Check Point SASE Internet Access combines on device and cloud delivered protections to give users the fastest, most secure path to the internet. By inspecting traffic locally when possible and leveraging global PoPs when needed, it provides up to 10x faster browsing, more accurate location handling for SaaS and compliance, and stronger privacy by minimizing unnecessary data exposure. With AI driven threat prevention and advanced policy controls, organizations gain tighter security while users enjoy a seamless, high performance internet experience.
Check Point SASE Internet Access eliminates the limitations of traditional cloud-only and on-prem SWGs by delivering a hybrid, on-device-plus-cloud architecture that improves security, privacy, performance, and simplicity. It removes the need to compromise between protection and speed by enabling local on-device inspection when possible and cloud inspection when required, delivering up to 10x faster secure Internet access than cloud-only SWGs. Internet Access is simple to deploy and manage, and can run as a standalone solution or as part of the full Check Point SASE platform, which includes ZTNA, FWaaS, SaaS Security, Browser Security, and SD-WAN.
Key Advantages:
Single-pane-of-glass management for all SASE functions through the Check Point Portal, simplifying administration for AWS environments.
Hybrid on-device + cloud protection provides direct-to-Internet performance for AWS-hosted and SaaS applications, delivering up to 10x faster secure browsing than cloud-only SWGs.
Always-on protection, even off-network or on public Wi-Fi.
Full visibility into user web activity with granular filtering logs.
Category-based web filtering across both cloud inspection and on-device modes.
Support for multiple networks, allowing tailored policies across AWS workloads, branch offices, and remote users.
Split-tunnel traffic protection using on-device inspection to secure traffic that bypasses cloud gateways.
On-device SSL inspection for stronger privacy, no decryption inside third-party cloud centers.
Secure public Wi-Fi usage with multi-layer, AI-driven threat prevention.
Flexible policy controls, including user-based and time-based rules.
Zero infrastructure overhead, no on-prem hardware or maintenance.
Integrated features include Browser Security (DLP, file sanitization, phishing protection, GenAI governance) and SaaS Access Protection for account takeover prevention.
Highlights
HYBRID DEPLOYMENT: While typical deployments are either an on-prem appliance or cloud service, Check Point SASE Internet Access includes both on-device and cloud-based components. They work in concert to provide the highest level of Internet security for corporate users. Internet Access can also work in device- or cloud-only modes, enabling full flexibility for organizations to meet their security needs.
10X FASTER: On-device SSL inspection results in increased speed and a localized browsing experience. Internet Access delivers 10X faster performance, as proven in head-to-head tests.
GRANULAR WEB FILTERING: Check Point SASEs user-centric granular control extends to Web Filtering. Website access rules can be customized for different individuals or groups, and according to time of day. For example, social media sites can be blocked during work hours for all employees except for the social media management team. t team.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
Both dimensions cover Internet Access for 100 users on the Premium package, and you buy them as units under a contract. The difference lies in deployment. The On-Device Premium option secures web traffic directly on user devices. The Hybrid Premium option adds one SASE gateway, combining on-device protection with a network gateway. You pick based on how you want traffic inspected. Pricing scales by the 100-user unit, so you add units as your workforce grows.
Top-of-mind questions for buyers
What counts as one user for billing on these Premium packages?
Each package covers 100 users. A user is a single person you onboard through the cloud console, connecting from managed or unmanaged devices. You buy coverage in blocks of 100 users. To cover more people, you add more 100-user units.
What is the difference between the On-Device and Hybrid Premium options for my bill?
The On-Device option inspects web traffic directly on user devices, so you pay only for 100-user coverage. The Hybrid option adds one SASE gateway, combining on-device inspection with a network gateway. That gateway is bundled into the Hybrid unit, so it raises the per-unit price accordingly.
If my workforce grows beyond 100 users, how does the cost change?
Coverage scales in fixed 100-user blocks. When your headcount passes 100, you add another unit for the next group of users. The added unit charges at the same per-unit rate. There is no partial-block option, so you buy whole 100-user increments.
Request a private offer to receive a custom quote.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
A single pane-of-glass security management console delivers consistent visibility, policy management, logging, reporting and control across all cloud environments and networks
Check Point Check Point Cloud Firewall is a cloud-native security gateway that delivers automated, advanced threat prevention and multi-layered network security for assets that customers migrate to or store on AWS. Try it free for 30 days.
A single security management console delivers consistent visibility, policy management, logging, reporting and control across all cloud environments and networks
Advanced threat prevention security for AWS and hybrid cloud environments, with Threat Extraction and Threat Emulation, and with GWLB (starting with R81.20)
**Please note: To ensure optimal operations, Check Point recommends a 4 vCores machine size. This provides balanced efficiency and smooth performance, which most customers find ideal for their needs.
Advanced threat prevention security for AWS and hybrid cloud environments, with Threat Extraction and Threat Emulation.
**Please note: To ensure optimal operations, Check Point recommends a 4 vCores machine size. This provides balanced efficiency and smooth performance, which most customers find ideal for their needs.
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.