As the term “cloud-first” suggests, many corporate IT departments are implementing or considering the development of new systems and the migration of existing on-premises systems to private and public cloud environments.
Check Point Cloud Firewall from Check Point is a next-generation firewall solution designed to operate in virtualized and cloud environments. It uses the same architecture as Check Point’s on-premises gateways and provides multi-layered protection as a virtual appliance.
Check Point Cloud Firewall from Check Point is a next-generation firewall solution designed to operate in virtualized and cloud environments. It uses the same architecture as Check Point’s on-premises gateways and provides multi-layered protection as a virtual appliance.
Features of Check Point Cloud Firewall
-
Public Cloud Security
-
Comprehensive Cloud Protection Powered by Software Blade Architecture
Check Point Cloud Firewall for Public Cloud enables organizations to secure servers and networks operating on platforms such as Amazon Web Services and Microsoft Azure.
This virtual appliance (a security gateway for virtualized environments) is designed for seamless deployment. It safeguards network connectivity within dynamic cloud computing environments, effectively preventing sophisticated attacks and data breaches. -
Inter-VM Traffic Inspection
With finely tunable Check Point firewall policies and industry-leading intrusion prevention capabilities, all traffic flowing between virtual machines—both internal and external—is inspected to protect the virtual machines. It secures virtual applications from external threats and enables isolation between them. Real-time updates keep your defenses always up to date. -
Unified management of physical and virtual environments
As with other Check Point security appliances, physical and virtual environments can be centrally managed using Check Point management products.
This ensures consistent security across all gateways while minimizing the cost associated with management consoles.
<Differences Between Host-Based security and Gateway-based Security (Check Point Cloud Firewall) in Public Cloud Environments>
-
Comprehensive Cloud Protection Powered by Software Blade Architecture
-
Private Cloud Security
-
Comprehensive Cloud Protection with Software Blades
Check Point Cloud Firewall for private cloud security combines microsegmentation with network virtualization platforms that provide built-in network isolation and segmentation capabilities, delivering advanced protection for east-west traffic within the data center. No configuration of VLANs, ACLs, firewall rules, physical firewalls, or routers is required. -
Multi-Layered Protection in a Single Virtual Appliance
A single security function is not sufficient to defend against sophisticated attacks such as zero-day targeted attacks. Multiple security capabilities must be combined to block threats through multi-layered protection. Check Point Cloud Firewall integrates the security capabilities required to protect against zero-day targeted attacks into a single virtual appliance, including malware protection with Antivirus, Threat Emulation, and Threat Extraction; protection against attacks that exploit vulnerabilities with IPS; and data leakage prevention with Anti-Bot. This multi-layered approach reduces the cost and operational effort associated with deploying and managing multiple security functions, while enabling advanced security capabilities to be delivered through a single solution. -
Seamless Advanced Security
Check Point security gateway appliances are coded using Intel CPU instructions without relying on ASICs, enabling high performance in virtualized and cloud environments. Enterprise-level throughput can be achieved with as few as 2 vCPUs, helping reduce operating costs in cloud environments. If higher throughput is required, performance can be increased by adding more vCPUs.
-
Comprehensive Cloud Protection with Software Blades
Product Lineup
| Private cloud | Public cloud | ||
|---|---|---|---|
| Product lineup | for VMware NSX | for VMware ESXi | for Amazon Web Services for Microsoft Azure |
| License counting | Per physical CPU | Per virtual CPU | Per virtual CPU |
| Security functions |
Firewall IPsec VPN Identity Awareness IPS Application Control URL Filtering Anti-virus Anti-Bot Anti-Spam Content Awareness |
Firewall IPSec VPN Advanced Networking and Clustering Identity Awareness Mobile Access IPS Application Control URL Filtering Anti-Virus Anti-Bot Anti-Spam Content Awareness Threat Emulation Threat Extraction |
Firewall IPSec VPN Advanced Networking and Clustering Identity Awareness Mobile Access IPS Application Control URL Filtering Anti-Virus Anti-Bot Anti-Spam Content Awareness Threat Emulation Threat Extraction |
| Management functions | ─ |
Network Policy Management Logging and Status |
Network Policy Management Logging and Status |
For virtual environments other than those listed above, please contact us.
Security Products
- Next-Generation Firewall
- Targeted Attack Protection
- Cloud Security / Virtualization
- Mobile / Endpoint Security
- Email Security
- Anti-Phishing
(BEC etc.) - Application Security
- Server Security
- Sandbox
- File Sanitization
- Log Analysis
- Server Monitoring
- Encryption
- Security Policy
- Industrial Control System Security
- Connected Car Security
- WAAP
- Browser Security
- Cloud Backup
- SASE
- ASM
- Vulnerability Management
- Security for AI
Next-Generation Firewall Solution that protects Public and Private Cloud Environments
