Solution Brief | Check Point Cloud Firewall for AWS Technical Overview
Secure cloud workloads with advanced threat prevention, unified management, and automated scaling. This solution brief breaks down architecture, deployment models, and key capabilities of Check Point Cloud Firewall for AWS. Download the solution brief.

© 2026 Check Point Software Technologies Ltd. All rights reserved.
About This Document
With Check Point Cloud Firewall on AWS, customers gain advanced threat prevention,
unified management, and automated protection that scales seamlessly with their cloud
workloads. This document outlines the key features and capabilities of Check Point
Cloud Firewall and its native integration with Amazon Web Services (AWS), providing a
comprehensive breakdown of deployment models, security functions, automation and
scaling mechanisms, content security, monitoring, and advanced networking features,
designed to help organizations secure dynamic, cloud-native environments with
maximum flexibility and visibility.
Contents
Check Point Components and Architecture .................................................................................................. 1
Performance ................................................................................................................................................. 2
Deployment ................................................................................................................................................... 3
Management, Visibility, and Monitoring ........................................................................................................ 3
Security ......................................................................................................................................................... 4
Cloud Integration & Automation ................................................................................................................... 5
Network Features ......................................................................................................................................... 5
Check Point Cloud Firewall for Amazon Web Services Architecture, Performance, Features, and Capabilities
© 2026 Check Point Software Technologies Ltd. All rights reserved.
CHECK POINT CLOUD FIREWALL FOR AWS
CHECK POINT COMPONENTS AND ARCHITECTURE 1
Check Point Components and Architecture
m t ou centrally manages e erything, interoperable with SmartConsole
deploys gateways using predefined templates
ont o e syncs dynamic ob ects from cloud to policy
Th e t ou A not shown pro ides real time threat intelligence to gateways and collects data from them
m t ou Deployed as a SaaS
ont o e Deployed on the management ser er Smart 1 Cloud or on prem
te s Firewalls irtual or F aaS deployed in VPC, usually as part of auto scaling groups
m t ou
Central Management
ou n ement tension
Synchroni e Policies and ateway Pro isioning
martConsole ni ersal Policies o s ents
Automatic ate a pro isionin Polic pac a e assi nment
Polic pac a es, lo s, ob ect , confi urations, etc
ou ont o e
Automatic Ad ustment to Cloud Changes
namic polic push Cloud ob ects import
Pro isionin metadata, tunnel
info, etc eplo ment templates, disco er tri ers
a P updates, deleted assets disco er metadata
Cloud AP Connector
u ti b i ou s
PC to PC ransit ate a , ate a oad alancer, Cloud A
ate a s ate a s ate a s
© 2026 Check Point Software Technologies Ltd. All rights reserved.
CHECK POINT CLOUD FIREWALL FOR AWS
PERFORMANCE 2
Performance h k P ud F w R81.20 – AW 6 VM
Capability Tested 2 vCPU 4 vCPU 8 vCPU 16 vCPU
New connections handled per second 815,527 1,847,153 3,957,108 8,048,880
Maximum simultaneous connections (Firewall only) 42,700 67,300 140,000 150,000
Firewall with Intrusion Prevention (Gbps) 8.30 11.00 14.70 20.00
Firewall with Intrusion Prevention and App Control
(Gbps) 3.40 7.40 13.80 19.50
Full Threat Prevention Suite (Gbps) 2.50 5.30 11.20 19.50
Encrypted HTTPS with Firewall and IPS only (Gbps) 1.00 2.00 4.40 8.90
Encrypted HTTPS with Threat Prevention (Gbps) 0.60 1.20 2.40 5.40
Remote access VPN* - Simultaneous users (with
firewall & IPS) 500 1,000 1,700 2,900
Remote access VPN* - Simultaneous users (with
complete threat prevention) 400 750 1,500 2,500
N :
• F w w h I u P d A throughput is measured using Check
Point enterprise testing conditions
• Th fu Th P u includes firewall, intrusion pre ention, application control, URL
filtering, anti irus protection, and anti bot protection
• E d ff f is measured for HTTPS traffic using the same inspection profiles
• R VPN u is estimated based on ideal lab conditions and may ary in real
world deployments
• F w w h - - VPN was tested using the iPerf tool with UDP traffic and 1300 byte packet
si e under controlled conditions
• Accu c n e ±3% For items marked with *, the accuracy range is ±15%
© 2026 Check Point Software Technologies Ltd. All rights reserved.
CHECK POINT CLOUD FIREWALL FOR AWS
DEPLOYMENT 3
Deployment • Auto c in uppo t in AW Supports Auto Scaling roups, pro isioning or terminating Check
Point Cloud Firewall pre iously known as Cloud uard ateways based on demand, ensuring
elasticity and cost efficiency
• Auto c in nte tion vi ou ont o e Cloud Controller keeps track of auto scale e ents,
ensuring new instances are disco ered and decommissioned ones are remo ed from management
• te Dep o ment n Onbo in vi Token ateways use a one time SIC token embedded in
templates for secure registration with the management ser er
• A v nce Temp te B se P ovisionin Templates define the gateway configuration, including
software blades, policies, and custom scripts, ensuring consistency across deployments
• Autom tic otfi Dep o ment Installs pre appro ed hotfix packages during pro isioning to ensure
gateways are fully patched from the start
• uppo t fo AW T nsit te n te Lo B nce Enables integration with ad anced
A S networking constructs like T and LB for scalable, centrali ed traffic inspection
Management, Visibility, and Monitoring • ent ize ou B se n ement Smart 1 Cloud pro ides unified, cloud hosted security
management for all gateways and policies
• ecu it Po ic n ement n m t onso e Access Offers full featured policy and ob ect
management through SmartConsole, with web, desktop, and streamed access options
• nu Pe missions n A nte tion fo AW Uses IAM roles, STS Assume Role, or
credentials for secure, cloud nati e authentication and authori ation
• Re Time Up tes n TTL pi tion ont o Cloud ob ects ha e configurable TTLs to pre ent
stale data; the system refreshes information regularly
• Limit tions to Note Certain legacy features e g , VSX, SmartPro isioning, LEA are excluded from
cloud based management
• Lo Retention n po t to Supports log forwarding in multiple formats Syslog, LEEF, etc
to SIEMs like Splunk, QRadar, and ArcSight
• onito in , Lo in , n nte tion ith AW ecu it ub Sends threat detection logs and
findings to A S Security Hub for centrali ed isibility and incident response
• Lo Visibi it n T oub eshootin nh ncements Logs include rich metadata such as scan times
and ob ect names for better debugging and forensics
© 2026 Check Point Software Technologies Ltd. All rights reserved.
CHECK POINT CLOUD FIREWALL FOR AWS
SECURITY 4
Security • tensive B e uppo t vi Temp tes ateways can be pro isioned with a wide range of blades,
including Intrusion Pre ention, VPN, HTTPS Inspection, Application Control, and more
• Autonomous Th e t P evention Deli ers smart threat pre ention without needing fine tuned rule
definitions, ideal for dynamic en ironments
• uppo t fo VPN, NAT, n entit A eness Full support for secure tunneling, address
translation, and user identity based policy enforcement
• entit h in fo Auto c in te s Auto Scaling instances can recei e user identity data
from static PDPs, enabling consistent enforcement
• Use of T s in ecu it Po icies Enables tag based policies that automatically follow the lifecycle of
cloud resources e g , en =prod, role=db
• Po ic Objects ith D t ente Que ies Dynamic ob ects can be queried across cloud pro iders
and used in policies without hardcoding IPs
• Net o k oup Objects e te Pe c e et Automatically created and updated ob ects group all
members of an auto scaling set for use in policy rules
• Autom tic NAT n Access Ru e e tion Dynamically generates NAT and access rules based on
tags and listener configuration, reducing manual effort
• D n mic Use B se Po ic Enforces user and role based access control by integrating with
Microsoft Acti e Directory, LDAP, RADIUS, Cisco px rid, Terminal Ser ices, or third party identity
sources ia eb API Supports consistent policy enforcement across indows, macOS, Linux,
Android, and iOS platforms
• Fi st Time P evention p bi ities Includes OS le el and static file analysis, file saniti ation ia
Threat Extraction, and full sandbox emulation for unknown files under 100 seconds on a erage
• App ic tion ont o Includes 8,000+ pre defined application signatures and allows custom
definitions Administrators can accept, block, schedule, or apply bandwidth shaping to application
traffic
• D t Loss P evention DLP Identifies and classifies o er 700 pre defined data types, enabling
sensiti e data protection Includes mechanisms for end user alerts and data owner escalation
workflows
© 2026 Check Point Software Technologies Ltd. All rights reserved.
CHECK POINT CLOUD FIREWALL FOR AWS
CLOUD INTEGRATION & AUTOMATION 5
Cloud ntegration & Automation • AW Object nte tion VP s, ubnets, nst nces, T s, n o e Automatically disco ers and
synchroni es A S nati e ob ects such as EC2 instances, subnets, security groups, and tags, making
them a ailable as dynamic ob ects in the policy layer
• n ement n onito in ith AP s, Te fo m, n m t onso e Offers complete lifecycle
control ia REST APIs and Terraform for De Ops teams while pro iding intuiti e UI access through
SmartConsole for security operations and analysts
• uppo t fo u ti Account n u ti Re ion AW nvi onments Enables centrali ed management
across multiple A S accounts and regions through CME controllers and role based access,
ensuring secure and scalable cloud deployments
• L n onfi u tion Too s Supports flexible pro isioning and automation workflows using
tools like autopro _cfg, cme_menu, and CME’s REST API, enabling powerful customi ation and
scripting
• oss P tfo m entit n Po ic nte tion Integrates with Microsoft AD, LDAP, RADIUS, px rid,
and other third party identity sources, enabling consistent policy enforcement across cloud nati e,
hybrid, and remote user scenarios
Network Features • A v nce Net o kin p bi ities Supports Acti e/Acti e Layer 2, Acti e/Passi e Layer 2, and
Layer 3 configurations non applicable to CSPs with session failo er across routing changes, de ice
failures, and link disruptions
• Pv6 uppo t Includes NAT66 and performance optimi ation features such as CoreXL and SecureXL
• Routin u tic st Supports dynamic and static routing protocols, including OSPF 2, B P, RIP,
policy based routing, and multicast protocols such as PIM SM, PIM DM, and I MP 2/ 3
Read more about Check Point Cloud Firewall for public clouds
Wo i e e qu te s
5 Shlomo Kaplan Street, Tel A i 6789159, Israel | Tel +972 3 753 4599
U. . e qu te s
100 Oracle Parkway, Suite 800, Redwood City, CA 94065 | Tel 1 800 429 4391
.checkpoint.com
© 2026 Check Point Software Technologies Ltd All rights reser ed
Fin Us On
https://www.checkpoint.com/cloudguard/cloud-network-security/iaas-public-cloud-security/ https://aws.amazon.com/marketplace/search/results?searchTerms=CloudGuard+Network+Security https://aws.amazon.com/marketplace/seller-profile?id=a979fc8a-dd48-42c8-84cc-63d5d50e3a2f https://aws.amazon.com/marketplace/seller-profile?id=a979fc8a-dd48-42c8-84cc-63d5d50e3a2f