sk111013 - AWS CloudFormation Templates
AWS CloudFormation Templates
Solution
CloudFormation is an Amazon Web Services (AWS) service that enables modeling and setting up resources in AWS in an automated fashion.
The table below lists CloudFormation templates provided and maintained by Check Point that simplify the deployment of Check Point security solutions in AWS.
You can use these templates as-is or as building blocks for customizing your own templates.
Notes:
You must accept the Software Terms of the relevant Check Point Product AMI in the AWS Marketplace at least once prior to launching the CloudFormation templates. It is not required to actually launch the instance from the Marketplace, but the agreement must be accepted from this location.
For R81.20 and higher versions, Gateway Load Balancer (GWLB) and Gateway images are unified. They use the same Product AMI in the AWS Marketplace.
Some stacks may "roll back" automatically after 1 hour with an error: " WaitCondition timed out". If this happens, check if the Internet access is working, either through AWS (Internet Gateway (IGW) assigned to the VPC, route tables with a default route and assigned to the relevant subnet(s), and Elastic IP (EIP) assigned), or through another method like an external proxy, or route to on-prem, for example.
If you want to deploy Check Point security solutions in AWS with Terraform, use this Terraform module.
Cloud Firewall for AWS Gateway Load Balancer Auto Scale Group (for version R81.20 and higher)
| Description | Notes | Terraform Template | CloudFormation Template | Direct Launch |
|---|---|---|---|---|
| Quick-Start Auto Scale Group - New VPC Creates a new Security VPC with Gateway Load Balancer, Cloud Firewall Gateway Auto Scaling Group, Servers' VPC with Gateway Load Balancer Endpoints (1 per Availability Zone), Application Load Balancer in Servers' VPC, Servers, and optionally a Security Management Server. |
Deploys and configures a Quick Start AWS Auto Scaling Group configured for Gateway Load Balancer in a Centralized Security VPC, and Servers in Servers VPC For more details, refer to Cloud Firewall for AWS Gateway Load Balancer Auto Scaling Group Deployment Guide. |
-- | AWS Global](https://cgi-cfts.s3.amazonaws.com/gwlb/qs-gwlb-master.yaml) | |
| Quick-Start Auto Scale Group - Existing VPC Deploys a Gateway Load Balancer, Cloud Firewall Gateway Auto Scaling Group, optionally a Security Management Server into an existing Security VPC, Gateway Load Balancer Endpoints (1 per Availability Zone), Application Load Balancer, and Servers into an existing Servers' VPC. |
-- | AWS Global](https://cgi-cfts.s3.amazonaws.com/gwlb/qs-gwlb.yaml) | ||
| Auto Scale Group - New Centralized VPC Creates a new VPC and deploys a Gateway Load Balancer, a Cloud Firewall Gateway Auto Scaling Group, and, optionally, a Security Management Server into it. |
Deploys and configures an AWS Auto Scaling group configured for Gateway Load Balancer in a Centralized Security VPC. For more details, refer to Cloud Firewall for AWS Gateway Load Balancer Auto Scale Group Deployment Guide |
AWS Global](https://registry.terraform.io/modules/checkpointsw/cloudguard-network-security/aws/latest/submodules/gwlb_master) AWS China](https://registry.terraform.io/modules/CheckPointSW/china-cloudguard-network-security/aws/latest/submodules/gwlb_master) |
AWS Global](https://cgi-cfts.s3.amazonaws.com/gwlb/gwlb-master.yaml) AWS China](https://cgns-china-cft.s3.amazonaws.com/gwlb/gwlb-master.yaml) |
|
| Auto Scale Group - Existing Centralized VPC Deploys a Gateway Load Balancer, Cloud Firewall Gateway Auto Scaling Group, and optionally a Security Management Server into an existing VPC. |
-- | AWS Global](https://registry.terraform.io/modules/checkpointsw/cloudguard-network-security/aws/latest/submodules/gwlb) AWS China](https://registry.terraform.io/modules/CheckPointSW/china-cloudguard-network-security/aws/latest/submodules/gwlb) |
AWS Global](https://cgi-cfts.s3.amazonaws.com/gwlb/gwlb.yaml) AWS China](https://cgns-china-cft.s3.amazonaws.com/gwlb/gwlb.yaml) |
|
| IAM Role Create an IAM role for the Security Management Server managing the Gateway Load Balancer Auto Scale Group instances in your account, preconfigured with all required permissions. For more details, refer to sk122074. |
Deploy an IAM role for Cloud Firewall for AWS Gateway Load Balancer Auto Scale Group solutions. | AWS Global](https://registry.terraform.io/modules/checkpointsw/cloudguard-network-security/aws/latest/submodules/cme_iam_role_gwlb) AWS China](https://registry.terraform.io/modules/CheckPointSW/china-cloudguard-network-security/aws/latest/submodules/cme_iam_role_gwlb) |
AWS Global](https://cgi-cfts.s3.amazonaws.com/gwlb/cme-iam-role-gwlb.yaml) AWS China](https://cgns-china-cft.s3.amazonaws.com/gwlb/cme-iam-role-gwlb.yaml) |
Cloud Firewall for AWS Single Gateway (for version R81.10 and higher)
Cloud Firewall for AWS Cross Availability Zone Cluster (for version R81.20 and higher)
Cloud Firewall for AWS Cross Availability Zone Cluster with Transit Gateway (for version R81.20 and higher)
Cloud Firewall for AWS Single Availability Zone Cluster (for version R81.10 and higher)
Cloud Firewall for AWS Auto Scale Group (for version R81.10 and higher)
Cloud Firewall for AWS Security Management Server (for version R81.10 and higher)
Cloud Firewall for AWS Multi-Domain Management Server (for version R81.10 and higher)
| Description | Notes | Terraform Template | CloudFormation Template | Direct Launch |
|---|---|---|---|---|
| Deploys a Multi-Domain Security Management Server into an existing VPC. | Deploys and configures a Multi-Domain Security Management Server. For more details, refer to sk143213. |
AWS Global](https://registry.terraform.io/modules/CheckPointSW/cloudguard-network-security/aws/latest/submodules/mds) AWS China](https://registry.terraform.io/modules/CheckPointSW/china-cloudguard-network-security/aws/latest/submodules/mds) |
AWS Global](https://cgi-cfts.s3.amazonaws.com/management/mds.yaml) AWS China](https://cgns-china-cft.s3.amazonaws.com/management/mds.yaml) |
Cloud Firewall for AWS Standalone (for version R81.10 and higher)
Cloud Firewall WAF (formerly AppSec)
| Description | Notes | CloudFormation Template | Direct Launch |
|---|---|---|---|
| WAF - New VPC Creates a new VPC and deploys a CloudGuard Infinity Next Gateway into it. |
Deploys and configures a CloudGuard Infinity Next Gateway. | AWS Marketplace | |
| WAF - Existing VPC Deploys a CloudGuard Infinity Next Gateway into an existing VPC. |
AWS Marketplace |
General
Note: CloudFormation Templates are often referred to as CFTs by customers and partners.