Listing Thumbnail

    Check Point Cloud Firewall (formerly CloudGuard Network Security)

     Info
    Deployed on AWS
    Free Trial
    Check Point Check Point Cloud Firewall is a cloud-native security gateway that delivers automated, advanced threat prevention and multi-layered network security for assets that customers migrate to or store on AWS. Try it free for 30 days.
    4.4

    Overview

    Play video

    Check Point Check Point Cloud Firewall is a cloud-native security gateway that delivers industry-leading threat prevention and multi-layered network security for workloads migrated to or deployed in AWS environments.

    Comprehensive Cloud Network Security: Check Point Cloud Firewall for AWS protects cloud assets with a full suite of advanced security capabilities, including: firewall, Data Loss Prevention (DLP), Intrusion Prevention System (IPS), application control, IPsec VPN, URL filtering, antivirus, and anti-bot. These features enable proactive defense against known and unknown threats, ensuring robust protection for cloud workloads.

    Industry-Leading Threat Prevention: Check Point Cloud Firewall for AWS provides advanced threat prevention to secure AWS environments from sophisticated threats, unapproved access, and application-layer Denial of Service (DoS) attacks with industry-leading catch rates.

    Full Control of Network Traffic: Check Point Cloud Firewall for AWS ensures secure, encrypted data flows between your on-premises network and your AWS VPCs. It inspects traffic entering and exiting private subnets in the VPC ("North-South") as well as between VPCs ("East-West").

    Unified Security Management: Extend on-premises security policies into the AWS cloud with unified, centralized management via Check Point Security Management Server. Manage policies, logs, and reports consistently across AWS, hybrid, and on-premises environments from a single pane of glass. This listing includes the gateway only. For management, use Check Point Smart-1 Cloud: https://www.checkpoint.com/quantum/unified-cyber-security-platform/smart-1-cloud/ 

    Automated, Scalable Cloud Security: Integrates with infrastructure-as-code tools like Terraform and Ansible for policy automation and cloud-native scaling. Cloud Firewall dynamically adapts security policies based on real-time cloud metadata and changes. Supports AWS Transit Gateway, auto-scaling, high availability, and multi-AZ redundancy.

    Flexible Licensing and Seamless AWS Integration: Deploy within minutes as either a single gateway, as a high availability cluster, or as an auto scaling group via Check Point CloudFormation templates (sk111013). Recommended deployment on a 4 vCPU instance for optimal performance. Check Point Cloud Firewall integrates with a broad range of AWS services, including Gateway Load Balancer, AWS Security Hub, VPC Ingress Routing, AWS Traffic Mirroring, AWS Transit Gateway, AWS Outposts, and Amazon Macie.

    Getting Started: Supports both Pay-As-You-Go (PAYG) and Bring Your Own License (BYOL) models with a flexible pricing model that supports both usage-based billing and contract-based subscriptions. Start your free 30-day trial to gain full access to Cloud Firewall's features and capabilities. At the end of the trial, your subscription will automatically convert to a paid, usage-based plan, unless canceled beforehand. Request a private offer for custom pricing and terms. For a guided walkthrough, you may request a product demo through this listing.

    Highlights

    • Advanced Protection with Security Features: Firewall, DLP, IPS, Application Control, IPsec VPN, URL Filtering, Antivirus and Anti-Bot.
    • Industry-Leading Threat Prevention: Cutting-edge threat prevention with industry-leading catch rate of malware, ransomware and other types of attacks (per Miercom and Cyberratings, 2025).
    • Unified Security Management: Provides consistent visibility, policy management, logging, reporting and control across hybrid-clouds and on-premises from a single pane of glass.

    Details

    Delivery method

    Delivery option
    64-bit (x86) Amazon Machine Image (AMI)

    Latest version

    Operating system
    OtherLinux Gaia 3.10

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Features and programs

    Buyer guide

    Gain valuable insights from real users who purchased this product, powered by PeerSpot.
    Buyer guide

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    Free trial

    Try this product free for 30 days according to the free trial terms set by the vendor. Usage-based pricing is in effect for usage beyond the free trial terms. Your free trial gets automatically converted to a paid subscription when the trial ends, but may be canceled any time before that.

    Check Point Cloud Firewall (formerly CloudGuard Network Security)

     Info
    Pricing is based on actual usage, with charges varying according to how much you consume. Subscriptions have no end date and may be canceled any time. Alternatively, you can pay upfront for a contract, which typically covers your anticipated usage for the contract duration. Any usage beyond contract will incur additional usage-based costs.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    Usage costs (211)

     Info
    • ...
    Dimension
    Cost/hour
    c6in.xlarge
    Recommended
    $0.96
    r5a.2xlarge
    $1.58
    c7a.12xlarge
    $9.23
    c7i-flex.16xlarge
    $12.08
    m6a.large
    $0.84
    c5n.4xlarge
    $3.15
    m6a.8xlarge
    $6.16
    c6in.8xlarge
    $6.16
    c6in.large
    $0.84
    r7a.4xlarge
    $3.15

    Vendor refund policy

    Terminate the instance at any given time to stop incurring charges.

    Custom pricing options

    Request a private offer to receive a custom quote.

    How can we make this page better?

    Tell us how we can improve this page, or report an issue with this product.
    Tell us how we can improve this page, or report an issue with this product.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    64-bit (x86) Amazon Machine Image (AMI)

    Amazon Machine Image (AMI)

    An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.

    Additional details

    Usage instructions

    Once the instance is running, connect to it using SSH, set an admin password using: 'set user admin password' followed by 'save config'. Then connect to https://[instance] using Internet Explorer (IE) to finalize the configuration. Notes:

    1. SSH password authentication is disabled in /etc/ssh/sshd_config
    2. For information regarding Firefox and Chrome refer to sk121373.

    Support

    Vendor support

    This offer includes Premium Support. For the full list of included support services visit: https://www.checkpoint.com/support-services/support-plans/  To open a support ticket, you would need to have a Check Point user center account. If you do not have a user center account, you can sign up for one here: https://accounts.checkpoint.com . Need support? Contact us at https://www.checkpoint.com/support-services/contact-support/ 

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Product comparison

     Info
    Updated weekly

    Accolades

     Info
    Top
    10
    In Log Analysis, Network Infrastructure
    Top
    10
    In Network Infrastructure, Security
    Top
    50
    In Migration

    Customer reviews

     Info
    Sentiment is AI generated from actual customer reviews on AWS and G2
    Reviews
    Functionality
    Ease of use
    Customer service
    Cost effectiveness
    Positive reviews
    Mixed reviews
    Negative reviews

    Overview

     Info
    AI generated from product descriptions
    Advanced Threat Prevention Capabilities
    Includes firewall, Data Loss Prevention (DLP), Intrusion Prevention System (IPS), application control, IPsec VPN, URL filtering, antivirus, and anti-bot features for multi-layered network security.
    Traffic Inspection and Control
    Inspects and controls encrypted data flows between on-premises networks and AWS VPCs, including North-South traffic entering and exiting private subnets and East-West traffic between VPCs.
    Infrastructure-as-Code Integration
    Integrates with infrastructure-as-code tools including Terraform and Ansible for policy automation, with dynamic security policy adaptation based on real-time cloud metadata.
    AWS Service Integration
    Supports integration with Gateway Load Balancer, AWS Security Hub, VPC Ingress Routing, AWS Traffic Mirroring, AWS Transit Gateway, AWS Outposts, and Amazon Macie.
    Centralized Security Management
    Provides unified, centralized management through Check Point Security Management Server with consistent policy, logging, and reporting across AWS, hybrid, and on-premises environments.
    Advanced Threat Prevention
    Safeguards network from known and zero-day threats including exploits, malware, spyware, and command and control attacks using researcher-grade signatures and machine learning inspection engine.
    Advanced URL Filtering
    Defends against phishing, ransomware, and web-based attacks using inline machine learning-based web security engine with real-time detection of previously unseen threats and dynamic policy controls.
    File-Based Threat Detection
    Identifies file-based threats through inline static and dynamic analysis in the cloud with proprietary hypervisor technology for detection of sandbox-resistant malware.
    DNS Security
    Detects and prevents sophisticated DNS-layer network attacks and data exfiltration attempts.
    Dynamic Policy Management
    Applies policy definitions to cloud assets based on AWS tags, Application IDs, User IDs, geographies, or zones with automatic adaptation to infrastructure changes without manual intervention.
    Next Generation Firewall Architecture
    High-performance firewall solution with core firewall, VPN, NAT, and advanced L4-L7 security services including application security, IPS, and anti-virus capabilities.
    Anti-Virus and Malware Protection
    Cloud-based anti-virus protection that detects and blocks spyware, adware, viruses, keyloggers, and other malware over POP3, HTTP, SMTP, and FTP protocols.
    Intrusion Detection and Prevention
    Intrusion detection and prevention (IPS) system integrated with application visibility and control through AppSecure for threat detection and workload protection.
    VPN and Secure Connectivity
    IPsec and full mesh VPN termination services enabling secure connectivity from on-premises data centers, campuses, and branches to AWS cloud across geographically dispersed VPCs.
    AWS Cloud Service Integration
    Native integration with AWS services including Elastic Load Balancer, Auto-Scaling Groups, CloudWatch, Security Hub, Key Management Service, Elastic Network Adapter support, and Gateway Load Balancer with L3 gateway and L4 load balancer capabilities.

    Contract

     Info
    Standard contract
    No
    No
    No

    Customer reviews

    Ratings and reviews

     Info
    4.4
    402 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    65%
    31%
    3%
    1%
    0%
    39 AWS reviews
    |
    363 external reviews
    External reviews are from G2  and PeerSpot .
    reviewer2875401

    Unified security policies have protected our hybrid network with deep, user-based controls

    Reviewed on Jul 20, 2026
    Review from a verified AWS customer

    What is our primary use case?

    Check Point Cloud Firewall (formerly CloudGuard Network Security)  is the main manager that provides network security in different forms in my organization. The primary task that Check Point solves is serving as the main means of network security.

    Check Point Cloud Firewall (formerly CloudGuard Network Security)  has several classes of modules. The main modules include Firewall, Antivirus, Anti-Bot, URL Filtering, the IPS module, and Identity Awareness, which is tightly integrated into our organization and ensures connectivity of corporate users with the corporate network, allowing us to create dynamic sessions and policies.

    In our practice, we use a single common profile for all gateways in Check Point Cloud Firewall (formerly CloudGuard Network Security), which allows us to unify all policies and, with the help of sections, display what accesses exist for particular services.

    The Identity Awareness module helps our company by allowing us to have approximately fifty Active Directory controllers. We have deployed three Identity Awareness controllers, which are connected to all our security gateways. It works on the principle that when a user logs into their device, data about their current IP address and login is written to the Active Directory logs. The Identity Awareness controller integration reads them and sends them to the security gateway. Check Point Cloud Firewall (formerly CloudGuard Network Security) then queries the Active Directory controller, pulls in all the user's groups, and allows access for each user based on their Active Directory groups, which makes it possible to create dynamic policies and dynamic accesses.

    Check Point Cloud Firewall (formerly CloudGuard Network Security) is also used to provide VPN access for engineers. At the moment, we are no longer using Check Point Cloud Firewall (formerly CloudGuard Network Security) together with other Check Point solutions. Previously, we had approximately five projects integrated with Check Point. We used their IA (Identity and Access) solutions, their analyzers, and also their endpoint client at the workstation level.

    What is most valuable?

    The main benefit and main advantage of using Check Point Cloud Firewall (formerly CloudGuard Network Security) is that we use unified security approaches both on on-premises segments and in the cloud. We have the same set of policies applied to different types of gateways—both physical and virtual. A unified approach greatly simplifies the administration of the entire network.

    By default, most companies do not use separate firewalling solutions in the cloud at all. They use basic functions such as security groups, NACLs, target evaluation, and similar tools. This is sufficient for them. However, all these solutions do not allow the network to be protected from more advanced attacks above standard firewalling. Check Point Cloud Firewall (formerly CloudGuard Network Security) or any NGFW solution makes it possible to protect against a large number of attacks at the IPS, antivirus, and anti-bot level. If there is a sandbox—SandBlast—then the solution can also inspect what is inside the packets themselves to maximally protect the corporate network. By default, cloud-native solutions do not provide this capability.

    What needs improvement?

    The main limitations of Check Point Cloud Firewall (formerly CloudGuard Network Security) are not in Check Point itself but in the cloud platforms on which it is deployed. Because not all clouds have L2 infrastructure, you cannot build a unified clustering system everywhere. As a result, the problem usually is not with Check Point, but with the cloud.

    The main problem with Check Point Cloud Firewall (formerly CloudGuard Network Security) is that it uses a separate thick client instead of a browser. A browser-based SmartConsole exists, but it still has a number of limitations, while the thick client, the so-called SmartConsole, often works unstably, freezes, and has to be restarted.

    I do not recommend using Check Point Cloud Firewall (formerly CloudGuard Network Security) as a VPN hub for site-to-site VPN because it is inconvenient to monitor the state of its tunnels, especially visually. It does not have a convenient snap-in and everything can be checked only via the console, which is very inconvenient. Check Point is not the most universal solution as a device that provides routing and administration capabilities in addition to security. It is an excellent firewall, but it has a number of limitations in terms of routing and in creating VPN sessions, especially in terms of displaying their states.

    For how long have I used the solution?

    I have been in my current position for more than seven years.

    What do I think about the stability of the solution?

    Regarding the firewall of Check Point Cloud Firewall (formerly CloudGuard Network Security), I would rate it an eight because of its not always stable operation. As a universal device that provides both security and some routing functions, I would rate it a seven.

    Check Point Cloud Firewall (formerly CloudGuard Network Security) is an excellent central firewall. At the same time, it has some limitations in terms of optimization at the level of displaying VPN-tunnel operation. It also has a more complicated approach to building clusters. Unlike Fortinet, for example, it does not allow you to simply make an active-passive configuration using a shared config. Its clustering approach uses the presence of two IP addresses on each node and necessarily one shared virtual IP address using a VRRP-like architecture. I consider this inconvenient, especially when you need to swap nodes or when the role of each node changes.

    I handled the entire technical part of Check Point Cloud Firewall (formerly CloudGuard Network Security); a separate manager was responsible for licensing and handled all licensing issues for all products, so that was not my area of responsibility.

    Check Point Cloud Firewall (formerly CloudGuard Network Security) still has many additional tools that are not fully integrated into SmartConsole. To get to some specific Check Point functions, you have to open additional consoles, which is very inconvenient. The thick client, SmartConsole, is not maximally stable. It often freezes and requires a lot of resources.

    I do consider Check Point Cloud Firewall (formerly CloudGuard Network Security) to be a stable solution, but I also believe that Check Point requires constant monitoring and timely reaction to possible failures.

    What do I think about the scalability of the solution?

    Check Point has two solutions: cluster and Maestro. ClusterXL is initially intended for a certain volume of traffic. Maestro technology allows you to scale out the firewall group and expand the capabilities of the logical group.

    How are customer service and support?

    The work of Check Point's customer support for Check Point Cloud Firewall (formerly CloudGuard Network Security) varies. We had a large number of cases with Check Point. There were cases that were solved fairly quickly. There were very long ones. There are still cases that we have not closed, but we are no longer actively dealing with them—we have found workarounds to temporarily close certain problems.

    Which solution did I use previously and why did I switch?

    In my practice, I have also used Fortinet's solution, which is also very stable. Fortinet uses the same approaches as Check Point; it has one and the same operating system across its devices. Unlike Check Point, Fortinet has a number of advantages and a number of limitations. The main advantage is its versatility: it acts as both a firewall and a router, works perfectly with VPN, but in terms of security class, it has limitations. Check Point Cloud Firewall (formerly CloudGuard Network Security), as a firewall, has a number of advantages. If you analyze the datasheets provided by Check Point and Fortinet, Fortinet greatly inflates its performance figures.

    I have also used solutions from Fortinet and Cisco ASA  before moving to Check Point Cloud Firewall (formerly CloudGuard Network Security) because it provides more capabilities in terms of security and deeper analysis, as well as more detailed troubleshooting options. At the same time, it has some limitations in terms of performance and stability, which I have already mentioned.

    How was the initial setup?

    We have had all possible options for deploying Check Point Cloud Firewall (formerly CloudGuard Network Security). Approximately sixty percent are solutions represented as Quantum (CloudGuard) in configurations like VSX  and standalone. We had solutions integrated with VMware NSX , but we have already abandoned them because VMware no longer supports such architectures. Forty percent of our current firewalls are firewalls deployed in public clouds—Azure  and AWS .

    What about the implementation team?

    We initially purchased Check Point Cloud Firewall (formerly CloudGuard Network Security) with licenses from AWS , and later we switched to purchasing licenses from an integrator and changed the licensing approach from pure cloud to external licensing.

    What was our ROI?

    The main investment effect and everything I can say is that for all the time of my personal work at companies, our services have never been hacked with Check Point Cloud Firewall (formerly CloudGuard Network Security). There were many attempts, they were all logged, but there were no successful hacks. This is the main benefit we gained from working with this product.

    What's my experience with pricing, setup cost, and licensing?

    Since we use a unified standard for using policies and modules in Check Point Cloud Firewall (formerly CloudGuard Network Security), we can clearly plan which modules we need to activate on a particular gateway for its maximum effective use and cost savings. It does not make sense to activate all blades on all gateways. In our architecture, we have two types of gateways: external and corporate. The corporate ones are more heavily loaded, so they have slightly weaker protection. The external ones are less loaded; therefore, they are maximally protected, and almost all possible Check Point blades are activated for them.

    Which other solutions did I evaluate?

    By default, most companies do not use separate firewalling solutions in the cloud at all. They use basic functions such as security groups, NACLs, target evaluation, and similar tools. This is sufficient for them. However, all these solutions do not allow the network to be protected from more advanced attacks above standard firewalling. Check Point Cloud Firewall (formerly CloudGuard Network Security) or any NGFW solution makes it possible to protect against a large number of attacks at the IPS, antivirus, and anti-bot level. If there is a sandbox—SandBlast—then the solution can also inspect what is inside the packets themselves to maximally protect the corporate network. By default, cloud-native solutions do not provide this capability.

    What other advice do I have?

    My advice to other professionals who are considering using Check Point Cloud Firewall (formerly CloudGuard Network Security) is to treat it exactly as a firewall. It is an excellent fit for some central nodes, data centers, and core levels. As a universal device, especially a small universal device, I would not recommend it because of the complex cluster configuration and also, in some cases, more complex troubleshooting. In particular, it has issues with role changes at the cluster level when older Check Point versions, the so-called R80 .x and earlier, are used.

    I really hope that in the future, Check Point Cloud Firewall (formerly CloudGuard Network Security) will abandon the thick client and be able to fully switch to working only via the web interface, and also improve the operation of site-to-site VPN in terms of displaying tunnel states. This is the main problem I have encountered. At the same time, the logging system is excellent, and the troubleshooting system is also very good, but the client's operation definitely has room for improvement. I would rate this review an eight overall.

    Ahad A.

    Beautiful UI, Fine Traffic Control, and Amazing SupportHead of cheese

    Reviewed on Jul 16, 2026
    Review provided by G2
    What do you like best about the product?
    It allows me to have fine control over the traffic that is sent through to our systems. Especially the logging features allows our team to easily inspect any unauthorised intrusions into our network. The user interface is beautiful and it integrates easily into our own systems. The performance is comparable to top systems that we use previously and is good value for money helping us get a high roi. The support from the team is amazing with some exciting ai features.
    What do you dislike about the product?
    I love it so much, their is nothing i dislike about the platform other than a rude sales person but other than that they were amazing. Couldnt ask for a better team to suppor tthe work and provide the solution whciht hey did
    What problems is the product solving and how is that benefiting you?
    It sollves the very hard problemsof stopping intruders and bot traffic into our network. Form hackers to disgruntled employees. IThey helped soilve the problem really well
    Akhilesh G.

    Strong Threat Prevention, Needs Easier Setup

    Reviewed on Jul 16, 2026
    Review provided by G2
    What do you like best about the product?
    I like Check Point Cloud Firewall's strong threat prevention, centralized policy management, easy integration with the cloud environment, and comprehensive visibility into network traffic and security events.
    What do you dislike about the product?
    I find the initial setup and policy configuration to be complex, and the management interface has a learning curve. More intuitive reporting and simplified troubleshooting would improve the overall experience. Simplifying the initial deployment with better setup wizards, improving the UI for policy management, and providing a more customizable dashboard and reporting would make the platform easier to use, especially for new administrators.
    What problems is the product solving and how is that benefiting you?
    I use Check Point Cloud Firewall to secure cloud workloads and prevent threats, though its initial setup and policy configuration can be complex. It improves cloud traffic visibility despite a management interface learning curve.
    Pavan R.

    Strong Multi-Cloud Security with Centralized Management and Powerful Automation

    Reviewed on Jul 08, 2026
    Review provided by G2
    What do you like best about the product?
    What I like most about Check Point Cloud Firewall is its strong security capabilities combined with centralized management across multiple cloud environments. It provides advanced threat prevention, granular access control, and excellent visibility into network traffic. The integration with public cloud platforms is smooth, making it easier to enforce consistent security policies across AWS, Azure, and Google Cloud. The user interface is intuitive, logging and monitoring are comprehensive, and the automation features help reduce manual effort while improving overall security posture. It is a reliable solution for organizations looking to secure hybrid and multi-cloud deployments.
    What do you dislike about the product?
    While Check Point Cloud Firewall offers strong security features, the initial setup and configuration can be complex, especially for teams that are new to the platform. The management console has a learning curve, and troubleshooting policy-related issues can sometimes take longer than expected. Licensing and pricing can also be expensive for smaller organizations. Improving the user interface, simplifying deployment, and providing more intuitive documentation and guided configuration would make the overall experience much better.
    What problems is the product solving and how is that benefiting you?
    Check Point Cloud Firewall helps us secure cloud workloads and network traffic across multiple cloud environments from a single management console. It improves visibility into traffic, enforces consistent security policies, and provides advanced threat prevention to reduce the risk of cyberattacks. The solution has helped simplify firewall management, strengthen compliance, minimize manual configuration efforts through automation, and improve our overall cloud security posture while reducing operational overhead.
    Information Technology and Services

    Flexible SMS and MDS Models Make Check Point Cloud Firewall Stand Out

    Reviewed on Jul 03, 2026
    Review provided by G2
    What do you like best about the product?
    The best about checkpoint cloud firewall is its two models, sms and mds. The checkpoint sms is the end firewall and mds is the top one which manages sms
    What do you dislike about the product?
    The dislike about check point is its not up to date like palo alto/fortinet as they are the market leaders with lot of capabilities which are lacking in checkpoint
    What problems is the product solving and how is that benefiting you?
    The problem that checkpoint cloud firewall solving is security rule creation and rule placement. I use checkpoint smart console to access checkpoint sms device and creates rule. I used to automate these kind of usecases using external scripting to avoid manual errors
    View all reviews