Solution Brief | Securing AWS Access with Check Point SASE

Solution Brief | Securing AWS Access with Check Point SASE

Learn how Check Point SASE secures access to AWS resources with Zero Trust Network Access (ZTNA), encrypted connectivity, Firewall as a Service (FWaaS), and granular application controls. Strengthen cloud security, improve visibility, and simplify access management. Read the solution brief.

Solution Brief | Securing AWS Access with Check Point SASE

Securing AWS Access with Check Point Harmony SASE Provide Secure Access for All Users, Anywhere to Your Public Cloud Resources

© 2024 Check Point Software Technologies Ltd. All rights reserved.

Check Point Harmony Secure Access Service Edge (SASE) enables secure access to company resources in the public cloud whether employees are working from the office or remotely. Administrators, meanwhile, can easily audit team activity and enjoy full network visibility with our single-pane-of-glass management console.

Configuring AWS Access

Remote users

Internal web apps hosted on AWS

Internal web apps hosted on other clouds

SaaS apps & private clouds

Internal apps hosted on-premises

Contractors Branch office

https://www.checkpoint.com/harmony/sase/

SECURING AWS ACCESS

© 2024 Check Point Software Technologies Ltd. All rights reserved.

Step 3: Add Tunnel Configuration to Harmony SASE Next, we take the configuration data from the file we downloaded in the last step and add it to your Harmony SASE gateway. This will include the IP address for your AWS gateway, the tunnel’s shared secret, as well as defining some of the encryption options.

Harmony SASE also supports redundant tunnels for high availability in active-active mode at no extra charge.

Step 1: Define a Gateway in AWS IT admins first need to create a virtual private gateway or transit gateway in their AWS environment. Both tools enable a connection to your Harmony SASE network. Which one you need will depend on your AWS set-up. In brief, a private gateway connects a single AWS virtual private cloud (VPC) to your Harmony SASE network. For more complex AWS environments with multiple VPCs, a transit gateway acts as a hub between your Harmony SASE network and AWS resources.

Step 2: Configure the Tunnel in AWS Next, you’ll need to configure secure connection tunnels between your Harmony SASE network and AWS cloud resources. Tunnel configuration requires multiple steps such as providing AWS with your Harmony SASE subnet IP prefix and defining the static routing table.

Once it’s done, you will be able to download a configuration file for the next step

Step 4: Set ZTNA Rules You should also set access rules within the Harmony SASE management console to enable Zero Trust access to your AWS resources. This way only the individuals and/or groups who actually need access to these resources will have it, while all other employees won’t.

We also support the advanced WireGuard protocol to connect to AWS based on our easy-to-use proprietary connector.

For more information about connecting to AWS resources, see our help center for detailed step-by-step guides.

“Any remote access is going to come over [the network]. Our attack footprint doesn’t exist anymore.” - Brett A. Sudeck, NP Inc.

Connecting an Amazon Web Services (AWS) cloud environment to your Harmony SASE network is easy.

https://support.perimeter81.com/docs/configuring-a-site-to-site-ipsec-tunnel-to-aws-virtual-gateway?utm_content=DTS&utm_medium=PDF&utm_campaign=aws_integration_guide

SECURING AWS ACCESS

© 2024 Check Point Software Technologies Ltd. All rights reserved.

Access Your AWS Resources Securely With a secure, encrypted tunnel between your Harmony SASE gateway and AWS resources employees can connect securely. We also increase your organization’s security by hiding the public IP address of your AWS resources. Your Harmony SASE network assigns your AWS VPC an internal IP address, thereby obscuring its public IP from the outside world. Internal IP addresses cannot be used outside the network rendering your AWS resources invisible and inaccessible, which greatly reduces the attack surface.

Should you prefer direct connectivity we also provide users with a static IP address to enable allowlisting. This isn’t as secure as implementing a secure tunnel using supported VPN protocols. But allowlisting means that only employees coming through your Harmony SASE private IP address will be able to access your AWS resources. To use IP allowlisting, all you have to do is add a firewall rule on the AWS side that only allows access via your Harmony SASE gateway’s IP address.

Harmony SASE also implements granular access on a per-user application basis, which ensures users only have access to the specific applications they need, and not the entire virtual private cloud (VPC).

Harmony SASE Key Advantages

Faster Connections

We remove the need to route traffic to an on-prem VPN allowing direct access to cloud resources. This means reduced latency, more responsive applications, and increased productivity for your employees.

Cover It All With FWaaS

No need to pay extra for a virtual firewall. Reduce costs and complexity with a Firewall as a Service that works across all cloud instances.

Better Network Visibility

With all traffic to your cloud resources routing through Harmony SASE, you will have better visibility into network activity, and detailed logs for SIEM ingestion and investigating security events.

High Availability Tunnels, No Additional Cost

We do not limit the number of tunnels you can create, nor do we charge extra for additional tunnels–so define as many as necessary.

Effortless Deployment

In minutes, you can deploy a company network, and set up secure connections to cloud and on-premises resources.

Easy Zero Trust Network Access (ZTNA)

IT professionals can easily enforce Zero Trust Network Access policies for individuals or groups quickly and easily. Enforce granular permissions that restrict access to sensitive on-prem and cloud applications.

Broad IdP Support

Harmony SASE supports custom identity management lists and integrates with many trusted and well-known IdP services such as G Suite, JumpCloud, Microsoft Azure AD, and Okta.

Secure Connections for Remote Workers

Administrators can enhance network security with IPSec or WireGuard tunnels between the Harmony SASE gateway and company resources.

https://www.checkpoint.com/harmony/sase/private-access/

SECURING AWS ACCESS

Driving Continuous Security and Compliance in AWS Check Point is an AWS Advanced Technology partner. We have a team of Amazon-accredited individuals with AWS-specific technical expertise to support and integrate AWS customer resources with Harmony SASE. We also have a proven customer service record that exceeds Amazon’s highest standards.

About Harmony SASE Check Point’s Harmony SASE is a robust, yet easy-to-use, converged networking and network security platform that connects all users, in the office or remote, to all resources, located on-prem or in the cloud. It is a cloud-delivered service that includes advanced capabilities such as zero trust remote access, Internet access control, malware protection, firewall as a service, and SD-WAN. It enables any business to build a secure corporate network over a private global backbone in less than an hour. The service is managed from a unified console and is backed by an award-winning global support team that has you covered 24/7.

Request a Demo

Worldwide Headquarters 5 Ha’Solelim Street, Tel Aviv 67897, Israel | Tel: 972-3-753-4555 | Fax: 972-3-624-1100 | Email: info@checkpoint.com

U.S. Headquarters 959 Skyway Road, Suite 300, San Carlos, CA 94070 | Tel: 800-429-4391; 650-628-2000 | Fax: 650-654-4233

www.checkpoint.com

© 2024 Check Point Software Technologies Ltd. All rights reserved.

https://www.perimeter81.com/demo-cp?utm_source=cp&utm_content=DTS&utm_medium=PDF&utm_campaign=aws_integration_guide mailto:info@checkpoint.com http://www.checkpoint.com


Item Type: pdf