Solution Brief | Check Point Architecture Blueprint Diagrams

Solution Brief | Check Point Architecture Blueprint Diagrams

This solution brief outlines Check Point's flexible and scalable cloud security architecture, featuring advanced threat prevention, automated deployment, and continuous compliance. With single, double, and triple hub options, it ensures secure, scalable, and efficient deployment. Learn about dynamic policies, cloud-native tools, and network segmentation. Download to explore optimal security for your cloud environment.

Solution Brief | Check Point Architecture Blueprint Diagrams

1©2026 Check Point Software Technologies Ltd.

W E S E C U R E Y O U R A I T R A N S F O R M A T I O N

Check Point Cloud Firewall Architecture Blueprint Diagrams

Network Security

• Advanced Threat Prevention & Traffic Inspection • Common Policy and Logging Infrastructure • Unified management of physical and virtual infrastructure • Automated deployment through IaC • Dynamic policies map to cloud through tags and metadata • Support also for Oracle, Alibaba Cloud, IBM, and more

Additional Cloud Security Capabilities

• Continuous Compliance with Industry Frameworks and Best Practices

• Identify misconfigurations in IaaS and PaaS • Automatic Remediation integrated natively • WIZ Integration for Workload Protection for Kubernetes clusters and

Serverless functions • “Shift left” security posture into CI/CD pipeline • Consumes & correlates cloud native network and audit logs

Overall Architecture:

• ThreatCloud AI delivers real-time dynamic security intelligence from a collaborative cloud driven knowledge base

• Holistic security view • High Fidelity context for Threat Hunting & Intelligence • Extensive APIs integrated with Cloud Firewall, over 22 Vendors

supported

SIEM/Ticketing Solution

Traffic & Event Logs

WIZ CNAAP Integration CSPM

Workload Protection , Containers & Serverless

Branch Office SD-WAN

Automation & Orchestration

Remote Users

VPN IoT

Internet CloudBots (Auto-Remediation)

Public Cloud Private Cloud

AWS Cloud Formation

Azure Resource Manager

On Premises Data Center

Network Security Automation

Cloud Firewall

WAAP

Check Point Smart-1 Console

Email and Collaboration Security Endpoint Security Mobile Security Browser Security Extended Detection and Response (XDR)

Network Edge

Cloud Firewall

Internet

On Premises Data Center

CloudBots (Auto-Remediation)

< API >

Values

• “Network perimeter” security with Advanced Threat Prevention • Simple architecture deployment • Agility, Automation, Efficiency, Elasticity • Unified management for hybrid environment

Architecture

• The Single Hub (VPC or vNET) acts as a central point for the security of the entire cloud environment. • Ingress & Egress Zones for North/South Traffic Inspection • Ability to add East/West inspection between VPCs, VPN, or MPLS connections • Flexible deployment templates for single gateway, HA clusters, or Auto-Scaling group • With Auto-Scaling groups, automatic scale out and scale in based on load and performance • Spokes represent a virtual network where different assets are deployed.

VPN

Spoke-2 (Web App)

Load Balancer Load Balancer

Spoke-1 (Dev)

Egress Zone

GW-1

GW-2

GW-1

Ingress Zone

GW-2

Load Balancer

Security-Hub

Spoke-3 (Database)

Spoke-N (Server)

Automation & Orchestration

Public Cloud Single Hub Architecture

Single Hub Architecture

Ideal for small environments with little prospect for growth (not very scalable)

Cloud Firewall

AWS Cloud Formation

Azure Resource Manager

Cloud Firewall

WIZ CNAAP Integration CSPM

Workload Protection , Containers & Serverless

Network Security Automation

WAAP

Internet

AWS Cloud Formation

Azure Resource Manager

On Premises Data Center

CloudBots (Auto-Remediation)

Public Cloud

< API >

Values

• Automation of deployment, scaling, and policy enforcement • Enhance Cloud Native tools with Advanced Threat Prevention • Ease of enforcement on traffic through cloud networking • Segmentation of internet facing and private facing traffic

Architecture

• Double Hub Architecture segments and enforces security controls on traffic entering or exiting a spoke. • The Ingress Hub deploys Auto-Scaling gateways that handle fluctuating levels of traffic from the Internet. • The Egress Hub is responsible for East/West traffic between spokes, outgoing traffic to the Internet, and

corporate traffic from the On Premises Data Center. • Flexible deployment options for standalone, clusters, and auto-scaling to meet resiliancy and

performance requirements. This Architecture is the official Check Point recommendation.

Ingress-Hub

Automation & Orchestration

VPN

GW-1

Cloud Firewall Auto-Scale

GW-N

GW-1

Cloud Firewall Auto-Scale

GW-N

Load Balancer

Load Balancer

Load Balancer

Load Balancer

Internet Spoke-1

(Web App) Spoke-2

(Database) Spoke-N (Server)

Double Hub Architecture

Double Hub Architecture

Ideal for customers who need a flexible environment with options for growth

Cloud Firewall

Egress-Hub

Cloud Firewall

WIZ CNAAP Integration CSPM

Workload Protection , Containers & Serverless

Network Security Automation

WAAP

Cloud Firewall

GW-1 GW-2

Cloud Firewall HA

East-West Hub

Automation & Orchestration

On Premises Data Center

InternetCloudBots (Auto-Remediation)

< API >

Values

• Internet connected North/South traffic uses dedicated security zone

• Options to separate East/West hubs and Egress Hubs • Separation for performance, change management, and

maintenance • Zero Trust Model

Architecture

• Triple Hub Architecture offers the most separated architecture and adheres the most to a Zero Trust model. • This architecture segments the different traffic flows with security controls on each hub.

• The Ingress Hub deploys Auto-Scaling gateways that handle fluctuating levels of traffic from the Internet. • The Egress Hub is responsible for outgoing traffic to the Internet. • TheEast-WestHubhandlesEast/WesttrafficbetweenthespokesandcorporatetrafficfromtheOnPremisesDataCenter

• All deployment templates support agile security policies that dynamically learn from cloud subscriptions through tags and metadata

Ingress-Hub

VPN

Cloud Firewall Cluster

GW-1

GW-2

Egress-Hub

Load Balancer Load Balancer

Spoke-1 (Web App)

Spoke-3 (Database)

Spoke-N (Server)

Public Cloud Triple Hub Architecture

Triple Hub Architecture

Ideal for customers who want granular separation between ingress, egress, and East/West traffic

Azure Resource Manager

AWS Cloud Formation

CloudGuard Auto-Scale

GW-1 GW-N

Load Balancer

Cloud Firewall Cloud Firewall

Internet

Cloud Firewall

WIZ CNAAP Integration CSPM

Workload Protection , Containers & Serverless

Network Security Automation

WAAP

Cloud Firewall

Cloud Firewall

AWS Architecture Diagrams

AWS Architecture Diagrams

Check Point Software Technologies Ltd. All Rights Reserved

Three Security VPCs - Security By Design

• Triple Hub Architecture offers the most separated architecture and adheres the most to a Zero Trust model.

• More security-oriented design with ingress & egress traffic controlled per VPC through TGW, plus optimized throughput. (This architecture segments the different traffic flows with security controls on each hub)

• The Ingress Hub deploys Auto-Scaling gateways that handle fluctuating levels of traffic from the Internet.

• The Egress Hub deploys Auto-Scaling gateways that handle fluctuating levels of outgoing traffic to the Internet.

• The East-West Hub handles East/West traffic between the spokes (optional) and corporate traffic from the On Premises Data Center

• Automated deployment through IaC (Infrastructure as Code) • All deployment templates support agile security policies that dynamically learn

from cloud subscriptions through tags and metadata • Vertical scalability by increasing the size of the Cloud Firewall instances (2

core, 4 core, 8 core) • Horizontal scalability by increasing the number of Cloud Firewall instances

within the Scaling Group (changing min and max values)

• Internet connected North/South traffic uses their dedicated security zone

• Provides granular separation between internet facing (ingress & egress) and private facing (East/West) traffic

• Separation for performance, change management, and maintenance

• Separate fault isolation domains

• Zero Trust Model

• Provides a flexible environment with options for growth - Horizontal & Vertical scalability

• Selective traffic steering for east-west inspection

• Ability to add East/West inspection between VPCs, VPN, on-prem (direct connect) or MPLS connections

Cloud Firewall Auto Scaling Group

Cloud Firewall Auto Scaling Group

Cloud Firewall Auto Scaling Group

Values

• Simple per hop routing directs traffic to Security VPC for inspection

• SNAT is not required for GWLB, so original traffic is seen at CG Gateways

Architecture

• GWLB Endpoint is deployed in it’s own subnet in the Consumer VPC • This endpoint will forward all ingress (via Ingress routing edge attachment to IGW) and egress traffic to the GWLB • GWLB automatically forwards traffic to CG Auto-scaling GWsfor enforcement and inspection • Deploy an Application Load Balancer in Consumer VPC for SSL Termination

GWLB connection to endpoints

Ideal for customers without the requirement for E/W traffic inspection

App Subnet AZ BApp Subnet AZ B

Security VPC

Gateway Load Balancer

Gateway Load Balancer

GW-1 GW-2

GW-N

GW-1 GW-2

GW-N

Cloud Firewall

Cloud Firewall

GWLB Subnet

Web ServerWeb Server Web ServerWeb Server

Values

• SNAT not required to view original outbound, E/W, or encrypted inbound traffic

• Simple per hop routing directs traffic to Security VPC for inspection

• Combined with TGW, eliminates need for IPSec/ BGP/ECMP tunnels

Architecture

• The GWLBe in the Spoke VPCs will forward ingress traffic to the GWLB and automatically to CG enforcement via ingress routing edge attachment to IGW

• IGW must be deployed in every spoke for this inbound inspection • For SSL offloading of ingress traffic, deploy an Application Load Balancer subnet per AZ • The GWLBe in the Security VPC forwards egress and E/W traffic to the GWLB and automatically to CG enforcement • A NAT GW is deployed per AZ to handle outbound traffic NAT translation

Gateway Load Balancer with Transit GW

Gateway Load Balancer with Transit GW

GWLB connection to Endpoints

TGW VPC Attachment

Spoke VPC 3

Spoke VPC 2

Spoke VPC 1

GWLBe Subnet

GWLBe

App Subnet

EC2

LB Subnet

EC2

Security VPC

GW-1 GW-2

GW-N

GW-1 GW-2

GW-N

Subnet AZ A

NAT GW

Subnet AZ B

GWLBe Subnet

GWLBe

TGW Attachment Subnet Per AZ

AWS Transit GW

VPC Attachment per Spoke

Cloud Firewall

Cloud Firewall

Check Point Software Technologies Ltd. All Rights Reserved

Azure Architecture Diagrams

Azure Architecture Diagrams

Values

• Incredible scalability and resiliency • Highly automated • Intra-vNET and micro segmentation simplified

through use of UDRs • Inter and Intra vNET Security Deployments

supported • Ability to do host to host micro-segmentation • On demand and elastic remote access

Architecture

• All security controls are deployed in one vNET. • Inbound traffic flows through an External Load Balancer hosting the public IP addresses. • Outbound traffic flows match UDRs which can be sent to single GWs, HA clusters, and/or VMSS • With VMSS, UDRs point to the Microsoft standard load balancer attached to HA ports comprised of a Cloud Firewall VMSS • Such UDRs eliminate the need for route table manipulation during failover, heavily reducing downtime • VMSS with UDRs can be used inter or intra vNETS, ExpressRoutes, VPN, and/or micro-segmentation

Outgoing Traffic

Incoming Traffic

Ingress Cloud Firewall VM Scale Set Egress and East-West Cloud Firewall VM Scale Set

ExpressRoute

DatabaseApplicationsWeb Servers

GW-1 GW-2

GW-3

GW-1 GW-2

GW-3

vNet Peering Spoke 3 vNetSpoke 2 vNetSpoke 1 vNet

Ideal for customers who want very simple routing that works for both small and large environments

Security vNet

Internet

Single Security vNet

Single Security vNet

Cloud Firewall Cloud Firewall

On Premises Data Center

Internet

Values

• Security by design – Zero Trust Model • Systematically separate between incoming and

outgoing traffic flows • Traffic flow isolation for performance and policy

optimization • On demand and elastic remote access

Architecture

• Two vNETs with separate security controls. All the vNETs are connected through peering. • Security by design. Spokes which do not require Internet connection are not peered to the Ingress vNET, preventing the risk for a routing configuration error.

In the Ingress vNET, Inbound traffic flows through an External Load Balancer hosting the public IP addresses. • The Egress vNET handles East/West traffic, outgoing traffic, and the communication to the on premises data center. • ARM Templates for single GW, HA Cluster, and/or VMSS are available to meet performance and availability options

Outgoing Traffic

Incoming Traffic

Cloud Firewall VM Scale Set

Cloud Firewall VM Scale Sets with Internal LB

ExpressRoute vNet Peering

Ingress vNet

Egress vNet

DatabaseApplicationsWeb Servers

Spoke 3 vNetSpoke 2 vNetSpoke 1 vNet

Two Security vNet

Two Security vNet

Ideal for customers desiring better segmentation for traffic flows, with ability to easily send desired traffic flow to a dedicated hub and choose which spokes are exposed to internet.

On Premises Data Center

GW-1 GW-2 GW-3

Cloud Firewall

GW-1 GW-2 GW-3

Cloud Firewall

Architecture designed for customers deploying Azure Virtual WAN. Check Point Cloud Firewall integrates natively to provide security within the hub. Internet

Cloud Firewall Cloud Firewall Cloud Firewall Cloud Firewall

Check Point Cloud Firewall is provided via an Azure Managed Application and located in the middle of the fabric allowing customers to steer relevant traffic to it for security inspection

Check Point Software Technologies Ltd. All Rights Reserved

Google Cloud Architecture Diagrams

Google Cloud Architecture Diagrams

Values

• Grows with demand for ingress automatically • Take full advantage of compute that’s provisioned.

No idle compute, only when needed • Scalable deployment for exposing back-end

applications/services with Multi Instance Group (MIG)

Architecture

• Automatically provisioned MIG instances with built-in Cloud Management Extension • MIGs are deployed in both the external and internal VPC, with interfaces in both • Load balancer on the external subnet of the external VPC receives inbound connections from the internet and

distributes across the MIG instances • Back End Spoke VPCs are peered to the internal VPC • Traffic automatically forwarded from MIGs to back-end internal load balancer serving the spokes.

Inbound MIG

Inbound MIG

net-production net-development

vpc-spoke1 vpc-spoke2

VPC Peering with Route

Import/Export

Security-vpc- external

InterConnect

Security-vpc- internal

On Premises Data Center

Multi Instance Group

External-subnet

Internal-subnet

Inbound Connections

Internet

VPC Peering

Traffic Flow

Ideal for Google customers who need a dynamic and scalable Check Point Cloud Firewall solution to handle unpredictable inbound traffic flows.

Cloud Firewall Cloud Firewall Cloud Firewall

Internet

Values

• Good for something that grows with demand for E/W and egress

• Active/active load sharing takes advantage of all the GCP Compute and Check Point licenses

• Scalable deployment with Multi Instance Group handling E/W and Egress flows

Architecture

• All VPCs must be in the same region for this architecture • Egress and E/W traffic relies on internal TCP/UDP load balancer in the internal Security VPC • All spoke VPCs have a default route pointing to the internal load balancer • Route exchange (import/export) between spoke and security internal VPC • Does not support ingress flows • Note that Outbound Autoscaling solution to be released later this year will replace this

Outbound and E/W Traffic MIG

Outbound and E/W Traffic MIG

net-production

vpc-spoke1

East-West Connections

East-West Connections

vpc-spoke2

VPC Peering with Route

Import/Export

Security-vpc- external

InterConnect

Security-vpc- internal

On Premises Data Center

Multi Instance Group

External-subnet

Internal-subnet

Outbound Connections

Internet

VPC Peering

Traffic Flow

Ideal for Google cloud customers without publicly facing assets who have no need for VPN.

Cloud Firewall Cloud Firewall Cloud Firewall

net-development

Internet

Values

• Good for something that grows with demand for E/W and egress

• Active/active load sharing takes advantage of all the GCP Compute and Check Point licenses

• Scalable deployment with Multi Instance Group handling E/W and Egress flows

Architecture

• All VPCs must be in the same region for this architecture • Egress and E/W traffic relies on internal TCP/UDP load balancer in the internal Security VPC • All spoke VPCs have a default route pointing to the internal load balancer • Route exchange (import/export) between spoke and security internal VPC • Does not support ingress flows • Note that Outbound Autoscaling solution to be released later this year will replace this

Hub Spoke HA

Hub & Spoke HA

net-production

Cloud Firewall Cloud Firewall

Internet

VPN Tunnel

VPC Peering

Traffic Flow

Ideal for Google Cloud customers who want a single deployment at enterprise scale, without any interface limits.

VPC Peering with Route

Import/Export

net-hub

vpc-mgmt

vpc-sec-ext

VPC-Hub

vpc-spoke2 vpc-spoke1

East-West Connections

East-West Connections

Outbound Connections

Inbound Connections

eth2-zoneA

Mgmt-subnet

eth1-zoneA eth1-zoneB

External-subnet

eth0-zoneA eth0-zoneB

eth2-zoneB

On Premises Data Center

net-development

Internet

net-production net-development

vpc-spoke1 vpc-spoke2

Outbound Connections

net-gke

vpc-kubernetes

Values • Security by design – Zero Trust Model • Good for something that grows with demand for N/S, E/W and ingress/egress • Active/active load sharing takes advantage of all the GCP Compute and Check Point licenses • Systematically separate between incoming and outgoing traffic flows • Traffic flow isolation for performance and policy optimization

Architecture

• Supports multiple regions when the Cloud Interconnect terminates on a Security/Shared VPC • Multiple VPCs are deployed for North/South, East/West Ingress and Egress Security Zones. • Vertical scalability by increasing the size of the Check Point Cloud Firewall instances (2 core, 4 core, 8 core) • Horizontal scalability by increasing the number of Check Point Cloud Firewall instances within the Managed Instance Group - “MIG” (changing min and max values) • Supports static or dynamically learned routes to be exported to peer VPC networks benefitting from centralized configuration and allowing for scalable VPC network growth. • Following this best practice enables handling fluctuating traffic load efficiently and independently.

Two Security VPCs

Two Security VPCs Internet

Internet

On Premises Data Center

vpc-ingress-ext

vpc-ingress-int

vpc-egress-int

vpc-egress-ext

Cloud Firewall Cloud Firewall Cloud Firewall

Managed Instance Group

ingress-ext-subnet

ingress-int-subnet

egress-int-subnet

VPC Peering import export export import

eth2-zoneA

egress-int-subnet

eth2-zoneA eth2-zoneB

egress-int-subnet

eth2-zoneA eth2-zoneBeth2-zoneB

Cloud Firewall

East-West Connections East-West Connections

Cloud Firewall

InterConnect

vpc-mgmt

Internet

Internet

24©2026 Check Point Software Technologies Ltd. [Internal Use] for Check Point employees

Thank You!

W E S E C U R E Y O U R A I T R A N S F O R M A T I O N


Item Type: pdf