Overview
Video 1
Video 1

Product video
CloudGuard Network Security for AWS delivers advanced, multi-layered network security for the AWS cloud environment and protects cloud assets. Security features include Firewall, IPS, Application Control, IPsec VPN, Antivirus and Anti-Bot, Threat Extraction and Threat Emulation. CloudGuard Network Security enables secure VPN connectivity between AWS and enterprise networks, data centers and secure clients with simplified setup, deployment and management. CloudGuard Network Security includes SSL/TLS traffic inspection with traffic forwarding and SNI support for advanced threat prevention inside secure SSL traffic. The Check Point CloudGuard for AWS Security Blueprint provides best practices for designing a secure cloud-based deployment allowing agility, scalability and efficiency. The blueprint promotes automation of processes using APIs and supports Infrastructure As Code practices. This offering will be deployed as a single "All-In-One" CloudGuard Network Security gateway and Security Management Server via Check Point CloudFormation templates (sk111013) or via automation tools such as Ansible, Terraform, etc. This PAYG distributed security gateway is managed from a central Security Management Server which provides consistent security policy management, enforcement, and reporting within a single pane of glass.
The Security Management Server is included in this "All-In-One" offering; there is no need to choose one of the Check Point Security Management offers.
To maintain the highest quality and security of our management solutions, Check Point recommends installing the latest recommended Jumbo Hotfix, especially after the initial deployment.
Highlights
- Fully integrated and industry-leading advanced threat prevention security features include: Firewall, IPS, Application Control, IPsec VPN, Antivirus and Anti-Bot. Sandblast adds Threat Extraction (removes exploitable content & promptly delivers sanitized content to users) and Threat Emulation (prevents infections from new malware & targeted attacks using threat sandboxing with the best possible catch rate, and is virtually immune to evasion techniques). Includes Security Management Server.
- Provides advanced threat prevention to inspect traffic entering and leaving private subnets in the VPC ("North-South") as well as between VPCs ("East-West"). Designed for the dynamic security requirements of cloud deployments, CloudGuard Network Security is cloud-native: it seamlessly integrates with native AWS controls to enable rapid deployment, while supporting network segmentation, AWS Transit Gateway, auto-scaling and high availability across multiple Availability Zones.
- Check Point is an APN Advanced Technology Partner with Networking and Security Competencies. CloudGuard Network Security is integrated with a broad range of AWS services, including AWS GWLB, AWS Cloud WAN, AWS Outposts, Amazon GuardDuty, Amazon CloudWatch, AWS Security Hub, AWS Transit Gateway, AWS CloudTrail and VPC Flow Logs. CloudGuard Network Security also provides a library of CloudGuard CloudFormation templates (CFTs) to simplify deployment.
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Buyer guide

Financing for AWS Marketplace purchases
Pricing
Free trial
- ...
Dimension | Cost/hour |
|---|---|
c6in.xlarge Recommended | $0.91 |
r5.xlarge | $0.91 |
m8i-flex.16xlarge | $11.50 |
r6i.24xlarge | $15.34 |
m8i.metal-48xl | $48.67 |
m7i-flex.2xlarge | $1.50 |
r6i.4xlarge | $3.00 |
m5.16xlarge | $3.00 |
r5.12xlarge | $8.35 |
m7i-flex.16xlarge | $11.50 |
Vendor refund policy
Terminate the instance at any given time to stop incurring charges.
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
64-bit (x86) Amazon Machine Image (AMI)
Amazon Machine Image (AMI)
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Additional details
Usage instructions
Once the instance is running, connect to it using SSH, set an admin password using: 'set user admin password' followed by 'save config'. Then connect to https://[instance] using Internet Explorer (IE) to finalize the configuration. Notes:
- SSH password authentication is disabled in /etc/ssh/sshd_config
- For information regarding Firefox and Chrome refer to sk121373.
Resources
Support
Vendor support
This offer includes Premium Support. For the full list of included support services visit: https://www.checkpoint.com/support-services/support-plans/ To open a support ticket, you would need to have a Check Point user center account. If you do not have a user center account, you can sign up for one here: https://accounts.checkpoint.com . Need support? Contact us at https://www.checkpoint.com/support-services/contact-support/Â
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Standard contract
Customer reviews
Unified cloud security has simplified multi-cloud protection and has improved policy consistency
What is our primary use case?
I use Check Point CloudGuard Network Security mainly to protect cloud workloads and applications across multi-cloud environments. Day-to-day, I rely on it for managing cloud-based firewalls, enforcing unified security policies across accounts and regions, and continuously monitoring traffic and threat activity to keep our cloud infrastructure secure.
In addition to protecting workloads and managing cloud firewalls, I also use Check Point CloudGuard Network Security to maintain a consistent security posture across multiple cloud providers.
What is most valuable?
The best features Check Point CloudGuard Network Security offers include unified multi-cloud firewall and network security, real-time threat prevention, and automated detection of anomalies, which helped us catch misconfigurations.
The unified multi-cloud firewall feature helps me manage and enforce firewall rules consistently across different cloud providers and accounts. Centralized visibility and monitoring of cloud network activity is another helpful feature of Check Point CloudGuard Network Security that makes compliance audits and security reviews easier.
Check Point CloudGuard Network Security has positively impacted my organization by providing ease of use between different clouds. It has strengthened our overall cloud security posture and reduced the number of configuration-related issues that used to slip through. We have seen fewer unauthorized traffic flows, faster detection of anomalies, and clearer visibility across all cloud environments.
Check Point CloudGuard Network Security is deployed fully in public cloud. It provides unified security management across hybrid clouds. For security operations, this has reduced fragmentation and made it easier to maintain uniform policy across environments. It also shortens investigation time because all logs, events, and traffic insights flow into one place. My team does not have to switch tools or reconcile different rule sets, and this consistency lowers the risk of misconfiguration.
What needs improvement?
Several areas of Check Point CloudGuard Network Security could be improved. The dashboard is comprehensive, but navigating advanced views can take time for administration, so the learning curve is somewhat high. Some automation workflows required additional tuning to work smoothly in complex multi-account setups. Integration with third-party cloud-native tools could also be broader to reduce reliance on custom configuration.
For how long have I used the solution?
I have been using Check Point CloudGuard Network Security for approximately two years.
What do I think about the stability of the solution?
Check Point CloudGuard Network Security is stable.
What do I think about the scalability of the solution?
The scalability of Check Point CloudGuard Network Security is solid.
How are customer service and support?
Customer support for Check Point CloudGuard Network Security is good. I would rate the customer support a solid 10.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
I previously used a mix of native cloud firewalls and FortiGate appliances. I switched because managing multiple tools across different clouds became too time-consuming.
What was our ROI?
I have seen a return on investment with Check Point CloudGuard Network Security. The time saved was significant because now we have everything in the same place. We have fewer false positives, so my coworkers have time to look at other projects.
Which other solutions did I evaluate?
We evaluated solutions such as Palo Alto Prisma Cloud and Fortinet's FortiGate. Compared to them, Check Point CloudGuard Network Security was slightly easier to manage overall. Its unified console and policy management model made setup faster and central control simpler. The trade-off is that Check Point CloudGuard Network Security feels less customizable in deeply complex scenarios.
What other advice do I have?
It has made me more confident overall in secure cloud deployments and migrations. Knowing that the same security controls follow us as we move workloads or spin up new ones removes a lot of stress. We do not have to rebuild policies from scratch or worry about gaps during migrations, which makes cloud projects smoother and faster to roll out.
I utilize Check Point CloudGuard Network Security alongside Harmony Endpoint and a few on-premises Check Point gateways. They all tie back into the same management console, so policies, logs, and threat data flow into one place, making it easier to keep everything consistent.
I would suggest planning your policy structure early and keeping it consistent across accounts to avoid complexity later. I would rate this product an eight out of ten.
