Solution Brief | Deploy Check Point’s AI-powered WAF-as-a-Service in Minutes

Solution Brief | Deploy Check Point’s AI-powered WAF-as-a-Service in Minutes

Download the solution brief to learn how to deploy Check Point’s AI-powered WAF-as-a-Service in minutes on AWS. Follow these steps on how to set up CloudGuard WAF-as-a-Service, including a solution walkthrough and how to connect your web domain to CloudGuard WAF-as-a-Service.

Solution Brief | Deploy Check Point’s AI-powered WAF-as-a-Service in Minutes

© 2025 Check Point Software Technologies Ltd. All rights reserved.

CloudGuard WAF-as-a-Service Powerful features of CloudGuard WAF have been available for years in AWS Marketplace, and now CloudGuard WAF is offered as a service. This new model significantly reduces the time to deployment and supports monthly payments. With four straightforward steps that only take minutes, any organization can protect their web applications and APIs with the power of CloudGuard WAF-as-a- Service, resulting in close to zero impact on the AWS customer’s environment and removing the need to install and maintain an infrastructure-as-a-service solution.

How to set up CloudGuard WAF-as-a-Service Below are five easy steps: 1. Login to your Infinity Portal account. 2. Create a web asset and prove ownership of the domain. 3. Connect your web domain to CloudGuard WAF-as-a-Service. 4. Allow access from CloudGuard WAF-as-a-Service IP addresses. 5. Test access to your site.

Prerequisites To perform the setup, you need to complete the following prerequisites. • Have or create an Infinity Portal account. • Purchase and activate CloudGuard WAF-as-a-Service from the AWS Marketplace. • Verify ownership of the DNS configuration for the protected domain.

• Have or create an internal web address for the asset.

Solution walkthrough: Add AI-powered WAF-as-a-Service security on AWS in minutes

To secure your traffic for each domain in each asset protected by CloudGuard WAFas-a-Service, you need to perform the following four steps.

Deploy Check Point’s AI-powered WAF-as-a-Service in minutes

https://aws.amazon.com/marketplace/pp/prodview-tu225yyfqpryk?sr=0-2&ref_=beagle&applicationId=AWSMPContessa https://aws.amazon.com/marketplace/pp/prodview-tu225yyfqpryk

© 2025 Check Point Software Technologies Ltd. All rights reserved.

2

Login to your Infinity Portal account and navigate to CloudGuard WAF.

If you do not have an Infinity Portal account follow the steps located at the Getting Started with the Infitnity Portal guide to create one.

Figure 1 – WAF on Check Point Console

Create web asset and prove ownership of domain

1. Create a new web asset by navigating to New Asset > Web Application

Figure 2 – Create a new Web Asset

2. In the Policy tab, choose Profiles and select the WAF-as-a-Service profile that was automatically created during the New Web Application wizard in Step 1.

Figure 3 – Select WebApp SaaS Profile

https://portal.checkpoint.com/ https://sc1.checkpoint.com/documents/Infinity_Portal/WebAdminGuides/EN/Infinity-Portal-Admin-Guide/Content/Topics-Infinity-Portal/Getting-Started-Infinity-Portal.htm https://sc1.checkpoint.com/documents/Infinity_Portal/WebAdminGuides/EN/Infinity-Portal-Admin-Guide/Content/Topics-Infinity-Portal/Getting-Started-Infinity-Portal.htm

© 2025 Check Point Software Technologies Ltd. All rights reserved.

3

3. For each web domain pending validation, choose the web domain and follow the instructions to prove ownership by adding a CNAME record with the provided name and value in your DNS configuration, as shown in Figure 4.

Figure 4 – Proving web domain ownership

You need to perform this action for each web domain. For example, if you are protecting both www.<insert your domain>.net and api.<insert your domain>.net you need to prove ownership for each web domain separately, as shown in Figure 5.

Figure 5 – Example domain configuration for www..net

4

Connect your web domain to CloudGuard WAF-as-a-Service

Important: Before performing this step, disable any existing Amazon CloudFront configuration for your website’s address.

1. Once domain ownership is verified (which can take up to 30 minutes), a CNAME record will be issued.

2. Change the existing DNS CNAME record for the domain you want to protect, updating its value to the provided string.

After DNS propagation worldwide, traffic will pass through CloudGuard WAF-as-a-Service and then be routed to your internal web server.

Figure 6 -Successful domain validation and updating existing DNS to new CNAME

Allow Access from CloudGuard WAF-as-a-Service IP addresses

In this step, you add IP addresses to the access list allowed by your internal web server and you may need to remove IP addresses that are no longer needed. Because DNS propagation can take up to 72 hours, we recommend only adding IP addresses as needed but not removing any access from the web server until 72 hours have passed and you have tested your connectivity through WAF-as-a-Service.

1. For each asset protected by CloudGuard WAF-as-a-Service, configure the upstream URL for the reverse proxy function to allow access from the IP addresses provided in the CloudGuard WAF UI deployment form. Allow access only from those addresses. 2. If the domain was previously exposed publicly, reduce accessibility and allow traffic only from those IP addresses.

3. If the domain was previously accessible only from a configured reverse proxy, add the WAF-as-a-Service IP addresses to the access list and consider removing irrelevant IP addresses from the previous reverse proxy.

© 2024 Check Point Software Technologies Ltd. All rights reserved.© 2024 Check Point Software Technologies Ltd. All rights reserved.

5

© 2024 Check Point Software Technologies Ltd. All rights reserved.© 2024 Check Point Software Technologies Ltd. All rights reserved.

Worldwide Headquarters 5 Shlomo Kaplan Street, Tel Aviv 6789159, Israel | Tel: +972-3-753-4599

U.S. Headquarters 100 Oracle Parkway, Suite 800, Redwood City, CA 94065 | Tel: 1-800-429-4391

www.checkpoint.com

© 2025 Check Point Software Technologies Ltd. All rights reserved.

Figure 7 – IPs allow listed and domain ready to test access

Test access to your site

After completing the previous steps, test access to your site. Changing DNS records typically takes a few hours to propagate worldwide, but it can take up to 72 hours. Make sure you verify that you have not left a publicly exposed domain in your previous environment.

Ready to get started?

Contact Check Point, request a demo, or find Check Point CloudGuard WAF-as-a-Service in AWS Marketplace today!

https://partners.amazonaws.com/contactpartner?partnerId=001E000000UfZXoIAN&partnerName=Check%20Point%20Software%20Technologies https://aws.amazon.com/marketplace/customer-connect/demo/prodview-tu225yyfqpryk?ref_=saas&feature=header https://aws.amazon.com/marketplace/pp/prodview-tu225yyfqpryk?sr=0-1&ref_=beagle&applicationId=AWSMPContessa https://aws.amazon.com/marketplace/pp/prodview-tu225yyfqpryk?sr=0-1&ref_=beagle&applicationId=AWSMPContessa


Item Type: pdf