Solution Brief | Check Point Architecture Blueprint Diagrams
This solution brief outlines Check Point's flexible and scalable cloud security architecture, featuring advanced threat prevention, automated deployment, and continuous compliance. With single, double, and triple hub options, it ensures secure, scalable, and efficient deployment. Learn about dynamic policies, cloud-native tools, and network segmentation. Download to explore optimal security for your cloud environment.

1©2026 Check Point Software Technologies Ltd.
W E S E C U R E Y O U R A I T R A N S F O R M A T I O N
Check Point Cloud Firewall Architecture Blueprint Diagrams
Network Security
• Advanced Threat Prevention & Traffic Inspection • Common Policy and Logging Infrastructure • Unified management of physical and virtual infrastructure • Automated deployment through IaC • Dynamic policies map to cloud through tags and metadata • Support also for Oracle, Alibaba Cloud, IBM, and more
Additional Cloud Security Capabilities
• Continuous Compliance with Industry Frameworks and Best Practices
• Identify misconfigurations in IaaS and PaaS • Automatic Remediation integrated natively • WIZ Integration for Workload Protection for Kubernetes clusters and
Serverless functions • “Shift left” security posture into CI/CD pipeline • Consumes & correlates cloud native network and audit logs
Overall Architecture:
• ThreatCloud AI delivers real-time dynamic security intelligence from a collaborative cloud driven knowledge base
• Holistic security view • High Fidelity context for Threat Hunting & Intelligence • Extensive APIs integrated with Cloud Firewall, over 22 Vendors
supported
SIEM/Ticketing Solution
Traffic & Event Logs
WIZ CNAAP Integration CSPM
Workload Protection , Containers & Serverless
Branch Office SD-WAN
Automation & Orchestration
Remote Users
VPN IoT
Internet CloudBots (Auto-Remediation)
Public Cloud Private Cloud
AWS Cloud Formation
Azure Resource Manager
On Premises Data Center
Network Security Automation
Cloud Firewall
WAAP
Check Point Smart-1 Console
Email and Collaboration Security Endpoint Security Mobile Security Browser Security Extended Detection and Response (XDR)
Network Edge
Cloud Firewall
Internet
On Premises Data Center
CloudBots (Auto-Remediation)
< API >
Values
• “Network perimeter” security with Advanced Threat Prevention • Simple architecture deployment • Agility, Automation, Efficiency, Elasticity • Unified management for hybrid environment
Architecture
• The Single Hub (VPC or vNET) acts as a central point for the security of the entire cloud environment. • Ingress & Egress Zones for North/South Traffic Inspection • Ability to add East/West inspection between VPCs, VPN, or MPLS connections • Flexible deployment templates for single gateway, HA clusters, or Auto-Scaling group • With Auto-Scaling groups, automatic scale out and scale in based on load and performance • Spokes represent a virtual network where different assets are deployed.
VPN
Spoke-2 (Web App)
Load Balancer Load Balancer
Spoke-1 (Dev)
Egress Zone
GW-1
GW-2
GW-1
Ingress Zone
GW-2
Load Balancer
Security-Hub
Spoke-3 (Database)
Spoke-N (Server)
Automation & Orchestration
Public Cloud Single Hub Architecture
Single Hub Architecture
Ideal for small environments with little prospect for growth (not very scalable)
Cloud Firewall
AWS Cloud Formation
Azure Resource Manager
Cloud Firewall
WIZ CNAAP Integration CSPM
Workload Protection , Containers & Serverless
Network Security Automation
WAAP
Internet
AWS Cloud Formation
Azure Resource Manager
On Premises Data Center
CloudBots (Auto-Remediation)
Public Cloud
< API >
Values
• Automation of deployment, scaling, and policy enforcement • Enhance Cloud Native tools with Advanced Threat Prevention • Ease of enforcement on traffic through cloud networking • Segmentation of internet facing and private facing traffic
Architecture
• Double Hub Architecture segments and enforces security controls on traffic entering or exiting a spoke. • The Ingress Hub deploys Auto-Scaling gateways that handle fluctuating levels of traffic from the Internet. • The Egress Hub is responsible for East/West traffic between spokes, outgoing traffic to the Internet, and
corporate traffic from the On Premises Data Center. • Flexible deployment options for standalone, clusters, and auto-scaling to meet resiliancy and
performance requirements. This Architecture is the official Check Point recommendation.
Ingress-Hub
Automation & Orchestration
VPN
GW-1
Cloud Firewall Auto-Scale
GW-N
GW-1
Cloud Firewall Auto-Scale
GW-N
Load Balancer
Load Balancer
Load Balancer
Load Balancer
Internet Spoke-1
(Web App) Spoke-2
(Database) Spoke-N (Server)
Double Hub Architecture
Double Hub Architecture
Ideal for customers who need a flexible environment with options for growth
Cloud Firewall
Egress-Hub
Cloud Firewall
WIZ CNAAP Integration CSPM
Workload Protection , Containers & Serverless
Network Security Automation
WAAP
Cloud Firewall
GW-1 GW-2
Cloud Firewall HA
East-West Hub
Automation & Orchestration
On Premises Data Center
InternetCloudBots (Auto-Remediation)
< API >
Values
• Internet connected North/South traffic uses dedicated security zone
• Options to separate East/West hubs and Egress Hubs • Separation for performance, change management, and
maintenance • Zero Trust Model
Architecture
• Triple Hub Architecture offers the most separated architecture and adheres the most to a Zero Trust model. • This architecture segments the different traffic flows with security controls on each hub.
• The Ingress Hub deploys Auto-Scaling gateways that handle fluctuating levels of traffic from the Internet. • The Egress Hub is responsible for outgoing traffic to the Internet. • TheEast-WestHubhandlesEast/WesttrafficbetweenthespokesandcorporatetrafficfromtheOnPremisesDataCenter
• All deployment templates support agile security policies that dynamically learn from cloud subscriptions through tags and metadata
Ingress-Hub
VPN
Cloud Firewall Cluster
GW-1
GW-2
Egress-Hub
Load Balancer Load Balancer
Spoke-1 (Web App)
Spoke-3 (Database)
Spoke-N (Server)
Public Cloud Triple Hub Architecture
Triple Hub Architecture
Ideal for customers who want granular separation between ingress, egress, and East/West traffic
Azure Resource Manager
AWS Cloud Formation
CloudGuard Auto-Scale
GW-1 GW-N
Load Balancer
Cloud Firewall Cloud Firewall
Internet
Cloud Firewall
WIZ CNAAP Integration CSPM
Workload Protection , Containers & Serverless
Network Security Automation
WAAP
Cloud Firewall
Cloud Firewall
AWS Architecture Diagrams
AWS Architecture Diagrams
Check Point Software Technologies Ltd. All Rights Reserved
Three Security VPCs - Security By Design
• Triple Hub Architecture offers the most separated architecture and adheres the most to a Zero Trust model.
• More security-oriented design with ingress & egress traffic controlled per VPC through TGW, plus optimized throughput. (This architecture segments the different traffic flows with security controls on each hub)
• The Ingress Hub deploys Auto-Scaling gateways that handle fluctuating levels of traffic from the Internet.
• The Egress Hub deploys Auto-Scaling gateways that handle fluctuating levels of outgoing traffic to the Internet.
• The East-West Hub handles East/West traffic between the spokes (optional) and corporate traffic from the On Premises Data Center
• Automated deployment through IaC (Infrastructure as Code) • All deployment templates support agile security policies that dynamically learn
from cloud subscriptions through tags and metadata • Vertical scalability by increasing the size of the Cloud Firewall instances (2
core, 4 core, 8 core) • Horizontal scalability by increasing the number of Cloud Firewall instances
within the Scaling Group (changing min and max values)
• Internet connected North/South traffic uses their dedicated security zone
• Provides granular separation between internet facing (ingress & egress) and private facing (East/West) traffic
• Separation for performance, change management, and maintenance
• Separate fault isolation domains
• Zero Trust Model
• Provides a flexible environment with options for growth - Horizontal & Vertical scalability
• Selective traffic steering for east-west inspection
• Ability to add East/West inspection between VPCs, VPN, on-prem (direct connect) or MPLS connections
Cloud Firewall Auto Scaling Group
Cloud Firewall Auto Scaling Group
Cloud Firewall Auto Scaling Group
Values
• Simple per hop routing directs traffic to Security VPC for inspection
• SNAT is not required for GWLB, so original traffic is seen at CG Gateways
Architecture
• GWLB Endpoint is deployed in it’s own subnet in the Consumer VPC • This endpoint will forward all ingress (via Ingress routing edge attachment to IGW) and egress traffic to the GWLB • GWLB automatically forwards traffic to CG Auto-scaling GWsfor enforcement and inspection • Deploy an Application Load Balancer in Consumer VPC for SSL Termination
GWLB connection to endpoints
Ideal for customers without the requirement for E/W traffic inspection
App Subnet AZ BApp Subnet AZ B
Security VPC
Gateway Load Balancer
Gateway Load Balancer
GW-1 GW-2
GW-N
GW-1 GW-2
GW-N
Cloud Firewall
Cloud Firewall
GWLB Subnet
Web ServerWeb Server Web ServerWeb Server
Values
• SNAT not required to view original outbound, E/W, or encrypted inbound traffic
• Simple per hop routing directs traffic to Security VPC for inspection
• Combined with TGW, eliminates need for IPSec/ BGP/ECMP tunnels
Architecture
• The GWLBe in the Spoke VPCs will forward ingress traffic to the GWLB and automatically to CG enforcement via ingress routing edge attachment to IGW
• IGW must be deployed in every spoke for this inbound inspection • For SSL offloading of ingress traffic, deploy an Application Load Balancer subnet per AZ • The GWLBe in the Security VPC forwards egress and E/W traffic to the GWLB and automatically to CG enforcement • A NAT GW is deployed per AZ to handle outbound traffic NAT translation
Gateway Load Balancer with Transit GW
Gateway Load Balancer with Transit GW
GWLB connection to Endpoints
TGW VPC Attachment
Spoke VPC 3
Spoke VPC 2
Spoke VPC 1
GWLBe Subnet
GWLBe
App Subnet
EC2
LB Subnet
EC2
Security VPC
GW-1 GW-2
GW-N
GW-1 GW-2
GW-N
Subnet AZ A
NAT GW
Subnet AZ B
GWLBe Subnet
GWLBe
TGW Attachment Subnet Per AZ
AWS Transit GW
VPC Attachment per Spoke
Cloud Firewall
Cloud Firewall
Check Point Software Technologies Ltd. All Rights Reserved
Azure Architecture Diagrams
Azure Architecture Diagrams
Values
• Incredible scalability and resiliency • Highly automated • Intra-vNET and micro segmentation simplified
through use of UDRs • Inter and Intra vNET Security Deployments
supported • Ability to do host to host micro-segmentation • On demand and elastic remote access
Architecture
• All security controls are deployed in one vNET. • Inbound traffic flows through an External Load Balancer hosting the public IP addresses. • Outbound traffic flows match UDRs which can be sent to single GWs, HA clusters, and/or VMSS • With VMSS, UDRs point to the Microsoft standard load balancer attached to HA ports comprised of a Cloud Firewall VMSS • Such UDRs eliminate the need for route table manipulation during failover, heavily reducing downtime • VMSS with UDRs can be used inter or intra vNETS, ExpressRoutes, VPN, and/or micro-segmentation
Outgoing Traffic
Incoming Traffic
Ingress Cloud Firewall VM Scale Set Egress and East-West Cloud Firewall VM Scale Set
ExpressRoute
DatabaseApplicationsWeb Servers
GW-1 GW-2
GW-3
GW-1 GW-2
GW-3
vNet Peering Spoke 3 vNetSpoke 2 vNetSpoke 1 vNet
Ideal for customers who want very simple routing that works for both small and large environments
Security vNet
Internet
Single Security vNet
Single Security vNet
Cloud Firewall Cloud Firewall
On Premises Data Center
Internet
Values
• Security by design – Zero Trust Model • Systematically separate between incoming and
outgoing traffic flows • Traffic flow isolation for performance and policy
optimization • On demand and elastic remote access
Architecture
• Two vNETs with separate security controls. All the vNETs are connected through peering. • Security by design. Spokes which do not require Internet connection are not peered to the Ingress vNET, preventing the risk for a routing configuration error.
In the Ingress vNET, Inbound traffic flows through an External Load Balancer hosting the public IP addresses. • The Egress vNET handles East/West traffic, outgoing traffic, and the communication to the on premises data center. • ARM Templates for single GW, HA Cluster, and/or VMSS are available to meet performance and availability options
Outgoing Traffic
Incoming Traffic
Cloud Firewall VM Scale Set
Cloud Firewall VM Scale Sets with Internal LB
ExpressRoute vNet Peering
Ingress vNet
Egress vNet
DatabaseApplicationsWeb Servers
Spoke 3 vNetSpoke 2 vNetSpoke 1 vNet
Two Security vNet
Two Security vNet
Ideal for customers desiring better segmentation for traffic flows, with ability to easily send desired traffic flow to a dedicated hub and choose which spokes are exposed to internet.
On Premises Data Center
GW-1 GW-2 GW-3
Cloud Firewall
GW-1 GW-2 GW-3
Cloud Firewall
Architecture designed for customers deploying Azure Virtual WAN. Check Point Cloud Firewall integrates natively to provide security within the hub. Internet
Cloud Firewall Cloud Firewall Cloud Firewall Cloud Firewall
Check Point Cloud Firewall is provided via an Azure Managed Application and located in the middle of the fabric allowing customers to steer relevant traffic to it for security inspection
Check Point Software Technologies Ltd. All Rights Reserved
Google Cloud Architecture Diagrams
Google Cloud Architecture Diagrams
Values
• Grows with demand for ingress automatically • Take full advantage of compute that’s provisioned.
No idle compute, only when needed • Scalable deployment for exposing back-end
applications/services with Multi Instance Group (MIG)
Architecture
• Automatically provisioned MIG instances with built-in Cloud Management Extension • MIGs are deployed in both the external and internal VPC, with interfaces in both • Load balancer on the external subnet of the external VPC receives inbound connections from the internet and
distributes across the MIG instances • Back End Spoke VPCs are peered to the internal VPC • Traffic automatically forwarded from MIGs to back-end internal load balancer serving the spokes.
Inbound MIG
Inbound MIG
net-production net-development
vpc-spoke1 vpc-spoke2
VPC Peering with Route
Import/Export
Security-vpc- external
InterConnect
Security-vpc- internal
On Premises Data Center
Multi Instance Group
External-subnet
Internal-subnet
Inbound Connections
Internet
VPC Peering
Traffic Flow
Ideal for Google customers who need a dynamic and scalable Check Point Cloud Firewall solution to handle unpredictable inbound traffic flows.
Cloud Firewall Cloud Firewall Cloud Firewall
Internet
Values
• Good for something that grows with demand for E/W and egress
• Active/active load sharing takes advantage of all the GCP Compute and Check Point licenses
• Scalable deployment with Multi Instance Group handling E/W and Egress flows
Architecture
• All VPCs must be in the same region for this architecture • Egress and E/W traffic relies on internal TCP/UDP load balancer in the internal Security VPC • All spoke VPCs have a default route pointing to the internal load balancer • Route exchange (import/export) between spoke and security internal VPC • Does not support ingress flows • Note that Outbound Autoscaling solution to be released later this year will replace this
Outbound and E/W Traffic MIG
Outbound and E/W Traffic MIG
net-production
vpc-spoke1
East-West Connections
East-West Connections
vpc-spoke2
VPC Peering with Route
Import/Export
Security-vpc- external
InterConnect
Security-vpc- internal
On Premises Data Center
Multi Instance Group
External-subnet
Internal-subnet
Outbound Connections
Internet
VPC Peering
Traffic Flow
Ideal for Google cloud customers without publicly facing assets who have no need for VPN.
Cloud Firewall Cloud Firewall Cloud Firewall
net-development
Internet
Values
• Good for something that grows with demand for E/W and egress
• Active/active load sharing takes advantage of all the GCP Compute and Check Point licenses
• Scalable deployment with Multi Instance Group handling E/W and Egress flows
Architecture
• All VPCs must be in the same region for this architecture • Egress and E/W traffic relies on internal TCP/UDP load balancer in the internal Security VPC • All spoke VPCs have a default route pointing to the internal load balancer • Route exchange (import/export) between spoke and security internal VPC • Does not support ingress flows • Note that Outbound Autoscaling solution to be released later this year will replace this
Hub Spoke HA
Hub & Spoke HA
net-production
Cloud Firewall Cloud Firewall
Internet
VPN Tunnel
VPC Peering
Traffic Flow
Ideal for Google Cloud customers who want a single deployment at enterprise scale, without any interface limits.
VPC Peering with Route
Import/Export
net-hub
vpc-mgmt
vpc-sec-ext
VPC-Hub
vpc-spoke2 vpc-spoke1
East-West Connections
East-West Connections
Outbound Connections
Inbound Connections
eth2-zoneA
Mgmt-subnet
eth1-zoneA eth1-zoneB
External-subnet
eth0-zoneA eth0-zoneB
eth2-zoneB
On Premises Data Center
net-development
Internet
net-production net-development
vpc-spoke1 vpc-spoke2
Outbound Connections
net-gke
vpc-kubernetes
Values • Security by design – Zero Trust Model • Good for something that grows with demand for N/S, E/W and ingress/egress • Active/active load sharing takes advantage of all the GCP Compute and Check Point licenses • Systematically separate between incoming and outgoing traffic flows • Traffic flow isolation for performance and policy optimization
Architecture
• Supports multiple regions when the Cloud Interconnect terminates on a Security/Shared VPC • Multiple VPCs are deployed for North/South, East/West Ingress and Egress Security Zones. • Vertical scalability by increasing the size of the Check Point Cloud Firewall instances (2 core, 4 core, 8 core) • Horizontal scalability by increasing the number of Check Point Cloud Firewall instances within the Managed Instance Group - “MIG” (changing min and max values) • Supports static or dynamically learned routes to be exported to peer VPC networks benefitting from centralized configuration and allowing for scalable VPC network growth. • Following this best practice enables handling fluctuating traffic load efficiently and independently.
Two Security VPCs
Two Security VPCs Internet
Internet
On Premises Data Center
vpc-ingress-ext
vpc-ingress-int
vpc-egress-int
vpc-egress-ext
Cloud Firewall Cloud Firewall Cloud Firewall
Managed Instance Group
ingress-ext-subnet
ingress-int-subnet
egress-int-subnet
VPC Peering import export export import
eth2-zoneA
egress-int-subnet
eth2-zoneA eth2-zoneB
egress-int-subnet
eth2-zoneA eth2-zoneBeth2-zoneB
Cloud Firewall
East-West Connections East-West Connections
Cloud Firewall
InterConnect
vpc-mgmt
Internet
Internet
24©2026 Check Point Software Technologies Ltd. [Internal Use] for Check Point employees
Thank You!
W E S E C U R E Y O U R A I T R A N S F O R M A T I O N