Security Products

Next-Generation Firewall Solution that protects Public and Private Cloud Environments Check Point Cloud Firewall

As the term “cloud-first” suggests, many corporate IT departments are implementing or considering the development of new systems and the migration of existing on-premises systems to private and public cloud environments.
Check Point Cloud Firewall from Check Point is a next-generation firewall solution designed to operate in virtualized and cloud environments. It uses the same architecture as Check Point’s on-premises gateways and provides multi-layered protection as a virtual appliance.

Features of Check Point Cloud Firewall

  1. Public Cloud Security
    • Comprehensive Cloud Protection Powered by Software Blade Architecture
      Check Point Cloud Firewall for Public Cloud enables organizations to secure servers and networks operating on platforms such as Amazon Web Services and Microsoft Azure.
      This virtual appliance (a security gateway for virtualized environments) is designed for seamless deployment. It safeguards network connectivity within dynamic cloud computing environments, effectively preventing sophisticated attacks and data breaches.
    • Inter-VM Traffic Inspection
      With finely tunable Check Point firewall policies and industry-leading intrusion prevention capabilities, all traffic flowing between virtual machines—both internal and external—is inspected to protect the virtual machines. It secures virtual applications from external threats and enables isolation between them. Real-time updates keep your defenses always up to date.
    • Unified management of physical and virtual environments
      As with other Check Point security appliances, physical and virtual environments can be centrally managed using Check Point management products.
      This ensures consistent security across all gateways while minimizing the cost associated with management consoles.

    <Differences Between Host-Based security and Gateway-based Security (Check Point Cloud Firewall) in Public Cloud Environments>
    The Difference Between Host-Based Security and Gateway-Based Security
  2. Private Cloud Security
    • Comprehensive Cloud Protection with Software Blades
      Check Point Cloud Firewall for private cloud security combines microsegmentation with network virtualization platforms that provide built-in network isolation and segmentation capabilities, delivering advanced protection for east-west traffic within the data center. No configuration of VLANs, ACLs, firewall rules, physical firewalls, or routers is required.
    • Multi-Layered Protection in a Single Virtual Appliance
      A single security function is not sufficient to defend against sophisticated attacks such as zero-day targeted attacks. Multiple security capabilities must be combined to block threats through multi-layered protection. Check Point Cloud Firewall integrates the security capabilities required to protect against zero-day targeted attacks into a single virtual appliance, including malware protection with Antivirus, Threat Emulation, and Threat Extraction; protection against attacks that exploit vulnerabilities with IPS; and data leakage prevention with Anti-Bot. This multi-layered approach reduces the cost and operational effort associated with deploying and managing multiple security functions, while enabling advanced security capabilities to be delivered through a single solution.
    • Seamless Advanced Security
      Check Point security gateway appliances are coded using Intel CPU instructions without relying on ASICs, enabling high performance in virtualized and cloud environments. Enterprise-level throughput can be achieved with as few as 2 vCPUs, helping reduce operating costs in cloud environments. If higher throughput is required, performance can be increased by adding more vCPUs.

Product Lineup

  Private cloud Public cloud
Product lineup for VMware NSX for VMware ESXi for Amazon Web Services
for Microsoft Azure
License counting Per physical CPU Per virtual CPU Per virtual CPU
Security functions Firewall
IPsec VPN
Identity Awareness
IPS
Application Control
URL Filtering
Anti-virus
Anti-Bot
Anti-Spam
Content Awareness
Firewall
IPSec VPN
Advanced Networking and Clustering
Identity Awareness
Mobile Access
IPS
Application Control
URL Filtering
Anti-Virus
Anti-Bot
Anti-Spam
Content Awareness
Threat Emulation
Threat Extraction
Firewall
IPSec VPN
Advanced Networking and Clustering
Identity Awareness
Mobile Access
IPS
Application Control
URL Filtering
Anti-Virus
Anti-Bot
Anti-Spam
Content Awareness
Threat Emulation
Threat Extraction
Management functions ─ Network Policy Management
Logging and Status
Network Policy Management
Logging and Status

For virtual environments other than those listed above, please contact us.