sk179464 - Cloud Firewall for AWS - Cloud WAN Overview and Integration
Cloud Firewall for AWS - Cloud WAN Overview and Integration
Product: Cloud Firewall
Version: R81.20, R82
OS: Gaia
Platform: AWS
Last Modified: 2026-03-29
Solution
AWS Cloud WAN and Cloud Firewall Integration Overview
AWS Cloud WAN is a managed wide-area network (WAN) service that simplifies the connection and routing of data centers, remote offices, and cloud applications over the AWS global network. It allows customers to build and manage their WAN using centralized network policies, eliminating the complexity of integrating multiple networking, security, and third-party services.
A key feature of Cloud WAN is Service Insertion, which enhances network security by allowing seamless integration of AWS and third-party services - such as Check Point Cloud Firewall (formerly known as CloudGuard Network) - into the network. This integration is managed centrally via policy documents, making it easy to steer traffic between VPCs or between VPCs and on-premises environments. Policies can be configured with simple statements or through an intuitive UI, enabling rapid deployment and management.
Cloud WAN also provides a centralized control plane for directing traffic across the AWS global infrastructure, supporting geographically distributed use cases with high performance, scalability, and security - all within minutes.
Check Point Cloud Firewall integrates with AWS Cloud WAN via the Service Insertion feature and leverages the existing Gateway Load Balancer (GWLB) integration. This combined solution simplifies and strengthens network security enforcement across AWS environments, particularly in multi-region deployments.
Cloud WAN Feature Details
Cloud WAN is a good selection for customers who want to operate in multiple regions, provide connectivity between sites through AWS's backbone, or prefer AWS-managed routing and automation.
The policy language in Cloud WAN makes it simple to manage security policies between connectivity methods across regions in one declarative document.
Cloud WAN operates primarily on layer 3 (routing) security. Cloud WAN uses policy to send selective traffic through a certain attachment where a firewall is (VPC or TGW Connect) or use attachment-level tags to determine which segment an attachment must map to - new or existing. For Check Point customers, integration with Cloud WAN offers a simpler L3 insertion of firewalls through the Security Insertion feature.
- AWS Network Manager
- Global Network
- Cloud WAN Core Network
- Core Network Edge (CNE)
- Core Network Attachments
- Network Function Group
- Core Network Segments
- Cloud WAN Policy
You can find the latest Cloud WAN documentation HERE
Prerequisites
In-depth knowledge of AWS Cloud WAN design, installation, and configuration
In-depth knowledge of Cloud Firewall's integration with AWS Gateway Load Balancer (GWLB)
Check Point Security Management Server or Smart-1 Cloud (R81.20 or higher)
Supported Versions: R81.20
Licensing: BYOL and PAYG
Supported BYOL SKUs:
- CPSG-VSEC-VEN-BUN-NGTP
- CPSG-VSEC-VEN-BUN-NGTX
Supported traffic flows:
- East/West
- Egress
- Ingress
Deployment Steps
Deploy Cloud Firewall for AWS GWLB CFT in the desired regions in their own VPC ( NOTE: Cloud Firewall is not required to be deployed in every Cloud WAN region).
Create AWS Global Network
Create the Cloud WAN Core Network
Create relevant workload VPCs or note which existing VPCs will participate in the Cloud WAN architecture.
Once the Core Network is in the AVAILABLE state
Create Attachments
- An attachment needs to be created for every VPC in every region (workload and Network Function Group)
- Create Segments
- To enforce security inspection from all sources, make sure to select the Isolated Attachments checkbox:
Create NFG(s)
Add Service Insertion Segment Actions
Associate the attachments to Segments/NFG(s) using Attachment policies
Create and execute the AWS Cloud WAN Policy
Deployment Templates
| Description | Notes | Version | Direct CFT Launch |
| Deploys and configures an AWS Cloud WAN Global Network and an AWS Auto Scaling group configured for Gateway Load Balancer in a Centralized Security VPC for Transit Gateway | This CFT deploys: - An AWS Cloud WAN Global Network and Core Network with 3 segments, basic policy and a Security VPC with Gateway Load Balancer - Cloud Firewall Gateway Auto Scaling Group - An optional Security Management Server - AWS Gateway Load Balancer Endpoints and NAT Gateways for each AZ, in a new VPC for Cloud WAN |
R81.20 R82 |
|
| This CFT deploys: - An AWS Cloud WAN Global Network and Core Network with 3 segments, basic policy and a Gateway Load Balancer - Cloud Firewall Gateway Auto Scaling Group - An optional Security Management Server - AWS Gateway Load Balancer Endpoints, and NAT Gateways for each AZ, in an existing VPC for Cloud WAN |
R81.20 R82 |
Reference Architecture
- Use one security VPC for each region to prevent cross-region charges.
- The region's CGNS GWLB/ASG pool inspects the inbound traffic without traversing through the Cloud WAN segments.
- Outbound traffic egresses from the same region the traffic originated from.
Example Cloud WAN Policy (json format)
{
"version": "2021.12",
"core-network-configuration": {
"vpn-ecmp-support": true,
"asn-ranges": [
"64512-64534"
],
"edge-locations": [
{
"location": "us-east-1"
},
{
"location": "us-west-2"
}
]
},
"segments": [
{
"name": "development",
"require-attachment-acceptance": false,
"isolate-attachments": true
},
{
"name": "production",
"require-attachment-acceptance": false,
"isolate-attachments": true
}
],
"network-function-groups": [
{
"name": "nfgchkp",
"require-attachment-acceptance": false
}
],
"segment-actions": [
{
"action": "send-via",
"segment": "development",
"mode": "single-hop",
"when-sent-to": {
"segments": [
"production"
],
"via": {
"network-function-groups": [
"nfgchkp"
]
}
}
],
"attachment-policies": [
{
"rule-number": 100,
"condition-logic": "or",
"conditions": [
{
"type": "tag-value",
"operator": "equals",
"key": "Name",
"value": "attachment-northern-virginia-nfg"
}
],
"action": {
"add-to-network-function-group": "nfgchkp"
}
}
]
}
Additional Information
- Maximum bandwidth for each VPC attachment: Up to 50 Gbps
- MTU:
- Cloud WAN core network supports an MTU of 8500 bytes for traffic between VPCs.
- Traffic over VPN connections can have an MTU of 1500 bytes.
- Packets larger than 8500 bytes that arrive at the core network are dropped.
- AWS GWLB itself supports packets up to 8500 bytes.