sk170334 - How to deploy Check Point CloudGuard on AWS Outposts

How to deploy Check Point CloudGuard on AWS Outposts

Product: CloudGuard Network for AWS
Version: R82
OS: Gaia
Platform: AWS
Last Modified: 2025-04-29

Solution

AWS Outposts is a fully managed service offering the same AWS infrastructure, AWS services, APIs, and tools to virtually any datacenter, co-location space, or on-premises facility for a truly consistent hybrid experience.

Customers who require the latest in next-generation security features while using Outposts can now deploy Check Point's CloudGuard Network Security and/or CloudGuard Network Security Managers on AWS Outposts to complement their deployments in AWS regions or on-premises.

The solution brief below describes how to deploy Check Point CloudGuard on Outposts including a reference architecture and support information.

Notes

Known Limitations

Prerequisites

Supported Use Cases

North/South (ingress/egress) next generation traffic inspection between subnets in an Outpost VPC and:

Reference Architecture

Deploy and configure CloudGuard in AWS Outposts

  1. Deploy a Single CloudGuard Gateway or CloudGuard Security Cluster using the CloudFormation templates available in sk111013.

  2. For a single CloudGuard Gateway use CFT # 2: “Deploys a Security Gateway into an existing VPC”.

    1. For a CloudGuard HA Security cluster, use CFT # 4: “Deploys a Cluster into an existing VPC”.
  3. Specify a stack name and parameters:

    1. VPC Network Configuration:
      • Choose the VPC, Public (external) subnet, and Private (internal) subnet created in the prerequisites.
      • Cluster deployment Only: Specify IP addresses for each Security Gateway, including cluster IP’s if you are deploying a Security Cluster.
    2. EC2 Instance Configuration:
      • Choose from the available instance types according to bandwidth and feature requirements.
        • Check Point Recommends c5.xlarge.
      • Select an EC2 key pair to use for ssh access to the instance(s).
        • SSH login uses the following username: admin instead of ec2-user.
      • Leave the root volume size.
      • Specify the customer managed key for EBS volume encryption or leave as is for the default AWS key.
    3. Check Point Settings:
      • Choose a version and license per your requirements.
        • Check Point Recommends R80.40.
      • Admin Shell: use the default /etc/cli.sh.
      • SIC Key: provide a OTP for SIC establishment with Check Point Manager.
      • Optionally:
        • Provide a password for admin login to the Gateways.
        • Allow automatic information sharing with Check Point License center to improve product experience.
        • Specify NTP servers.
        • Provide Automatic Provisioning with Security Management Server (SMS).
  4. Check the Capabilities to acknowledge creation of IAM resources with custom names and Auto Expand, and click Create Stack to deploy the Gateways.

  5. Cluster deployment only: Continue with CloudGuard Cluster configuration as outlined in the Check Point Cluster Deployment Guide.

Deploy Check Point Security Management Server (SMS) on Outposts

  1. Deploy a Security Management Server (SMS) or Multi-Domain SMS via the CloudFormation templates provided in sk111013.

  2. For an SMS Server, use template # 16: “Security Management Server” and refer to sk130372 for details.

    1. For Multi-Domain SMS, use template # 17: “Multi-Domain Security Management Server” and refer to sk143213 for details.
  3. Specify a stack name and Parameters and click Create Stack.

Support for Check Point CloudGuard Security Gateways or SMS on Outpost

For advanced scenarios beyond the solution described in this article, reach out to your AWS Solutions Architect/Partner Team, your Check Point Account Team, and/or contact Check Point Support.

To get support for an existing Check Point Deployment on Outposts, open a Service Request.

Article Properties

Access Level: General
Status: Approved
Date Created: 2020-11-10
Last Modified: 2025-04-29