sk179464 - Cloud Firewall for AWS - Cloud WAN Overview and Integration

Cloud Firewall for AWS - Cloud WAN Overview and Integration

Product: Cloud Firewall
Version: R81.20, R82
OS: Gaia
Platform: AWS
Last Modified: 2026-03-29

Solution

AWS Cloud WAN and Cloud Firewall Integration Overview

AWS Cloud WAN is a managed wide-area network (WAN) service that simplifies the connection and routing of data centers, remote offices, and cloud applications over the AWS global network. It allows customers to build and manage their WAN using centralized network policies, eliminating the complexity of integrating multiple networking, security, and third-party services.

A key feature of Cloud WAN is Service Insertion, which enhances network security by allowing seamless integration of AWS and third-party services - such as Check Point Cloud Firewall (formerly known as CloudGuard Network) - into the network. This integration is managed centrally via policy documents, making it easy to steer traffic between VPCs or between VPCs and on-premises environments. Policies can be configured with simple statements or through an intuitive UI, enabling rapid deployment and management.

Cloud WAN also provides a centralized control plane for directing traffic across the AWS global infrastructure, supporting geographically distributed use cases with high performance, scalability, and security - all within minutes.

Check Point Cloud Firewall integrates with AWS Cloud WAN via the Service Insertion feature and leverages the existing Gateway Load Balancer (GWLB) integration. This combined solution simplifies and strengthens network security enforcement across AWS environments, particularly in multi-region deployments.

Cloud WAN Feature Details

Cloud WAN is a good selection for customers who want to operate in multiple regions, provide connectivity between sites through AWS's backbone, or prefer AWS-managed routing and automation.

The policy language in Cloud WAN makes it simple to manage security policies between connectivity methods across regions in one declarative document.

Cloud WAN operates primarily on layer 3 (routing) security. Cloud WAN uses policy to send selective traffic through a certain attachment where a firewall is (VPC or TGW Connect) or use attachment-level tags to determine which segment an attachment must map to - new or existing. For Check Point customers, integration with Cloud WAN offers a simpler L3 insertion of firewalls through the Security Insertion feature.

You can find the latest Cloud WAN documentation HERE

Prerequisites

Deployment Steps

  1. Deploy Cloud Firewall for AWS GWLB CFT in the desired regions in their own VPC ( NOTE: Cloud Firewall is not required to be deployed in every Cloud WAN region).

  2. Create AWS Global Network

  3. Create the Cloud WAN Core Network

  4. Create relevant workload VPCs or note which existing VPCs will participate in the Cloud WAN architecture.

  5. Once the Core Network is in the AVAILABLE state

  6. Create Attachments

  1. Create Segments
  1. Create NFG(s)

  2. Add Service Insertion Segment Actions

  3. Associate the attachments to Segments/NFG(s) using Attachment policies

  4. Create and execute the AWS Cloud WAN Policy

Deployment Templates

Description Notes Version Direct CFT Launch
Deploys and configures an AWS Cloud WAN Global Network and an AWS Auto Scaling group configured for Gateway Load Balancer in a Centralized Security VPC for Transit Gateway This CFT deploys:
- An AWS Cloud WAN Global Network and Core Network with 3 segments, basic policy and a Security VPC with Gateway Load Balancer
- Cloud Firewall Gateway Auto Scaling Group
- An optional Security Management Server
- AWS Gateway Load Balancer Endpoints and NAT Gateways for each AZ, in a new VPC for Cloud WAN
R81.20
R82
This CFT deploys:
- An AWS Cloud WAN Global Network and Core Network with 3 segments, basic policy and a Gateway Load Balancer
- Cloud Firewall Gateway Auto Scaling Group
- An optional Security Management Server
- AWS Gateway Load Balancer Endpoints, and NAT Gateways for each AZ, in an existing VPC for Cloud WAN
R81.20
R82

Reference Architecture

Example Cloud WAN Policy (json format)

{
"version": "2021.12",
"core-network-configuration": {
    "vpn-ecmp-support": true,
    "asn-ranges": [
      "64512-64534"
    ],
    "edge-locations": [
      {
        "location": "us-east-1"
      },
      {
        "location": "us-west-2"
      }
    ]
},
"segments": [
    {
      "name": "development",
      "require-attachment-acceptance": false,
      "isolate-attachments": true
    },
    {
      "name": "production",
      "require-attachment-acceptance": false,
      "isolate-attachments": true
    }
],
"network-function-groups": [
    {
      "name": "nfgchkp",
      "require-attachment-acceptance": false
    }
],
"segment-actions": [
    {
      "action": "send-via",
      "segment": "development",
      "mode": "single-hop",
      "when-sent-to": {
        "segments": [
          "production"
        ],
        "via": {
          "network-function-groups": [
            "nfgchkp"
          ]
        }
    }
],
"attachment-policies": [
    {
      "rule-number": 100,
      "condition-logic": "or",
      "conditions": [
        {
          "type": "tag-value",
          "operator": "equals",
          "key": "Name",
          "value": "attachment-northern-virginia-nfg"
        }
      ],
      "action": {
        "add-to-network-function-group": "nfgchkp"
      }
    }
]
}

Additional Information