# Cloud Firewall for AWS Auto Scale Group with Transit Gateway Deployment Guide

# Check Point Cloud Firewall for AWS

Check Point Cloud Firewall for [AWS](https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CloudGuard_AWS_AutoScale_with_Transit_Gateway/Content/Topics-AWS-AutoScale-TGW-DG/Introduction.htm#) easily extends comprehensive Threat Prevention security to the AWS cloud and protects assets in the cloud from attacks, and at the same time enables secure connectivity.

Use Cloud Firewall to enforce consistent [Security Policies](https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CloudGuard_AWS_AutoScale_with_Transit_Gateway/Content/Topics-AWS-AutoScale-TGW-DG/Introduction.htm#) across your entire organization. It protects data between the corporate network and the Amazon VPC. Cloud Firewall inspects data that enters and leaves the private subnet in the Amazon VPC to prevent attacks and mitigate data loss or leakage. Cloud Firewall protects services in the public cloud from the most sophisticated threats, unapproved access, and prevents application layer Denial of Service (DoS) attacks.

Check Point Cloud Firewall for AWS meets organizational cloud security needs:

- Automatically deployed tags-based IPsec VPN between AWS Transit Gateway and the security VPC.
- Automatic configuration of AWS VPN Gateways on spoke VPCs. This includes planning of IP addresses to prevent subnet IP address conflicts.
- Next Generation Firewall with [Application Control](https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CloudGuard_AWS_AutoScale_with_Transit_Gateway/Content/Topics-AWS-AutoScale-TGW-DG/Introduction.htm#), Data Awareness, [HTTPS Inspection](https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CloudGuard_AWS_AutoScale_with_Transit_Gateway/Content/Topics-AWS-AutoScale-TGW-DG/Introduction.htm#), NAT, and logging.
- [IPS](https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CloudGuard_AWS_AutoScale_with_Transit_Gateway/Content/Topics-AWS-AutoScale-TGW-DG/Introduction.htm#) and virtual patching of cloud resources.
- [URL Filtering](https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CloudGuard_AWS_AutoScale_with_Transit_Gateway/Content/Topics-AWS-AutoScale-TGW-DG/Introduction.htm#) for Internet-bound traffic.
- [Anti-Bot](https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CloudGuard_AWS_AutoScale_with_Transit_Gateway/Content/Topics-AWS-AutoScale-TGW-DG/Introduction.htm#) and [Anti-Virus](https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CloudGuard_AWS_AutoScale_with_Transit_Gateway/Content/Topics-AWS-AutoScale-TGW-DG/Introduction.htm#), and Zero-day [Threat Emulation](https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CloudGuard_AWS_AutoScale_with_Transit_Gateway/Content/Topics-AWS-AutoScale-TGW-DG/Introduction.htm#) and [Threat Extraction](https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CloudGuard_AWS_AutoScale_with_Transit_Gateway/Content/Topics-AWS-AutoScale-TGW-DG/Introduction.htm#).
- IPsec VPN for VPC-to-VPC, and VPC-to-on-premises connections with optional Direct Connect support.
- High Availability deployment.
- Automated solution deployment with CloudFormation.

|     |     |
| --- | --- |
|  | Note - For the list of supported versions, refer to the [Support Life Cycle Policy](https://www.checkpoint.com/support-services/support-life-cycle-policy). |

## Costs and Licenses

You are responsible for the cost of the AWS services that you use, when you deploy the solution described in this guide.

The AWS CloudFormation template for the Security VPC includes parameters that you can configure. Some of these settings, such as instance type have an effect on the cost of deployment. For estimated costs, see the [AWS pricing calculator](https://calculator.s3.amazonaws.com/index.html).

This Transit VPC - Transit Gateway solution uses Amazon Machine Images (AMIs) from the AWS Marketplace. You must subscribe to Check Point Cloud Firewall in the AWS Marketplace before you start the deployment.

Check Point Cloud Firewall Gateways, Check Point [Security Management Server](https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CloudGuard_AWS_AutoScale_with_Transit_Gateway/Content/Topics-AWS-AutoScale-TGW-DG/Introduction.htm#), and AWS CloudFormation templates described in this guide must have a license. There are two licensing options:

- Pay As You Go (PAYG)
- Bring Your Own License (BYOL)

To buy BYOL licenses, contact [Check Point Sales](https://www.checkpoint.com/about-us/contact-us/).

## Prerequisites

Before you use this solution, make sure you read the AWS terms and services:

- Amazon EC2
- Amazon VPC
- AWS CloudFormation
- AWS IAM
- AWS Transit Gateway

If you are new to AWS, see [Getting Started with AWS](https://aws.amazon.com/getting-started/).

## Architecture

The diagram shows Transit Gateway architecture for Check Point Cloud Firewall AWS - an end-to-end solution, which includes:

- AWS Transit Gateway (TGW) object.
- Spoke (Consumer) VPCs attached to the AWS Transit Gateway.
- Outbound Security VPC with the Cloud Firewall Transit Gateways Auto Scaling Group.
- Automatic provisioning of VPN tunnels.
- BGP routing configuration between the AWS Transit Gateway and the Cloud Firewall Gateways.
- Inbound Security VPC with Cloud Firewall Gateways Auto Scaling Group attached to the AWS Transit Gateway.
- Corporate VPN between on-premises perimeter and the AWS Transit Gateway.

|     |     |
| --- | --- |
|  | Note - Red arrows show the provisioning flow from an on-premises Security [Management Server](https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CloudGuard_AWS_AutoScale_with_Transit_Gateway/Content/Topics-AWS-AutoScale-TGW-DG/Introduction.htm#). |

A Transit Gateway functions as a regional virtual router for traffic that flows between your Virtual Private Clouds (VPC) and VPN connections. A Transit Gateway scales elastically based on the volume of network traffic. Routing through a Transit Gateway operates at Layer 3, where the packets are sent to a specific next-hop attachment, based on their destination IP addresses.

## Use Cases

These are the examples of how you can set up your Transit Gateway architecture

| Architecture | Description |
| --- | --- |
| Transparent proxy | The transparent proxy provides secured proxy services to the spoke VPCs. It is transparent in that the security proxy services are seamless and do not need topological changes to the protected spoke VPCs.<br>With this solution, it is not necessary to have a [Cloud Firewall Gateway](https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CloudGuard_AWS_AutoScale_with_Transit_Gateway/Content/Topics-AWS-AutoScale-TGW-DG/Introduction.htm#) for AWS in each of the spoke VPCs. The solution relies on VPN connections to the central (hub) VPC for Internet-bound connections.<br>DevOps and application owners can use the transparent proxy to deploy solutions in designated VPCs, rely on AWS native security controls only, and have advanced Threat Prevention, Next Generation Firewall, and compliance, seamlessly from the central VPC. |
| Cloud perimeter | The Transit VPC - Security VPC of the Transit Gateway solution, as a cloud perimeter, provides Threat Prevention and Access Control to the spoke VPCs.<br>Each VPC can be deployed in multiple Availability Zones and provide security services to multiple spoke VPCs in the environment.<br>Only the central VPC has access to the Internet, and the spokes are limited to private subnets.<br>All traffic to and from the spoke VPCs is steered through the central VPC.<br>The security controls are concentrated in one central VPC. |
| Hybrid cloud | With a Hybrid cloud setup, you can connect your on-premises and cloud environments, and cloud assets can have secured access to on-premises assets.<br>The connection is set up through a secured VPN connection between your on-premises Cloud Firewall Gateway and a Cloud Firewall Gateway in AWS.<br>You can also implement a secure connection with AWS Direct Connect tunnels.<br>For example, a front-end server in the cloud can connect to an on-premises backend database to retrieve confidential data or business logic.<br>For more information, see [sk120534](https://support.checkpoint.com/results/sk/sk120534). |
| Direct Connect | Direct Connect makes it easy to establish a dedicated network connection from on-premises to AWS.<br>When you use AWS Direct Connect, it is transparent to Check Point Cloud Firewall Gateways.<br>For example, you can connect route and tunnels from Transit Gateways directly to Corporate Gateways.<br>You must configure the Direct Connect manually, when you connect corporate gateways and Transit Gateways.<br>Automation is not supported.<br>For more information, see [sk120534](https://support.checkpoint.com/results/sk/sk120534). |

## VPN Community

A VPN Domain is a collection of internal networks that use VPN Cloud Firewall Gateways to send and receive their traffic. VPN Cloud Firewall Gateways are joined into a VPN Community. A VPN Community is a collection of VPN tunnels and their attributes. Networks from different VPN Domains can communicate safely with each other through VPN tunnels that end at the Cloud Firewall Gateways in the VPN communities.

VPN communities used for this Transit solution are based on a Star topology. In a Star VPN Community, each satellite gateway, an AWS VPN connection represented by an Interoperable Device object, has a VPN tunnel to the central Cloud Firewall Gateway, and through it to other satellite gateways in the Star VPN Community.

Transit solution uses Route Based VPN, where VPN traffic is routed based on the BGP routing settings of the Cloud Firewall Gateway. The Cloud Firewall Gateway uses a VPN Tunnel Interface (VTI) to send the VPN traffic, as if it were a physical interface.

Because of the Route Based VPN, it is not necessary to set a VPN Domain on the Cloud Firewall Gateway. The Transit service creates an empty Group object that is used when you configure the Cloud Firewall Gateway in [SmartConsole](https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CloudGuard_AWS_AutoScale_with_Transit_Gateway/Content/Topics-AWS-AutoScale-TGW-DG/Introduction.htm#). This ensures that Domain Based VPN is not used.

The `config-community.sh` script creates a Star VPN Community with these required settings for Transit:

- Encryption: IKE Security Association Phase 2 enabled, set to Group 2 (1024 bit)
- Tunnel management: One VPN tunnel for each gateway pair enabled
- Shared Secret: Use only Shared Secret for all external members enabled
- Advanced: IKE (Phase 1) set to 480

For information on this script, see [Configuring the VPN Community with the 'config-community.sh' Script](https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CloudGuard_AWS_AutoScale_with_Transit_Gateway/Content/Topics-AWS-AutoScale-TGW-DG/Advanced_Configuration.htm#Configuring-the-VPN-Community-with-the-config-community.sh-Script).

For more information about Check Point VPN solutions, see the [Site to Site VPN Administration Guide](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doShowproductpage&productTab=documents&product=446) for your specific version.

## Security Policy

A Security Policy package is a collection of different types of policies that are enforced after you install the policy on the Cloud Firewall Gateways.

A policy package can have one or more of these policy types:

- Access Control
- Quality of Service ( [QoS](https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CloudGuard_AWS_AutoScale_with_Transit_Gateway/Content/Topics-AWS-AutoScale-TGW-DG/Introduction.htm#))
- Desktop Security
- Threat Prevention

The Standard policy package is the default Security Policy defined in a newly deployed Security Management Server. Each policy package has a default cleanup [rule](https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CloudGuard_AWS_AutoScale_with_Transit_Gateway/Content/Topics-AWS-AutoScale-TGW-DG/Introduction.htm#) that drops all traffic.

When you configure the Check Point Security Management Server with the `autoprov_cfg` utility, specify the name of the Security Policy package to be installed on the Transit Gateways with the "-po" parameter. For the default Security Policy, use the value "Standard" (a capital "S" is required), for this parameter.

If you want to configure more policy packages and install a different policy package on the Cloud Firewall Gateways deployed for the transit solution, then specify the name that you want to give that policy package when you run `autoprov_cfg`. Afterward, create and configure the policy by connecting to your Security Management Server with SmartConsole.

For more information, see [Configuring the Security Management Server with the 'autoprov_cfg' Utility](https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CloudGuard_AWS_AutoScale_with_Transit_Gateway/Content/Topics-AWS-AutoScale-TGW-DG/Advanced_Configuration.htm#Configuring-the-Security-Management-Server-with-the-autoprov_cfg-Utility).

02 July 2026
