coped with network loads of varying average packet sizes and varying connections per second.

0.2 KB Response 3.9 KB Response 11.2 KB Response 25.7 KB Response 54.9 KB Response 113.8 KB Response

CheckPoint Tested Throughput (CPS) 1,497 1,377 1,311 1,196 1,001 745

AWS Max HTTPS Throughput (CPS) 49,900 24,992 12,496 6,248 3,124 1,562

CheckPoint Tested Throughput (Mbps) 47 86 164 299 501 745

1,497

1,377

1,311 1,196 1,001 745

49,900

24,992

12,496

6,248

3,124 1,562

0

100

200

300

400

500

600

700

800

0

10,000

20,000

30,000

40,000

50,000

60,000

M b

p s

C o

n n

e c ti

o n

s p

e r

S e

c o

n d

Figure 16 — HTTPS Capacity for TLS 1.3 (TLS_AES_256_GCM_SHA384 [0x13, 0x02])

0.2 KB Response 3.9 KB Response 11.2 KB Response 25.7 KB Response 54.9 KB Response 113.8 KB Response

CheckPoint Tested Throughput (CPS) 1,519 1,474 1,397 1,260 1,010 777

AWS Max HTTPS Throughput (CPS) 49,848 24,992 12,496 6,248 3,124 1,562

CheckPoint Tested Throughput (Mbps) 47 92 175 315 505 777

1,519

1,474

1,397 1,260 1,010 777

49,848

24,992

12,496

6,248

3,124 1,562

0

100

200

300

400

500

600

700

800

900

0

10,000

20,000

30,000

40,000

50,000

60,000

M b

p s

C o

n n

e c ti

o n

s p

e r

S e

c o

n d

Figure 17 — HTTPS Capacity for TLS 1.3 (TLS_AES_128_GCM_SHA256 [0x13, 0x01])

By creating session-based traffic with varying session lengths, the device was forced to track valid TCP sessions, thus ensuring a higher workload than simple packet-based background traffic. Encrypting the traffic using TLS/SSL with varying algorithms forced the device to decrypt traffic before inspection, increasing the workload further. This provided a test environment that is as close to real-world conditions as possible to achieve in a lab environment (albeit biased towards HTTPS traffic) while ensuring accuracy and repeatability. Tests were performed similarly to HTTP with one HTTPS transaction per connection. Testing determined the maximum rate the firewall was able to process HTTPS traffic of various sizes and its efficiency at forwarding packets quickly to provide the highest level of network performance with the lowest latency. The results were recorded at each response size at a load level of 95% of the maximum throughput, just before latency increased (which indicates the throughput is not sustainable).

Q1 2025 | CLOUD NETWORK FIREWALL

16

1.4 KB Response 5.0 KB Response 12.3 KB Response 27.0 KB Response 56.3 KB Response 115.0 KB Response

CheckPoint Tested Throughput (CPS) 1,118 1,070 1,021 938 785 634

AWS Max HTTPS Throughput (CPS) 47,467 24,992 12,496 6,248 3,124 1,562

CheckPoint Tested Throughput (Mbps) 35 67 128 235 393 634

1,118

1,070

1,021 938 785 634

47,467

24,992

12,496

6,248

3,124 1,562

0

100

200

300

400

500

600

700

0

5,000

10,000

15,000

20,000

25,000

30,000

35,000

40,000

45,000

50,000

M b

p s

C o

n n

e c ti

o n

s p

e r

S e

c o

n d

Figure 18 — HTTPS Capacity for TLS 1.2 (TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 [0xC0, 0x30])

1.4 KB Response 5.0 KB Response 12.3 KB Response 27.0 KB Response 56.3 KB Response 115.0 KB Response

CheckPoint Tested Throughput (CPS) 1,114 1,130 1,023 944 822 655

AWS Max HTTPS Throughput (CPS) 46,957 24,992 12,496 6,248 3,124 1,562

CheckPoint Tested Throughput (Mbps) 35 71 128 236 411 655

1,114

1,130

1,023 944 822 655

46,957

24,992

12,496

6,248

3,124 1,562

0

100

200

300

400

500

600

700

0

5,000

10,000

15,000

20,000

25,000

30,000

35,000

40,000

45,000

50,000

M b

p s

C o

n n

e c ti

o n

s p

e r

S e

c o

n d

Figure 19 — HTTPS Capacity for TLS 1.2 (TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 [0xC0, 0x2F])

Q1 2025 | CLOUD NETWORK FIREWALL

17

Delta between HTTP and HTTPS Capacity & Throughput How did the encryption overhead affect the bandwidth for the provided payloads? And how does the size of what is being transferred impact performance?

0.2 KB Response 3.9 KB Response 11.2 KB Response 25.7 KB Response 54.9 KB Response 113.8 KB Response

CheckPoint HTTP Throughput (CPS) 7,535 6,519 5,023 3,898 2,524 1,562

CheckPoint HTTPS Throughput (CPS) 1,497 1,377 1,311 1,196 1,001 745

CheckPoint HTTP Throughput (Mbps) 235 407 628 975 1,262 1,562

CheckPoint HTTPS Throughput (Mbps) 47 86 164 299 501 745

7,535

6,519

5,023

3,898

2,524

1,5621,497 1,377

1,311 1,196

1,001 745

0

200

400

600

800

1,000

1,200

1,400

1,600

1,800

0

1,000

2,000

3,000

4,000

5,000

6,000

7,000

8,000

M b

p s

C o

n n

e c ti

o n

s p

e r

S e

c o

n d

Figure 20 — Delta betweeb HTTP and HTTPS Capacity & Throughput

The purpose of these tests was to measure the amount of overhead added to each payload based on the cipher suite used. This test used HTTP without any TLS and then we tested the same payload using TLS 1.3 (TLS_AES_256_GCM_SHA384 [0x13, 0x02]). Each transaction consisted of a single HTTPS GET request with no transaction delays (i.e., the web server responds immediately to all requests). All traffic contains valid payloads.

Q1 2025 | CLOUD NETWORK FIREWALL

18

Stability & Reliability Long-term stability is essential for a firewall, where failure can produce network outages. These tests verified the firewall’s stability and ability to maintain security effectiveness while under normal load and while passing malicious traffic. Products that could not sustain legitimate traffic (or that crash) while under hostile attack did not pass.

The product was required to remain operational and stable throughout these tests and to block 100% of previously blocked traffic, raising an alert for each instance. If any policy-forbidden traffic passed—either due to a high volume of traffic or because the product failed open for any reason—this resulted in a fail.

Stability and Reliability Result

Blocking under Extended Attack

Blocking with Minimal Load Pass

Blocking Under Load Pass

Behavior of the State Engine under Load

Attack Detection/Blocking – Normal Load Pass

State Preservation – Normal Load Pass

Pass Legitimate Traffic – Normal Load Pass

State Preservation – Maximum Exceeded Pass

Drop Traffic – Maximum Exceeded Pass

Figure 21 — Stability & Reliability

Blocking Under Extended Attack These tests indicated the ability of the firewall to remain operational and stable (i.e., block violations and raise associated alerts) throughout an extended attack

Behavior of the State Engine Under Load These tests determined if the device could preserve its state across numerous open connections over an extended period. At various stages throughout the test (including after the maximum was reached), it was confirmed that the device could inspect and block traffic that violated the currently enforced security policy while ensuring that legitimate traffic was not blocked.

Q1 2025 | CLOUD NETWORK FIREWALL

19

Cost of Tested Configuration To assess the overall value of a firewall solution, security effectiveness should be evaluated alongside its cost. Implementation of security solutions can be complex, with several factors affecting the overall cost of deployment, maintenance, and upkeep.

For this report, we have estimated the cost of:

• 1 month of product usage (assuming 730 hours)

• 10 TB of data transfer per month to the internet

Understanding Cloud Deployment Costs The cost of deploying products in the cloud varies based on the use case and deployment model. Some cost components apply universally, while others depend on the specific service and how it is utilized. Below are common categories of cloud-related costs:

Product or Endpoint Costs (May Apply Depending on the Service)

Some cloud-based products have a fixed cost per instance, endpoint, or subscription. Others may be billed based on metered usage, such as the number of protected endpoints in a security solution or the amount of storage consumed.

Data Processing Costs (Typically Applies)

Many cloud services incur a cost for processing data, which can vary based on compute power, memory usage, or the complexity of operations performed on the data. For example, a firewall inspecting network traffic or a machine learning model analyzing logs will generate processing costs.

Data Transfer Costs (Product-Specific) (May Apply Depending on the Product)

Some cloud products charge for the volume of data they handle internally, such as log ingestion, telemetry, or large-scale data analysis. These costs can differ based on whether the data is transferred between cloud services or within the same service.

Cloud Provider Data Transfer Costs (Egress Fees) (Typically Applies When Data Leaves the Cloud)

Data that leaves the cloud provider’s infrastructure—such as from an EC2 instance to the public internet—incurs egress fees, usually charged per TB transferred. These costs can be a significant factor, especially for services that require large data transfers, such as content delivery, backups, or analytics.

Q1 2025 | CLOUD NETWORK FIREWALL

20

Price Per Mbps One way to consider value is in the context of price/performance, or, in this case, Price/Mbps. We have previously calculated each product’s rated throughput. Please see the performance section for more details. Using this formula, we can normalize data and account for wide-ranging price differences and product performance.

Price per Mbps = Total Cost (1-Month) / Rated Throughput (Mbps)

Figure 22 — Price per Mbps Formula

Cost Calculation The pricing was collected from Check Point’s product page on the AWS Marketplace:

• CloudGuard Network Security Next-Gen Firewall with Threat Prevention R81.20 Jumbo Hotfix Take 89: c6i- xlarge (Instance) = $664.30

If a customer opts to use the CloudGuard Network Security Next-Gen Firewall with Threat Prevention pay-as-you- go license with the c6i-xlarge in AWS (North Virginia), at an hourly cost of $0.17, the calculation would be as follows:

• Data Processing Cost: $0.17 * 730 hours = $124.10

• Data Transfer Cost: $0.09 * 10 TB (EC2) = $921.60

• Total Cost for one month: $1,710.00

1 Month Cost Tested Throughput (Mbps) Price per Mbps

$1,710 390 $4.38

Figure 23 — Price per Mbps Calculation

21

Q1 2025 | CLOUD NETWORK FIREWALL

Scorecard Summary

Vendor CheckPoint

Cloud Service Provider AWS

Instance Type (AWS or Native) c6i.xlarge

Version R81.20 Jumbo Hotfix Take 89

IPS Version 635250610

vCPU 4

Memory 8

False Positives Result

System Files (.dll, .lib, etc.) 100.00%

Executables (.exe,.msi, etc) 100.00%

Productivity (.sh,.msi,.json, .xlsx, etc.) 100.00%

Compressed Files (.zip, .gz, .cab, .tar, etc.) 100.00%

Media (.png, ico , etc.) 100.00%

Other files 100.00%

Routing Functionality Result

Unrestricted Traffic Test Pass

Segmented Traffic Test Pass

Access Control Result

Simple Policies Pass

Complex Multi-Zone Policies Pass

TLS/SSL Support

Cipher Suites Prevalence Version Result

TLS_AES_256_GCM_SHA384 (0x13, 0x02) 69% TLS 1.3 PASS

TLS_AES_128_GCM_SHA256 (0x13, 0x01) 11% TLS 1.3 PASS

TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (0xC0, 0x30) 9% TLS 1.2 PASS

TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 (0xC0, 0x2F) 7% TLS 1.2 PASS

TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256 (0xCC, 0xA8) 1% TLS 1.3 PASS

Decryption Validation Supported

Decryption Bypass Exceptions Supported

TLS Session Reuse - Session Tickets Supported

TLS Session Reuse - Session IDs Supported

22

Q1 2025 | CLOUD NETWORK FIREWALL

Exploits Block Rate

Exploits 100.00%

Evasion Effectiveness Result

IP Fragmentation : Non-Overlapping Pass

IP Fragmentation : Overlapping Pass

IP Header : Checksum Pass

IP Header : Options Pass

IP Header : Protocol Pass

IP Header : Time to Live Pass

TCP Header : Checksum Pass

TCP Header : Data Offset Pass

TCP Header : Options : Timestamps Pass

TCP Header : Sequence Number Pass

TCP Segmentation : Non-Overlapping Segments Pass

TCP Segmentation : Overlapping Segments Pass

TCP Transfer Control Block : Flags Pass

TCP Transfer Control Block : Resync Sequence Numbers Pass

TCP Transfer Control Block : Retransmission Pass

HTTP Content Encoding : Identity Pass

HTTP Content Encoding : Identity,HTTP Transfer Encoding : Chunked Pass

HTTP Headers : Bogus Content Encoding Pass

HTTP Headers : Bogus HTTP/1.0 Declaration Pass

HTTP Headers : Bogus Transfer Encoding Pass

HTTP Headers : Eicar Pass

HTTP Headers : Padding Pass

HTTP Headers : X-Forwarded-For Pass

HTTP Transfer Encoding : Chunked Pass

HTTP Transfer Encoding : Chunked : Alternative Chunk-Size Value Pass

HTTP Transfer Encoding : Identity Pass

Content JSON : Unicode Escaped Strings Pass

Performance

Maximum Capacity CPS TPS

Max HTTP CPS 7,910 N/A

Max HTTP TPS N/A 18,216

Max HTTPS (0x13-0x02) 1,756 N/A

Max HTTPS (0x13-0x01) 1,125 N/A

23

Q1 2025 | CLOUD NETWORK FIREWALL

HTTP Capacity (without transaction delay) CPS Throughput (Mbps)

Response Time (ms)

1,000 Connections per Second - 115.6 KB Response 1,562 1,562 186.40

2,000 Connections per Second - 57.4 KB Response 2,522 1,261 109.64

4,000 Connections per Second - 28.0 KB Response 3,699 925 87.55

8,000 Connections per Second - 13.5 KB Response 4,868 609 44.49

16,000 Connections per Second - 6.4 KB Response 6,012 376 30.32

32,000 Connections per Second - 2.7 KB Response 6,157 192 24.43

HTTPS Capacity (0x13, 0x02) CPS Throughput (Mbps)

Response Time (ms)

1,000 Connections per Second - 113.8 KB Response 745 745 260.50

2,000 Connections per Second - 54.9 KB Response 1,001 501 158.11

4,000 Connections per Second - 25.7 KB Response 1,196 299 114.02

8,000 Connections per Second - 11.2 KB Response 1,311 164 57.44

16,000 Connections per Second - 3.9 KB Response 1,377 86 19.28

32,000 Connections per Second - 0.2 KB Response 1,497 47 0.01

HTTPS Capacity (0x13, 0x01) CPS Throughput (Mbps)

Response Time (ms)

1,000 Connections per Second - 113.8 KB Response 777 777 209.53

2,000 Connections per Second - 54.9 KB Response 1,010 505 147.81

4,000 Connections per Second - 25.7 KB Response 1,260 315 83.44

8,000 Connections per Second - 11.2 KB Response 1,397 175 49.06

16,000 Connections per Second - 3.9 KB Response 1,474 92 18.13

32,000 Connections per Second - 0.2 KB Response 1,519 47 0.01

HTTPS Capacity (0xC0, 0x30) CPS Throughput (Mbps)

Response Time (ms)

1,000 Connections per Second - 115.0 KB Response 634 634 368.65

2,000 Connections per Second - 56.3 KB Response 785 393 166.04

4,000 Connections per Second - 27.0 KB Response 938 235 96.77

8,000 Connections per Second - 12.3 KB Response 1,021 128 67.09

16,000 Connections per Second - 5.0 KB Response 1,070 67 16.93

32,000 Connections per Second - 1.4 KB Response 1,118 35 0.01

HTTPS Capacity (0xC0, 0x2F) CPS Throughput (Mbps)

Response Time (ms)

1,000 Connections per Second - 115.0 KB Response 655 655 313.87

2,000 Connections per Second - 56.3 KB Response 822 411 175.40

4,000 Connections per Second - 27.0 KB Response 944 236 108.12

8,000 Connections per Second - 12.3 KB Response 1,023 128 78.26

Q1 2025 | CLOUD NETWORK FIREWALL

24

16,000 Connections per Second - 5.0 KB Response 1,130 71 31.30

32,000 Connections per Second - 1.4 KB Response 1,114 35 0.01

HTTP and HTTPS Delta (Using same packet size)

HTTP Capacity (without transaction delay) CPS Throughput (Mbps)

Response Time (ms)

1,000 Connections per Second - 113.8 KB Response 1,562 1,562 324.22

2,000 Connections per Second - 54.9 KB Response 2,524 1,262 206.19

4,000 Connections per Second - 25.7 KB Response 3,898 975 87.58

8,000 Connections per Second - 11.2 KB Response 5,023 628 33.22

16,000 Connections per Second - 3.9 KB Response 6,519 407 32.86

32,000 Connections per Second - 0.2 KB Response 7,535 235 0.00

HTTPS Capacity (0x13, 0x02) CPS Throughput (Mbps)

Response Time (ms)

1,000 Connections per Second - 113.8 KB Response 745 745 260.50

2,000 Connections per Second - 54.9 KB Response 1,001 501 158.11

4,000 Connections per Second - 25.7 KB Response 1,196 299 114.02

8,000 Connections per Second - 11.2 KB Response 1,311 164 57.44

16,000 Connections per Second - 3.9 KB Response 1,377 86 19.28

32,000 Connections per Second - 0.2 KB Response 1,497 47 0.01

Stability and Reliability Result

Blocking under Extended Attack

Blocking with Minimal Load Pass

Blocking Under Load Pass

Behavior of the State Engine under Load

Attack Detection/Blocking – Normal Load Pass

State Preservation – Normal Load Pass

Pass Legitimate Traffic – Normal Load Pass

State Preservation – Maximum Exceeded Pass

Drop Traffic – Maximum Exceeded Pass

Q1 2025 | CLOUD NETWORK FIREWALL

25

Special Thanks We want to issue a special thank you to Keysight for providing their CyPerf and BreakingPoint tools for us to test the performance, TLS functionality, and stability of Cloud Network Firewalls.

Authors Thomas Skybakmoen, Ahmed Basheer, Tim Otto, Vikram Phatak

Contact Information CyberRatings.org

515 South Capital of Texas Highway

Suite 225

Austin, TX 78746

info@cyberratings.org

www.cyberratings.org

© 2025 CyberRatings. All rights reserved. No part of this publication may be reproduced, copied/scanned, stored on a retrieval system, emailed, or otherwise disseminated or transmitted without the express written consent of CyberRatings (“us” or “we”).

Please read the disclaimer in this box because it contains important information that binds you. If you do not agree to these conditions, you should not read the rest of this report but should instead return the report immediately to us. “You” or “your” means the person who accesses this report and any entity on whose behalf he/she has obtained this report.

1. The information in this report is subject to change by us without notice, and we disclaim any obligation to update it.

2. The information in this report is believed by us to be accurate and reliable at the time of publication but is not guaranteed. All use of and reliance on this report are at your sole risk. We are not liable or responsible for any damages, losses, or expenses of any nature whatsoever arising from any error or omission in this report.

3. NO WARRANTIES, EXPRESS OR IMPLIED ARE GIVEN BY US. ALL IMPLIED WARRANTIES, INCLUDING IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, AND NON-INFRINGEMENT, ARE HEREBY DISCLAIMED AND EXCLUDED BY US. IN NO EVENT SHALL WE BE LIABLE FOR ANY DIRECT, CONSEQUENTIAL, INCIDENTAL, PUNITIVE, EXEMPLARY, OR INDIRECT DAMAGES, OR FOR ANY LOSS OF PROFIT, REVENUE, DATA, COMPUTER PROGRAMS, OR OTHER ASSETS, EVEN IF ADVISED OF THE POSSIBILITY THEREOF.

4. This report does not constitute an endorsement, recommendation, or guarantee of any of the products (hardware or software) tested or the hardware and/or software used in testing the products. The testing does not guarantee that there are no errors or defects in the products or that the products will meet your expectations, requirements, needs, or specifications, or that they will operate without interruption.

5. This report does not imply any endorsement, sponsorship, affiliation, or verification by or with any organizations mentioned in this report.

6. All trademarks, service marks, and trade names used in this report are the trademarks, service marks, and trade names of their respective owners.


Item Type: pdf