# AWS CloudFormation Templates

## Solution

**[CloudFormation](https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/Welcome.html)** is an Amazon Web Services (AWS) service that enables modeling and setting up resources in AWS in an automated fashion.

The table below lists CloudFormation templates provided and maintained by Check Point that simplify the deployment of Check Point security solutions in AWS.

You can use these templates as-is or as building blocks for customizing your own templates.

**Notes:**

- You must accept the Software Terms of the relevant Check Point Product AMI in the [AWS Marketplace](https://aws.amazon.com/marketplace/) at least once prior to launching the CloudFormation templates. It is not required to actually launch the instance from the Marketplace, but the agreement must be accepted from this location.

- For R81.20 and higher versions, Gateway Load Balancer (GWLB) and Gateway images are unified. They use **the same** Product AMI in the AWS Marketplace.

- Some stacks may "roll back" automatically after 1 hour with an error: " _WaitCondition timed out_". If this happens, check if the Internet access is working, either through AWS (Internet Gateway (IGW) assigned to the VPC, route tables with a default route and assigned to the relevant subnet(s), and Elastic IP (EIP) assigned), or through another method like an external proxy, or route to on-prem, for example.

- If you want to deploy Check Point security solutions in AWS with **Terraform**, use [this Terraform module](https://registry.terraform.io/modules/CheckPointSW/cloudguard-network-security/aws/latest).

## Cloud Firewall for AWS Gateway Load Balancer Auto Scale Group (for version R81.20 and higher)

| Description | Notes | Terraform Template | CloudFormation Template | Direct Launch |
| --- | --- | --- | --- | --- |
| **Quick-Start Auto Scale Group - New VPC**<br>Creates a new Security VPC with Gateway Load Balancer, Cloud Firewall Gateway Auto Scaling Group, Servers' VPC with Gateway Load Balancer Endpoints (1 per Availability Zone), Application Load Balancer in Servers' VPC, Servers, and optionally a Security Management Server. | Deploys and configures a Quick Start AWS Auto Scaling Group configured for Gateway Load Balancer in a Centralized Security VPC, and Servers in Servers VPC<br>For more details, refer to [Cloud Firewall for AWS Gateway Load Balancer Auto Scaling Group Deployment Guide](https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CloudGuard_Network_for_AWS_Gateway_Load_Balancer_ASG/Default.htm). | -- |  AWS Global](https://cgi-cfts.s3.amazonaws.com/gwlb/qs-gwlb-master.yaml) |  |
| **Quick-Start Auto Scale Group - Existing VPC**<br>Deploys a Gateway Load Balancer, Cloud Firewall Gateway Auto Scaling Group, optionally a Security Management Server into an existing Security VPC, Gateway Load Balancer Endpoints (1 per Availability Zone), Application Load Balancer, and Servers into an existing Servers' VPC. | -- |  AWS Global](https://cgi-cfts.s3.amazonaws.com/gwlb/qs-gwlb.yaml) |  |
| **Auto Scale Group - New Centralized VPC**<br>Creates a new VPC and deploys a Gateway Load Balancer, a Cloud Firewall Gateway Auto Scaling Group, and, optionally, a Security Management Server into it. | Deploys and configures an AWS Auto Scaling group configured for Gateway Load Balancer in a Centralized Security VPC.<br>For more details, refer to [Cloud Firewall for AWS Gateway Load Balancer Auto Scale Group Deployment Guide](https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CloudGuard_Network_for_AWS_Gateway_Load_Balancer_ASG/Default.htm) |  AWS Global](https://registry.terraform.io/modules/checkpointsw/cloudguard-network-security/aws/latest/submodules/gwlb_master)<br> AWS China](https://registry.terraform.io/modules/CheckPointSW/china-cloudguard-network-security/aws/latest/submodules/gwlb_master) |  AWS Global](https://cgi-cfts.s3.amazonaws.com/gwlb/gwlb-master.yaml)<br> AWS China](https://cgns-china-cft.s3.amazonaws.com/gwlb/gwlb-master.yaml) |  |
| **Auto Scale Group - Existing Centralized VPC**<br>Deploys a Gateway Load Balancer, Cloud Firewall Gateway Auto Scaling Group, and optionally a Security Management Server into an existing VPC. | -- |  AWS Global](https://registry.terraform.io/modules/checkpointsw/cloudguard-network-security/aws/latest/submodules/gwlb)<br> AWS China](https://registry.terraform.io/modules/CheckPointSW/china-cloudguard-network-security/aws/latest/submodules/gwlb) |  AWS Global](https://cgi-cfts.s3.amazonaws.com/gwlb/gwlb.yaml)<br> AWS China](https://cgns-china-cft.s3.amazonaws.com/gwlb/gwlb.yaml) |  |
| **IAM Role**<br>Create an IAM role for the Security Management Server managing the Gateway Load Balancer Auto Scale Group instances in your account, preconfigured with all required permissions.<br>For more details, refer to [sk122074](https://support.checkpoint.com/results/sk/sk122074). | Deploy an IAM role for Cloud Firewall for AWS Gateway Load Balancer Auto Scale Group solutions. |  AWS Global](https://registry.terraform.io/modules/checkpointsw/cloudguard-network-security/aws/latest/submodules/cme_iam_role_gwlb)<br> AWS China](https://registry.terraform.io/modules/CheckPointSW/china-cloudguard-network-security/aws/latest/submodules/cme_iam_role_gwlb) |  AWS Global](https://cgi-cfts.s3.amazonaws.com/gwlb/cme-iam-role-gwlb.yaml)<br> AWS China](https://cgns-china-cft.s3.amazonaws.com/gwlb/cme-iam-role-gwlb.yaml) |  |

### Cloud Firewall for AWS Single Gateway (for version R81.10 and higher)

| Description | Notes | Terraform Template | CloudFormation Template | Direct Launch |
| --- | --- | --- | --- | --- |
| **Single Gateway - New VPC**<br>Creates a new VPC and deploys a Security Gateway into it. | Deploys and configures a Security Gateway.<br>To deploy the Security Gateway for automatic provisioning, refer to [sk131434](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk131434). |  AWS Global](https://registry.terraform.io/modules/checkpointsw/cloudguard-network-security/aws/latest/submodules/gateway_master)<br> AWS China](https://registry.terraform.io/modules/CheckPointSW/china-cloudguard-network-security/aws/latest/submodules/gateway_master) |  AWS Global](https://cgi-cfts.s3.amazonaws.com/gateway/gateway-master.yaml)<br> AWS China](https://cgns-china-cft.s3.amazonaws.com/gateway/gateway-master.yaml) |  |
| **Single Gateway - Existing VPC**<br>Deploys a Security Gateway into an existing VPC. | -- |  AWS Global](https://registry.terraform.io/modules/checkpointsw/cloudguard-network-security/aws/latest/submodules/gateway)<br> AWS China](https://registry.terraform.io/modules/CheckPointSW/china-cloudguard-network-security/aws/latest/submodules/gateway) |  AWS Global](https://cgi-cfts.s3.amazonaws.com/gateway/gateway.yaml)<br> AWS China](https://cgns-china-cft.s3.amazonaws.com/gateway/gateway.yaml) |  |

### Cloud Firewall for AWS Cross Availability Zone Cluster (for version R81.20 and higher)

| Description | Notes | Terraform Template | CloudFormation Template | Direct Launch |
| --- | --- | --- | --- | --- |
| **Cross AZ Cluster - New VPC**<br>Creates a new VPC and deploys a Cross Availability Zone Cluster of Security Gateways into it. | Deploys two Security Gateways, each in a different Availability Zone.<br>For more details, refer to [Cloud Firewall for AWS Cross Availability Zone Cluster Deployment Guide](https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CloudGuard_for_AWS_Cross_AZ_Cluster/Default.htm) |  AWS Global](https://registry.terraform.io/modules/CheckPointSW/cloudguard-network-security/aws/latest/submodules/cross_az_cluster_master)<br> AWS China](https://registry.terraform.io/modules/CheckPointSW/china-cloudguard-network-security/aws/latest/submodules/cross_az_cluster_master) |  AWS Global](https://cgi-cfts.s3.amazonaws.com/cluster/cross-az-cluster-master.yaml)<br> AWS China](https://cgns-china-cft.s3.amazonaws.com/cluster/cross-az-cluster-master.yaml) |  |
| **Cross AZ Cluster - Existing VPC**<br>Deploys a Cross Availability Zone Cluster of Security Gateways into an existing VPC. |  AWS Global](https://registry.terraform.io/modules/CheckPointSW/cloudguard-network-security/aws/latest/submodules/cross_az_cluster)<br> AWS China](https://registry.terraform.io/modules/CheckPointSW/china-cloudguard-network-security/aws/latest/submodules/cross_az_cluster) |  AWS Global](https://cgi-cfts.s3.amazonaws.com/cluster/cross-az-cluster.yaml)<br> AWS China](https://cgns-china-cft.s3.amazonaws.com/cluster/cross-az-cluster.yaml) |  |

### Cloud Firewall for AWS Cross Availability Zone Cluster with Transit Gateway (for version R81.20 and higher)

| Description | Notes | Terraform Template | CloudFormation Template | Direct Launch |
| --- | --- | --- | --- | --- |
| **Cross AZ Cluster for Transit Gateway - New VPC**<br>Creates a new VPC and deploys a Cross Availability Zone Cluster of Security Gateways configured for Transit Gateway into it. | Deploys two Security Gateways, each in a different Availability Zone, configured for Transit Gateway. For more details, refer to [Cloud Firewall for AWS Cross Availability Zone Cluster Deployment Guide](https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CloudGuard_for_AWS_Cross_AZ_Cluster/Default.htm) |  AWS Global](https://registry.terraform.io/modules/checkpointsw/cloudguard-network-security/aws/latest/submodules/tgw_cross_az_cluster_master)<br> AWS China](https://registry.terraform.io/modules/CheckPointSW/china-cloudguard-network-security/aws/latest/submodules/tgw_cross_az_cluster_master) |  AWS Global](https://cgi-cfts.s3.amazonaws.com/cluster/tgw-cross-az-cluster-master.yaml)<br> AWS China](https://cgns-china-cft.s3.amazonaws.com/cluster/tgw-cross-az-cluster-master.yaml) |  |
| **Cross AZ Cluster for Transit Gateway - Existing VPC**<br>Deploys a Cross Availability Zone Cluster of Security Gateways configured for Transit Gateway into an existing VPC. |  AWS Global](https://registry.terraform.io/modules/checkpointsw/cloudguard-network-security/aws/latest/submodules/tgw_cross_az_cluster)<br> AWS China](https://registry.terraform.io/modules/CheckPointSW/china-cloudguard-network-security/aws/latest/submodules/tgw_cross_az_cluster) |  AWS Global](https://cgi-cfts.s3.amazonaws.com/cluster/tgw-cross-az-cluster.yaml)<br> AWS China](https://cgns-china-cft.s3.amazonaws.com/cluster/tgw-cross-az-cluster.yaml) |  |

### Cloud Firewall for AWS Single Availability Zone Cluster (for version R81.10 and higher)

| Description | Notes | Terraform Template | CloudFormation Template | Direct Launch |
| --- | --- | --- | --- | --- |
| **Single AZ Cluster - New VPC**<br>Creates a new VPC and deploys a Cluster into it. | Deploys and configures two Security Gateways as a Cluster.<br>For more details, refer to the [Cloud Firewall for AWS Single Availability Zone Cluster Deployment Guide](https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CloudGuard_Network_for_AWS_Single_AZ_Cluster/Default.htm). |  AWS Global](https://registry.terraform.io/modules/CheckPointSW/cloudguard-network-security/aws/latest/submodules/cluster_master)<br> AWS China](https://registry.terraform.io/modules/CheckPointSW/china-cloudguard-network-security/aws/latest/submodules/cluster_master) |  AWS Global](https://cgi-cfts.s3.amazonaws.com/cluster/cluster-master.yaml)<br> AWS China](https://cgns-china-cft.s3.amazonaws.com/cluster/cluster-master.yaml) |  |
| **Single AZ Cluster - Existing VPC**<br>Deploys a Cluster into an existing VPC. | -- |  AWS Global](https://registry.terraform.io/modules/CheckPointSW/cloudguard-network-security/aws/latest/submodules/cluster)<br> AWS China](https://registry.terraform.io/modules/CheckPointSW/china-cloudguard-network-security/aws/latest/submodules/cluster) |  AWS Global](https://cgi-cfts.s3.amazonaws.com/cluster/cluster.yaml)<br> AWS China](https://cgns-china-cft.s3.amazonaws.com/cluster/cluster.yaml) |  |

### Cloud Firewall for AWS Auto Scale Group (for version R81.10 and higher)

| Description | Notes | Terraform Template | CloudFormation Template | Direct Launch |
| --- | --- | --- | --- | --- |
| **Quick-Start Auto Scale Group - New VPC**<br>Creates a new Security VPC with an external Application/Network Load Balancer, Cloud Firewall Gateway, Auto Scaling Group, and optionally a Security Management Server and a web server Auto Scaling Group (with an internal Application/Network Load Balancer). | Deploys and configures a Quick Start AWS Auto Scaling Group, an external ALB/NLB, and optionally a Security Management Server and a web server Auto Scaling Group. <br>For more details, refer to [AWS Quick Start for Check Point Cloud Firewall Auto Scaling](https://aws.amazon.com/quickstart/architecture/check-point-cloudguard/). |  AWS Global](https://registry.terraform.io/modules/CheckPointSW/cloudguard-network-security/aws/latest/examples/qs_autoscale_master)<br> AWS China](https://registry.terraform.io/modules/CheckPointSW/china-cloudguard-network-security/aws/latest/submodules/autoscale_master) |  AWS Global](https://cgi-cfts.s3.amazonaws.com/autoscale/qs-autoscale-master.yaml)<br> AWS China](https://cgns-china-cft.s3.amazonaws.com/autoscale/autoscale-master.yaml) |  |
| **Quick-Start Auto Scale Group - Existing VPC**<br>Deploys an external Application/Network Load Balancer, Cloud Firewall Gateway Auto Scaling Group, and optionally a Security Management Server and a web server Auto Scaling Group (with internal Application/Network Load Balancer) into an existing VPC. | -- |  AWS Global](https://registry.terraform.io/modules/CheckPointSW/cloudguard-network-security/aws/latest/examples/qs_autoscale)<br> AWS China](https://registry.terraform.io/modules/CheckPointSW/china-cloudguard-network-security/aws/latest/submodules/autoscale) |  AWS Global](https://cgi-cfts.s3.amazonaws.com/autoscale/qs-autoscale.yaml)<br> AWS China](https://cgns-china-cft.s3.amazonaws.com/autoscale/autoscale.yaml) |  |
| **Auto Scale Group - New VPC**<br>Deploys an Auto Scaling group of Security Gateways into a new VPC. | Deploys and configures the Security Gateways as an AWS Auto Scaling group.<br>For more details, refer to the [Cloud Firewall for AWS Auto Scale Group Deployment Guide](https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CloudGuard_Network_for_AWS_AutoScaling_DeploymentGuide/Default.htm) |  AWS Global](https://registry.terraform.io/modules/CheckPointSW/cloudguard-network-security/aws/latest/submodules/autoscale_master)<br> AWS China](https://registry.terraform.io/modules/CheckPointSW/china-cloudguard-network-security/aws/latest/submodules/autoscale_master) |  AWS Global](https://cgi-cfts.s3.amazonaws.com/autoscale/autoscale-master.yaml)<br> AWS China](https://cgns-china-cft.s3.amazonaws.com/autoscale/autoscale-master.yaml) |  |
| **Auto Scale Group - Existing VPC**<br>Deploys an Auto Scaling group of Security Gateways into an existing VPC. | -- |  AWS Global](https://registry.terraform.io/modules/CheckPointSW/cloudguard-network-security/aws/latest/submodules/autoscale)<br> AWS China](https://registry.terraform.io/modules/CheckPointSW/china-cloudguard-network-security/aws/latest/submodules/autoscale) |  AWS Global](https://cgi-cfts.s3.amazonaws.com/autoscale/autoscale.yaml)<br> AWS China](https://cgns-china-cft.s3.amazonaws.com/autoscale/autoscale.yaml) |  |

### Cloud Firewall for AWS Security Management Server (for version R81.10 and higher)

| Description | Notes | Terraform Template | CloudFormation Template | Direct Launch |
| --- | --- | --- | --- | --- |
| Deploys a Security Management Server into a **new VPC**. | Deploys and configures a Security Management Server.<br>For more details, refer to [sk130372](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk130372). |  AWS Global](https://registry.terraform.io/modules/CheckPointSW/cloudguard-network-security/aws/latest/submodules/management_master)<br> AWS China](https://registry.terraform.io/modules/CheckPointSW/china-cloudguard-network-security/aws/latest/submodules/management_master) |  AWS Global](https://cgi-cfts.s3.us-east-1.amazonaws.com/management/management-master.yaml)<br> AWS China](https://cgns-china-cft.s3.amazonaws.com/management/management-master.yaml) |  |
| Deploys a Security Management Server into an **existing VPC**. | -- |  AWS Global](https://registry.terraform.io/modules/CheckPointSW/cloudguard-network-security/aws/latest/submodules/management)<br> AWS China](https://registry.terraform.io/modules/CheckPointSW/china-cloudguard-network-security/aws/latest/submodules/management) |  AWS Global](https://cgi-cfts.s3.amazonaws.com/management/management.yaml)<br> AWS China](https://cgns-china-cft.s3.amazonaws.com/management/management.yaml) |  |

### Cloud Firewall for AWS Multi-Domain Management Server (for version R81.10 and higher)

| Description | Notes | Terraform Template | CloudFormation Template | Direct Launch |
| --- | --- | --- | --- | --- |
| Deploys a Multi-Domain Security Management Server into an existing VPC. | Deploys and configures a Multi-Domain Security Management Server.<br>For more details, refer to [sk143213](https://support.checkpoint.com/results/sk/sk143213). |  AWS Global](https://registry.terraform.io/modules/CheckPointSW/cloudguard-network-security/aws/latest/submodules/mds)<br> AWS China](https://registry.terraform.io/modules/CheckPointSW/china-cloudguard-network-security/aws/latest/submodules/mds) |  AWS Global](https://cgi-cfts.s3.amazonaws.com/management/mds.yaml)<br> AWS China](https://cgns-china-cft.s3.amazonaws.com/management/mds.yaml) |  |

### Cloud Firewall for AWS Standalone (for version R81.10 and higher)

| Description | Notes | Terraform Template | CloudFormation Template | Direct Launch |
| --- | --- | --- | --- | --- |
| **AWS Standalone - New VPC**<br>Creates a new VPC and deploys a Standalone or manually configurable instance into it. | Deploys and configures a Standalone or a manually configurable instance. |  AWS Global](https://registry.terraform.io/modules/CheckPointSW/cloudguard-network-security/aws/latest/submodules/standalone_master)<br> AWS China](https://registry.terraform.io/modules/CheckPointSW/china-cloudguard-network-security/aws/latest/submodules/standalone_master) |  AWS Global](https://cgi-cfts.s3.amazonaws.com/gateway/standalone-master.yaml)<br> AWS China](https://cgns-china-cft.s3.amazonaws.com/gateway/standalone-master.yaml) |  |
| **AWS Standalone - Existing VPC**<br>Deploys a Standalone or a manually configurable instance into an existing VPC. | -- |  AWS Global](https://registry.terraform.io/modules/CheckPointSW/cloudguard-network-security/aws/latest/submodules/standalone)<br> AWS China](https://registry.terraform.io/modules/CheckPointSW/china-cloudguard-network-security/aws/latest/submodules/standalone) |  AWS Global](https://cgi-cfts.s3.amazonaws.com/gateway/standalone.yaml)<br> AWS China](https://cgns-china-cft.s3.amazonaws.com/gateway/standalone.yaml) |  |

### Cloud Firewall WAF (formerly AppSec)

| Description | Notes | CloudFormation Template | Direct Launch |
| --- | --- | --- | --- |
| **WAF - New VPC**<br>Creates a new VPC and deploys a CloudGuard Infinity Next Gateway into it. | Deploys and configures a CloudGuard Infinity Next Gateway. | [AWS Marketplace](https://aws.amazon.com/marketplace/pp/prodview-wctbkjip42idi) |  |
| **WAF - Existing VPC**<br>Deploys a CloudGuard Infinity Next Gateway into an existing VPC. | [AWS Marketplace](https://aws.amazon.com/marketplace/pp/prodview-wctbkjip42idi) |  |

### General

| Description | Terraform Template | CloudFormation Template | Direct Launch |
| --- | --- | --- | --- |
| **IAM role for Security Management Server**<br>Creates an IAM role in your account preconfigured with permissions to manage resources.<br>For more details, refer to [sk122074](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk122074). |  AWS Global](https://registry.terraform.io/modules/CheckPointSW/cloudguard-network-security/aws/latest/submodules/cme_iam_role)<br> AWS China](https://registry.terraform.io/modules/CheckPointSW/china-cloudguard-network-security/aws/latest/submodules/cme_iam_role) |  AWS Global](https://cgi-cfts.s3.amazonaws.com/iam/cme-iam-role.yaml)<br> AWS China](https://console.amazonaws.cn/cloudformation/home#/stacks/create/review?templateURL=https://cgns-china-cft.s3.amazonaws.com/iam/cme-iam-role.yaml) |  |
| **Current Check Point AMIs**<br>A helper template that returns the latest Check Point AMIs in a given region. |  AWS Global](https://registry.terraform.io/modules/CheckPointSW/cloudguard-network-security/aws/latest/submodules/amis)<br> AWS China](https://registry.terraform.io/modules/CheckPointSW/china-cloudguard-network-security/aws/latest/submodules/amis) |  AWS Global](https://cgi-cfts.s3.amazonaws.com/utils/amis.yaml)<br> AWS China](https://cgns-china-cft.s3.amazonaws.com/utils/amis.yaml) |  |

**Note:** CloudFormation Templates are often referred to as CFTs by customers and partners.
