White Paper | Securing Multi-Cloud Networks with Check Point Cloud Firewall as a Service

White Paper | Securing Multi-Cloud Networks with Check Point Cloud Firewall as a Service

Unified multi-cloud security with AI-driven threat prevention. Learn how Check Point Cloud Firewall as a Service delivers scalable protection across AWS, Azure, and Google Cloud.

White Paper | Securing Multi-Cloud Networks with Check Point Cloud Firewall as a Service

© 2025 Check Point Software Technologies Ltd. All rights reserv

Introduction

As organizations embrace multi-cloud and hybrid infrastructures, securing the network has become exponentially more complex. The cloud’s promise of agility and scalability also introduces a dynamic, fragmented perimeter made up of disparate platforms, identities, and services. In this environment, traditional security models fall short. This paper explores how Check Point Cloud Firewall as a Service delivers unified protection across public cloud environments, available on AWS, Azure and Google Cloud Marketplaces.

Through a cloud-adapted hybrid mesh firewall architecture, Check Point Cloud Firewall as a Service enforces consistent access control, prevents advanced threats with AI-driven intelligence, and scales security alongside dynamic workloads.

Whether you're modernizing your applications, expanding into new clouds, or consolidating network security, Check Point Cloud Firewall as a Service provides the visibility, control, and intelligence needed to prevent breaches before they happen.

Drawing from real-world use cases across AWS, Azure, Google Cloud, and other cloud networking environments, this paper outlines best practices for securing East-West and North-South traffic, protecting cloud-native services, and simplifying operations through centralized management and automation.

Securing Multi-Cloud Networks with Check Point Cloud Firewall as a Service Best Practices and Use Cases for Unified Security Across Clouds

https://www.checkpoint.com/resources/items/datasheet-check-point-cloud-firewall-as-a-service

UNIQUE CHALLENGES OF CLOUD NETWORKS 1

© 2025 Check Point Software Technologies Ltd. All rights reserv

Front Door Service Door (Enterprise Access Gateway)

Application layer Data Center & Branches

HTTP / API VPN

TCP, UDP... Cloud WAN

Network transport layers

Cloud Internals Traffic

Unique Challenges of Cloud Networks Cloud environments bring agility and scale but also introduce complexity and an expanded attack surface. The risks don’t stop at the public cloud. They span across private clouds, hybrid infrastructures, remote users, and on-premises data centers. This makes cloud network security the foundation of any modern, multi-layered defense strategy.

The Cloud Prevention Mesh: Securing All Entry Points • The Front Door (Internet Edge) is the entry point for public-facing applications and SaaS

platforms.

• The Service Door (Enterprise Access Gateway) is the entry point used by corporate users as well as privileged connections to on-premises environments and other clouds.

• The Cloud Internals (East-West Traffic): Cloud hosted workloads and data with their internal lateral traffic.

Why Organizations Choose Check Point Cloud Firewall as a Service Check Point Cloud Firewall as a Service is key to implementing scalable cloud security that is both adaptive and unified. Cloud Firewall as a Service addresses three critical needs across multi-cloud deployments: access control, threat prevention, and cloud-native scalability – which will be explored in this section. Scaling prevention is critical to secure the growing number of VPCs and VNets that support our AI-driven world.

UNIQUE CHALLENGES OF CLOUD NETWORKS 2

© 2025 Check Point Software Technologies Ltd. All rights reserv

Key benefits: • Reduced Attack Surface: Easily segmenting environments and inspecting east-west traffic

limits exposure and minimizes breach impact even when securing hundreds of VPCs or VNets.

• Advanced Threat Prevention: I-driven analytics, behavior-based detection, and deep packet inspection help stop malware, ransomware, and DDoS attacks before they cause harm.

• Seamless Scalability: Check Point Cloud Firewall as a Service scales security dynamically as workloads grow, supporting DevOps speed, remote teams, and new cloud deployments without disruption.

• Operational Simplicity and Cost Efficiency: unified management console reduces tool sprawl and overhead, helping teams enforce consistent policies across hybrid and multi- cloud environments.

• Consistent Policy Across All Environments: whether operating in AWS, Azure, Google Cloud, VMware, Nutanix, or private data centers, Check Point ensures uniform enforcement and compliance with unified management for all Check Point firewalls.

• Zero Trust Security Model: Implements least-privilege access across users, apps, and workloads, regardless of location or device.

WHAT IS NETWORK ACCESS CONTROL? 3

© 2026 Check Point Software Technologies Ltd. All rights reserved

What is Network Access Control?

To effectively secure the fragmented cloud perimeter, organizations must begin with the most fundamental layer of defense: controlling who and what can access their

environments. This is where modern Network Access Control plays a pivotal role.

Network Access Control (NAC) governs who can access systems, data, and services across the enterprise network. In today’s hybrid cloud world, NAC must adapt to complex environments that span public cloud, private cloud, and on-premises infrastructure.

Check Point delivers NAC through intelligent enforcement, deploying gateways at strategic intersections across the cloud. These gateways go beyond traditional firewalls by incorporating identity, roles, and contextual attributes (like location, device, or time) into access decisions.

Securing Dynamic Cloud Environments Modern cloud environments are fluid. Workloads scale up and down, resources shift, and users connect from everywhere. To secure this landscape, NAC must:

• Adapt in Real Time: Policies must automatically adjust based on changes in cloud workloads, user behavior, and network topology.

• Integrate Seamlessly: Security controls should tie into cloud provider controls to automate enforcement and reduce manual overhead.

• Scale Across Clouds: With unified policy enforcement across public, private cloud, and on-premises networks, Check Point simplifies access control, even in the most distributed architectures.

What Unified Access Control Policies Enable • Protection Against Unauthorized Access: Prevents attackers, malicious insiders,

and misconfigured systems from reaching sensitive resources.

• Regulatory Compliance: Enforces access controls and provides detailed audit logs to help meet industry-specific mandates like HIPAA, GPDR, and PCI DSS.

• Zero Trust Enforcement: No user or device is trusted by default, even inside the network. ccess is granted only after verification.

• Lateral Movement Prevention: Microsegmentation limits blast radius the spread of attacks across networks, workloads, and regions.

WHAT IS NETWORK ACCESS CONTROL? 4

© 2026 Check Point Software Technologies Ltd. All rights reserved

• Multi-Cloud and Hybrid Environment Support: Centralized policies reduce misconfigurations across diverse environments and simplify operations.

• Dynamic Policies: Adjust policies and access rules automatically responding to real-time changes in object meta data, user roles, server groups, and network context.

How Does Network Access Control Work in Clouds? In cloud environments, Network Access Control is enforced through virtual firewalls and intelligent gateways that inspect traffic and apply policies in real time. These policies are based on a combination of factors, including security zones, geographic regions, specific applications or services, types of data being accessed, and users' roles or identities. This multidimensional approach enables more precise access decisions than traditional static rule sets.

Check Point Cloud Firewall as a Service serves as a core enforcement point for this model. It inspects every connection and dynamically enforces access policies based on real-time context, helping organizations prevent unauthorized access and reduce risk across distributed environments.

To support compliance, auditing, and security operations, Check Point Cloud Firewall as a Service automatically generates detailed access logs. These logs include essential metadata such as the source and destination networks, communication protocols, applications used, user identities, accessed resources, and the types of data involved. This deep visibility enables faster investigation of anomalies, supports regulatory reporting, and strengthens overall governance across hybrid and multi-cloud architectures.

Creating Network Security Access Control Policies The core of any network firewall is a set of access control policies that determine which connections are allowed and denied. These policies are critical to enforcing security while maintaining efficient operations across cloud and on-premises environments. An effective policy begins by allowing only authorized connections and blocking those that present vulnerabilities or unnecessary exposure. This means ensuring that only verified users and devices can access specific internal resources and that all connections are thoroughly inspected.

Check Point Cloud Firewall as a Service enables organizations to define policies that go beyond traditional access lists. For example, stealth rules can block direct access to security gateways, shielding them from external probing or attacks. Clean-up rules, typically placed at the end of the policy, act as a final layer of defense by dropping any traffic that hasn’t explicitly been allowed earlier in the rule base.

WHAT IS NETWORK ACCESS CONTROL? 5

© 2026 Check Point Software Technologies Ltd. All rights reserved

Together, these elements ensure not just security but clarity, removing ambiguity from the network’s access posture and ensuring that every connection is intentional, traceable, and aligned with organizational policy.

Why is Unified Network Access Control Important?

As organizations adopt increasingly complex cloud architectures, fragmented access control becomes a growing risk. Managing security across multiple vendors and platforms can lead to misconfigurations, inconsistent policies, and gaps that attackers can exploit.

A unified approach to Network Access Control consolidates security policy creation, logging, monitoring, and reporting into a single, centrally managed system. With Check Point, security administrators can define and enforce policies across all environments, from on-premises data centers to AWS, Azure, Google Cloud, and more in one management console.

This centralized model dramatically improves operational efficiency while reducing the chances of human error. It also accelerates threat response by offering correlated visibility into user behavior, application usage, and policy violations across all networks.

THREAT PREVENTION: STAYING AHEAD OF ATTACKERS 6

© 2026 Check Point Software Technologies Ltd. All rights reserved

Unified access control should support a comprehensive set of capabilities, including firewall enforcement, application and URL filtering, content awareness to restrict sensitive data movement, secure VPN connectivity for site-to-site and mobile users, and identity-based access controls. These features work in concert to ensure that every access request is evaluated contextually and that security policies are consistently applied, no matter where the user or workload resides.

But network access control is not enough While access control governs who can access resources, it doesn’t determine what threats they may bring. That’s why access must be paired with proactive threat prevention, which can stop attacks before they spread.

Threat Prevention: Staying One Step Ahead of Attackers In modern environments, the network perimeter is no longer a well-defined boundary. It has become a patchwork of access points, cloud identities, and third-party services. While the phrase “identity is the new perimeter” is commonly used, it’s also misleading. Access control may determine who gets in, but it doesn’t stop threats. It simply defines who is allowed to bring them in. That’s why identity and access management alone is not enough. Organizations must pair it with AI-powered threat prevention that can inspect behavior, disarm malicious content, and proactively block sophisticated attacks, no matter how they enter.

To stay ahead, organizations need a prevention-first strategy that can anticipate and block threats before damage is done. Threat prevention does just that: detecting and blocking cyberattacks before they reach their targets, leveraging intrusion prevention, advanced malware detection, URL filtering, anti-phishing, anti-bot defenses, and sandboxing. More importantly, robust threat prevention requires real-time, accurate intelligence to stop threats before they spread. That’s where Check Point ThreatCloud AI stands apart.

ThreatCloud AI: The Brain Behind Check Point Real Time Security ThreatCloud AI combines the latest in AI and machine learning with massive-scale threat intelligence to deliver faster, more accurate protection with near-zero false positives. These capabilities translated into a perfect 100% block rate across 2,028 exploits, 2,500 evasion attempts, and over 2,700 legitimate samples in CyberRatings.org’s independent Q1 2025 evaluation, with zero false positives recorded. It aggregates data from over 150,000 connected

https://engage.checkpoint.com/cyber-ratings-resource-page/items/webinar--cyberratings-puts-cloud-network-firewalls-to-the-test?fw=3027d https://engage.checkpoint.com/cyber-ratings-resource-page/items/webinar--cyberratings-puts-cloud-network-firewalls-to-the-test?fw=3027d https://community.checkpoint.com/t5/Cloud-Firewall/Check-Point-Demos-Multi-Cloud-Security-Securing-an-Ever-Changing/m-p/277752#M6245

THREAT PREVENTION: STAYING AHEAD OF ATTACKERS 7

© 2026 Check Point Software Technologies Ltd. All rights reserved

networks, millions of endpoints, and dozens of global feeds, enriching it with exclusive research from Check Point Research (CPR). This elite team uncovers the world’s most advanced software vulnerabilities and threats, often before they’re publicly known.

These capabilities were validated by Miercom’s Q1 2025 Enterprise and Hybrid Mesh Firewall Security Report, which named Check Point the top-performing vendor across all threat prevention categories. In real-world zero-day scenarios, Check Point blocked 99.9% of Zero+1 Day malware, scored 99.74% phishing URL prevention with only a single miss, and outperformed all other vendors in first-to-block speed during live threat simulations.

https://www.checkpoint.com/2025-miercom-firewall-report/

THREAT PREVENTION: STAYING AHEAD OF ATTACKERS 8

© 2026 Check Point Software Technologies Ltd. All rights reserved

When a threat is identified, whether it’s a zero-day malware sample, a phishing link, or a sophisticated Trojan, ThreatCloud I instantly propagates protections across all Check Point products. For example, a malicious URL discovered in the U.S. can be blocked in real time just seconds later in a similar attack in Australia. This global sharing model ensures that customers are protected within moments of a threat being discovered, with no patching required.

Prevention in Action: What ThreatCloud AI Delivers • Block Zero-Day Threats at Scale: With 55+ AI-driven engines, ThreatCloud AI detects and

blocks zero-day ransomware, trojans, and advanced malware before others even know they exist.

• Real-Time Threat Sharing: New protections are delivered instantly worldwide, ensuring your organization benefits from worldwide visibility.

• Disarm Malicious Content Instantly: Ultra-fast Content Disarm and Reconstruction (CDR) technology removes potential threats from web downloads and email attachments in less than a second.

• Stop First-Seen Phishing: Advanced deep learning analyzes over 300 phishing indicators to prevent previously unknown attacks arriving via web or email. Miercom confirmed 99.74% phishing URL prevention with only one missed phishing link during their 2025 benchmark test.

• Fewer False Positives: ThreatCloud AI extreme accuracy means security teams deal with fewer alerts and tickets, improving productivity without compromising safety.

Securing the Future with Check Point Check Point Cloud Firewall as a Service integrates ThreatCloud AI into every layer of cloud network security, delivering proactive, intelligent, and globally enforced protection. This strength was validated in CyberRatings.org’s evaluation, where the 3 major CSPs scored 0 and Check Point Cloud Firewall products achieved a 100% block rate across exploits, evasions, and encrypted traffic, one of only two solutions to do so.

https://cyberratings.org/reports/cloud-network-firewall/ https://engage.checkpoint.com/cyber-ratings-resource-page/items/webinar--cyberratings-puts-cloud-network-firewalls-to-the-test?fw=3027d

THREAT PREVENTION: STAYING AHEAD OF ATTACKERS 9

© 2026 Check Point Software Technologies Ltd. All rights reserved

But threat prevention is not enough To ensure threat prevention keeps pace with rapidly evolving cloud workloads, security must be intelligent and cloud native. This means integrating directly with the infrastructure and scaling as fast as the applications it protects.

https://pages.checkpoint.com/2025-apr-cyber-ratings-report.html

CLOUD-NATIVE CAPABILITIES: SCALING WITH SPEED 10

© 2026 Check Point Software Technologies Ltd. All rights reserved

Cloud-Native Capabilities: Scaling with Speed Modern cloud environments are dynamic, workloads scale up or down by the hour, applications span regions, and new services spin up in seconds. Security must move just as fast.

Check Point Cloud Firewall as a Service is built from the ground up with cloud-native principles, enabling it to integrate, scale, and adapt across public and private cloud architectures without friction.

Seamless Integration with Cloud Platforms Check Point Cloud Firewall as a Service supports leading platforms: AWS, Azure, and Google Cloud.

Leveraging native API integrations, it connects directly with these environments to automate routine tasks such as policy updates, threat monitoring, and instance scaling.

Dynamic Policies with Cloud Tags In fast-moving environments, static rules become obsolete quickly. Check Point Cloud Firewall as a Service solves this by tying policies to cloud-native tags rather than IP addresses. When a tagged resource is deployed, security policies are applied automatically. If that resource is terminated or changed, policies adapt in real time. This automation-first approach eliminates configuration drift, reduces manual errors, and keeps security aligned with DevOps's velocity.

https://community.checkpoint.com/t5/Cloud-Firewall/Check-Point-Delivers-Cloud-Firewall-as-a-Service-on-Major/m-p/268153/highlight/true#M5630

CLOUD-NATIVE CAPABILITIES: SCALING WITH SPEED 11

© 2026 Check Point Software Technologies Ltd. All rights reserved

Managed by Check Point Network Operations Center (NOC) Check Point Cloud Firewall as a Service includes managed firewall infrastructure by Check Point Security Network Operations Center. Includes 24x7x365 support by Check Point engineers to monitor, triage, and remediate incidents following change control and other best practices

• Never patch a cloud firewall again

• Increase security posture and eliminate human errors

• Reduce strain on IT resources

Automated Scaling with Changing Workloads Check Point hybrid mesh firewalls scale in and out automatically based on real-time workload demands. During traffic spikes, such as product launches or seasonal events, firewalls scale up instantly. As the load decreases, they scale down to optimize cost.

Security policies are dynamically applied to new instances as they launch, ensuring no gaps in protection and no manual rework.

Unified Management Across Environments Whether you’re running on-premises, in the cloud, or a hybrid model, Check Point centralizes ALL firewall and gateway security operations through Smart-1. This unified console provides visibility, policy management, logging, and threat analysis across environments, eliminating silos and simplifying oversight.

Integration with Check Point ThreatCloud Events enables real-time correlation and enriched incident response, helping security teams respond faster and more accurately.

Managed Firewall Infrastructure Across 3 Major Cloud Providers Check Point Cloud Firewall as a Service native integration with cloud vendor control planes improves operational visibility, simplifies deployment workflows, and enables teams to leverage cloud infrastructure monitoring and logging frameworks as part of security operations. Cloud Firewall as a Service enforces multi-layer network security (firewall, IPS, application control, Anti-Virus/Anti-Bot) across cloud vendor traffic flows (egress and east-west intra-VPC/VNet).

Efficient by Design With built-in automation and scalability, Check Point Cloud Firewall as a Service reduces manual intervention and lowers operational overhead. Resources are allocated based on real- time needs, helping organizations avoid overprovisioning while maintaining enterprise-grade protection.

PUBLIC AND PRIVATE CLOUDS USE CASES 12

© 2026 Check Point Software Technologies Ltd. All rights reserved

Public and Private Clouds Use Cases The capabilities mentioned in the previous chapter are not hypothetical; they come to life in real-world deployments. The following use cases show how Check Point’s thousands of cloud customers secure their environments at scale.

Public Cloud Use Case: Auto-Scaling Security with AWS Cloud infrastructure is designed to scale, but unless your security scales with it, the attack surface grows unchecked. For example, an e-commerce platform anticipating a surge in traffic during a shopping holiday needs to expand both its infrastructure and its security posture instantly.

By deploying Check Point Cloud Firewall as a Service organizations can dynamically scale security protections across workloads without compromising performance or introducing operational complexity.

Auto-Scaling with Check Point Cloud Firewall as a Service The Check Point auto-scaling blueprint is built on automation, deep cloud-native visibility, and infrastructure-as-code. Here's how auto-scaling works in practice:

• Real-Time Monitoring and Scaling Triggers: Monitoring of traffic volumes automatically triggers scaling events as thresholds are exceeded.

• Deployment of Check Point Cloud Firewall as a Service: Once scoping is completed Cloud Firewall as a Service can be deployed immediately anywhere AWS, Azure, and Google Cloud are available.

PUBLIC AND PRIVATE CLOUDS USE CASES 13

© 2026 Check Point Software Technologies Ltd. All rights reserved

• Dynamic Security Policy Assignment: Once deployed, Check Point Cloud Firewall as a Service detects the new instances, maps associated AWS, Azure, and Google Cloud tags and metadata, and automatically assigns appropriate security policies, all based on predefined rules.

• Intelligent Traffic Distribution and HA: Check Point ensures traffic is evenly distributed across all firewall instances and uses health checks to ensure traffic only reaches healthy gateways. Failed instances are bypassed and automatically replaced.

• Efficient Cost Model: Pay based on consumption and receive a 99.99% uptime SLA.

Key Capabilities • Native Integration: Check Point Cloud Firewall as a Service integrates directly with

Cloud Service Provider APIs to import cloud-native objects, including instances, tags, ENIs, ELBs, Security groups, and subnets, importing them as dynamic objects for precise object-based policy enforcement.

• Secure Cross-Account Connectivity: Supports multiple credential options, including IAM role, Access Key Secret, and STS Assume Role, allowing secure management of multiple accounts from a centralized console.

• Tag-Driven Automation: Security policies automatically adapt based on cloud native tags (e.g., Env=Prod, App=Payments). When new instance is launched with a recognized tag, the relevant policy is instantly applied with no manual configuration.

• Fully Managed Infrastructure: Check Point NOC manages the entire firewall software infrastructure freeing up IT staff to focus on policy enforcement and business support. No more patching or outdated firewall software putting your organization at risk.

Benefits • Unmatched Security: In a head-to-head comparison of cloud firewalls conducted by

CyberRatings.org in 2025, Check Point Cloud Firewall products achieved 100% security effectiveness, outperforming AWS’s cloud firewall, which got 0% security effectiveness when tested across Routing Access Control, TLS SSL functionality, exploits, evasions, stability, and reliability.

• Resilient, Elastic Security Posture: Ensures that as workloads scale, so does protection, without lag or manual intervention.

• Unified Policy Management: All Check Point Cloud Firewall products, whether deployed in public cloud or elsewhere, are managed from a single pane of glass.

https://engage.checkpoint.com/cyber-ratings-resource-page/items/webinar--cyberratings-puts-cloud-network-firewalls-to-the-test?fw=3027d

PUBLIC AND PRIVATE CLOUDS USE CASES 14

© 2026 Check Point Software Technologies Ltd. All rights reserved

• Optimized Costs: Firewall infrastructure is efficiently architected and maintained preventing over provisioning while maintaining performance and compliance.

• Visibility and Governance: Real-time telemetry, logs, and threat events are centralized for auditing, troubleshooting, and incident response.

Conclusion With Check Point Cloud Firewall as a Service integration with AWS, Azure, and Google Cloud you can gain the elasticity of the cloud without compromising on visibility, control, or protection. Combined with ThreatCloud AI and centralized policy orchestration, organizations can enforce consistent, intelligent security policies at cloud speed without worrying about firewall infrastructure.

Public Cloud Use Case: Securing Azure Virtual WAN with Check Point As organizations adopt global cloud strategies, many are turning to Azure Virtual WAN (vWAN) for its unified connectivity, simplified routing, and native integration with Microsoft’s global backbone.

Check Point Cloud Firewalls integrate seamlessly into Azure Virtual WAN to provide scalable, intelligent traffic inspection across all flows, automating security orchestration and policy enforcement across Azure networks and connected environments.

Overcoming the Limits of Hub-and-Spoke Architecture Traditional Azure hub-and-spoke models often require a proliferation of ExpressRoute and VPN gateways to interconnect regions or branches, resulting in complex configurations, redundant infrastructure, and limited flexibility. Virtual WAN eliminates many of these constraints by centralizing routing in a cloud-native hub, but it does not provide built-in traffic inspection.

By inserting Check Point Cloud Firewall as a Service as a Network Virtual Appliance (NVA) into the Virtual WAN hub, organizations can secure traffic between spokes, across hybrid connections, and to from the internet as traffic is routed through the NVA using Azure’s Routing Intent feature, simplifying and automating the routing path configuration needed for inspection.

PUBLIC AND PRIVATE CLOUDS USE CASES 15

© 2026 Check Point Software Technologies Ltd. All rights reserved

Securing Azure Virtual WAN with Check Point Cloud Firewall as a Service Check Point integration with Azure Virtual WAN follows a scalable architecture that leverages routing intent, virtual appliances, and automation for full traffic inspection. Here’s how it works in practice:

• Check Point Cloud Firewall as a Service NVA Deployment into Virtual WAN Hub: Check Point Cloud Firewall is deployed as a centrally managed NVA orchestrated by the built-in Cloud Management Extension for fast provisioning and automated license and policy setup.

• Routing Intent for Full Traffic Steering: Azure’s Routing Intent feature directs internet- bound and private traffic through the Check Point Cloud Firewall as a Service NVA, enabling consistent inspection of east-west and north-south flows, including traffic between VNets, branches, and on-premises sites.

• Policy Enforcement and Rule Automation: Check Point Cloud Firewall as a Service auto- generates and manages ingress NAT and access control rules that define what traffic is allowed, blocked, or logged. These rules are tied to security policies and can adapt to real- time changes.

• Advanced Threat Prevention and TLS Inspection: With support for IPS, sandboxing, URL filtering, and TLS SSL decryption, Check Point Cloud Firewall as a Service delivers full-stack protection, even under encrypted TLS 1.2 and 1.3 traffic, enforcing consistent Zero Trust principles.

• Hybrid and Multi-Site Protection: Traffic from connected VNets, VPN gateways, and ExpressRoute links is routed through the Check Point Cloud Firewall as a Service NVA for inspection, ensuring consistent policy enforcement across cloud and hybrid infrastructure.

Benefits • Unmatched Security: Azure native fiewall scored 0% in security effectiveness

compared to Check Point 100% effectiveness, per CyberRatings.org’s evaluation.

• Unified Security for Distributed Environments: Enforce consistent policies across regions, clouds, and hybrid environments, all managed from a single console.

• Dynamic, Scalable Architecture: Check Point Cloud Firewall as a Service is engineered to efficiently scale firewalls, ensuring performance during peak loads and cost-efficiency during low-traffic periods.

• Simplified Routing and Policy Control: With Routing Intent, organizations don’t need to manage UDRs (User Defined Routes) manually. Traffic is automatically steered through the Check Point Cloud Firewall as a Service NVA for inspection.

https://cyberratings.org/reports/cloud-network-firewall/

PUBLIC AND PRIVATE CLOUDS USE CASES 16

© 2026 Check Point Software Technologies Ltd. All rights reserved

• Support for Hybrid Connectivity: Protect ExpressRoute and site-to-site VPN connections to on-premises networks while maintaining visibility and enforcement across all access points.

Conclusion Azure Virtual WAN offers powerful networking capabilities, but critical flows are unprotected without integrated traffic inspection. By inserting Check Point Cloud Firewall as a Service into the virtual hub, organizations can achieve scalable, centralized, and automated security across their entire Azure environment.

Private Cloud Use Case: Securing Private Cloud Environments As organizations modernize their data centers and adopt hybrid architectures or repatriate workloads back to on-prem environments, private cloud platforms continue to play a critical role, especially in regulated industries, performance-sensitive workloads, or environments requiring complete infrastructure control. However, securing private clouds brings its own challenges.

Traditional network security tools struggle to keep up with highly virtualized, software-defined environments that span multiple hypervisors, SDN layers, and automation stacks. Conversely, Check Point Cloud Firewall as a Service delivers Hybrid Mesh security unifying policy enforcement, automated object discovery, and advanced threat prevention across public and private clouds alike.

Common Security Architecture Across Private Clouds While Cloud Firewall as a Service is only available on AWS, Azure and Google Cloud, Check Point Cloud Firewall supports a wide range of private cloud and HCI platforms, including Nutanix, VMware, OpenStack, and Oracle Cloud Infrastructure, ensuring consistent and repeatable security controls even as infrastructure varies. Across these environments, Check Point Cloud Firewall delivers:

• Dynamic Object Discovery: Automatically imports virtual machines, tags, subnets, and other cloud-native objects to build real-time, adaptive policy.

• Microsegmentation and Policy Granularity: Enforces least-privilege access across tenants, services, and applications within virtual networks.

PUBLIC AND PRIVATE CLOUDS USE CASES 17

© 2026 Check Point Software Technologies Ltd. All rights reserved

Administrator Firewall

IPS DLP Service Chain

Check Point Cloud Firewall

Cloud Firewall Manager Extension

Unified Network Policy

Management URL Filtering

Auto Provision

Check Point Security Management

• Deep Packet Inspection and Threat Prevention: Stops malware, ransomware, and lateral movement using AI-powered security engines.

• Automation and Orchestration: Check Point Cloud Firewall integrates with private cloud orchestration tools to simplify provisioning, HA configuration, and policy rollout.

This unified firewall architecture allows enterprises to manage complex, distributed networks with a single policy model, managed through a single centralized console, regardless of whether the environment is on-premises, public cloud, or hybrid.

Example: Advanced Network Security in Nutanix Environments One powerful example of this model in action is the integration between Check Point Cloud Firewall and Nutanix, a leading enterprise cloud platform. Through native integration with Nutanix Prism, Check Point Cloud Firewall can dynamically discover VMs, virtual networks, categories, and applications, importing them directly into Check Point management console as dynamic objects for precise, tag-based, dynamic access policies that automatically adjust to environment changes.

Check Point Cloud Firewall also integrates with Nutanix’s Service Insertion Framework, allowing organizations to insert Check Point Cloud Firewall products directly into the data path of East- West and North-South traffic, without manual network reconfiguration.

Benefits • Simple Deployment and Orchestration: Check Point Cloud Firewall can be rapidly provisioned

in active standby pairs for high availability with automated policy assignment.

• Tenant Isolation and Microsegmentation: Logical segmentation can be enforced at the network level, minimizing the blast radius of any compromise.

Cloud Firewall

Cloud Firewall

Cloud Firewall

CONCLUSION 18

© 2025 Check Point Software Technologies Ltd. All rights reserv

• Unified Visibility Across Cloud and On-Premises: Logs, events, and threat telemetry are consolidated in a single console.

• Flexible Security Policy with Nutanix Categories: Check Point Cloud Firewall leverages Nutanix’s native tagging model to create adaptive rules that move with the workload, improving agility and reducing misconfigurations.

Private Cloud Conclusion No matter which private cloud architecture an organization chooses whether built on Nutanix, VMware, OpenStack, or OCI, Check Point Cloud Firewall provides a consistent, intelligent, and prevention-first security layer that is integrated with Cloud Firewall as a Service in the same management console. By extending hybrid mesh firewall capabilities into private infrastructure, enterprises can unify their cloud and on- premises security strategy with full visibility,

Conclusion A Strategic Approach to Securing Multi-Cloud Networks: The modern cloud perimeter isn’t a static edge, and securing it demands prevention, visibility, and automation. Check Point Cloud Firewall as a Service delivers precisely that: a cloud-adapted hybrid mesh firewall software infrastructure that is managed by Check Point NOC.

By combining access control, AI-powered threat prevention, and cloud-native agility, Check Point Cloud Firewall as a Service helps organizations reduce risk without slowing down innovation.

Start now on Amazon Web Services (AWS), Microsoft Azure, and Google Cloud.

Worldwide Headquarters 5 Shlomo Kaplan Street, Tel Aviv, 6789159, Israel | Tel: +972-3-753-4599

U.S. Headquarters 100 Oracle Parkway, Suite 800, Redwood City, CA 94065 | Tel: 1-800-429-4391

www.checkpoint.com

© 2026 Check Point Software Technologies Ltd. All rights reserved.

http://www.checkpoint.com/ https://aws.amazon.com/marketplace/pp/prodview-ig5zyvnhiy26y https://marketplace.microsoft.com/en-us/product/saas/checkpoint.fwaas?tab=overview https://console.cloud.google.com/marketplace/product/checkpoint-public/checkpoint-fwaas?project=buoyant-mason-274907

Unique Challenges of Cloud Networks The Cloud Prevention Mesh: Securing All Entry Points Why Organizations Choose Check Point Cloud Firewall for Hybrid Mesh Key benefits:

What is Network Access Control? To effectively secure the fragmented cloud perimeter, organizations must begin with the most fundamental layer of defense: controlling who and what can access their environments. This is where modern Network Access Control plays a pivotal role. Securing Dynamic Cloud Environments What Unified Access Control Policies Enable How Does Network Access Control Work in Clouds? Creating Network Security Access Control Policies Why is Unified Network Access Control Important?

As organizations adopt increasingly complex cloud architectures, fragmented access control becomes a growing risk. Managing security across multiple vendors and platforms can lead to misconfigurations, inconsistent policies, and gaps that attackers ca... But network access control is not enough

Threat Prevention: Staying One Step Ahead of Attackers ThreatCloud AI: The Brain Behind Check Point Real Time Security Prevention in Action: What ThreatCloud AI Delivers Securing the Future with Check Point But threat prevention is not enough

Cloud-Native Capabilities: Scaling with Speed Seamless Integration with Cloud Platforms Dynamic Policies with Cloud Tags Infrastructure as Code (IaC) for Consistent Deployment Automated Scaling with Changing Workloads Unified Management Across Environments Consistent Protection Across Multi-Cloud and Hybrid Networks Efficient by Design

Public and Private Clouds Use Cases Public Cloud Use Case: Auto-Scaling Security with AWS Auto-Scaling with Check Point Cloud Firewall and GWLBs Key Capabilities Benefits

Conclusion Public Cloud Use Case: Securing Azure Virtual WAN with Check Point Overcoming the Limits of Hub-and-Spoke Architecture Securing Azure Virtual WAN with Check Point Cloud Firewall Benefits

Conclusion Private Cloud Use Case: Securing Private Cloud Environments Common Security Architecture Across Private Clouds Example: Advanced Network Security in Nutanix Environments Benefits

Private Cloud Conclusion

Conclusion


Item Type: pdf