# Cloud Firewall for AWS - Cloud WAN Overview and Integration

**Product:** Cloud Firewall  
**Version:** R81.20, R82  
**OS:** Gaia  
**Platform:** AWS  
**Last Modified:** 2026-03-29

## Solution

### AWS Cloud WAN and Cloud Firewall Integration Overview

AWS Cloud WAN is a managed wide-area network (WAN) service that simplifies the connection and routing of data centers, remote offices, and cloud applications over the AWS global network. It allows customers to build and manage their WAN using centralized network policies, eliminating the complexity of integrating multiple networking, security, and third-party services.

A key feature of Cloud WAN is Service Insertion, which enhances network security by allowing seamless integration of AWS and third-party services - such as Check Point Cloud Firewall (formerly known as CloudGuard Network) - into the network. This integration is managed centrally via policy documents, making it easy to steer traffic between VPCs or between VPCs and on-premises environments. Policies can be configured with simple statements or through an intuitive UI, enabling rapid deployment and management.

Cloud WAN also provides a centralized control plane for directing traffic across the AWS global infrastructure, supporting geographically distributed use cases with high performance, scalability, and security - all within minutes.

Check Point Cloud Firewall integrates with AWS Cloud WAN via the Service Insertion feature and leverages the existing Gateway Load Balancer (GWLB) integration. This combined solution simplifies and strengthens network security enforcement across AWS environments, particularly in multi-region deployments.

### Cloud WAN Feature Details

Cloud WAN is a good selection for customers who want to operate in multiple regions, provide connectivity between sites through AWS's backbone, or prefer AWS-managed routing and automation.

The policy language in Cloud WAN makes it simple to manage security policies between connectivity methods across regions in one declarative document.

Cloud WAN operates primarily on layer 3 (routing) security. Cloud WAN uses policy to send selective traffic through a certain attachment where a firewall is (VPC or TGW Connect) or use attachment-level tags to determine which segment an attachment must map to - new or existing. For Check Point customers, integration with Cloud WAN offers a simpler L3 insertion of firewalls through the Security Insertion feature.

- **AWS Network Manager**  
- **Global Network**  
- **Cloud WAN Core Network**  
- **Core Network Edge (CNE)**  
- **Core Network Attachments**  
- **Network Function Group**  
- **Core Network Segments**  
- **Cloud WAN Policy**

You can find the latest **_Cloud WAN documentation_** **[HERE](https://docs.aws.amazon.com/vpc/latest/cloudwan/what-is-cloudwan.html)**

### Prerequisites

- **In-depth knowledge of AWS Cloud WAN** design, installation, and configuration
- **In-depth knowledge of Cloud Firewall's integration with AWS Gateway Load Balancer (GWLB)**
- **Check Point Security Management Server** or **Smart-1 Cloud** (R81.20 or higher)
- **Supported Versions:** [R81.20](https://support.checkpoint.com/results/sk/sk173903)
- **Licensing:**  BYOL and PAYG

- Supported BYOL SKUs:
    - CPSG-VSEC-VEN-BUN-NGTP
    - CPSG-VSEC-VEN-BUN-NGTX
- **Supported traffic flows:**
  - East/West
  - Egress
  - Ingress

### Deployment Steps

01. **Deploy Cloud Firewall for AWS GWLB CFT** in the desired regions in their own VPC ( **NOTE:** Cloud Firewall is _not_ required to be deployed in every Cloud WAN region).

02. **Create AWS Global Network**

03. **Create the Cloud WAN Core Network**

04. **Create relevant workload VPCs** or note which existing VPCs will participate in the Cloud WAN architecture.

05. Once the Core Network is in the **AVAILABLE** state

06. **Create Attachments**  
   - An attachment needs to be created for every VPC in every region (workload and Network Function Group)
   
07. **Create Segments**  
   - To enforce security inspection from all sources, make sure to select the **Isolated Attachments** checkbox:

08. **Create NFG(s)**

09. **Add Service Insertion Segment Actions**

10. **Associate the attachments to Segments/NFG(s) using Attachment policies**

11. **Create and execute the AWS Cloud WAN Policy**

### Deployment Templates

|     |     |     |     |
| --- | --- | --- | --- |
| **Description** | **Notes** | **Version** | **Direct CFT Launch** |
| **Deploys and configures an AWS Cloud WAN Global Network and an AWS Auto Scaling group configured for Gateway Load Balancer in a Centralized Security VPC for Transit Gateway** | **This CFT deploys:**<br>- An AWS Cloud WAN Global Network and Core Network with 3 segments, basic policy and a Security VPC with Gateway Load Balancer<br>- Cloud Firewall Gateway Auto Scaling Group<br>- An optional Security Management Server<br>- AWS Gateway Load Balancer Endpoints and NAT Gateways for each AZ, in a **new** VPC for Cloud WAN | R81.20<br>R82 |  |
| **This CFT deploys:**<br>- An AWS Cloud WAN Global Network and Core Network with 3 segments, basic policy and a Gateway Load Balancer<br>- Cloud Firewall Gateway Auto Scaling Group<br>- An optional Security Management Server<br>- AWS Gateway Load Balancer Endpoints, and NAT Gateways for each AZ, in an **existing** VPC for Cloud WAN | R81.20<br>R82 |  |

### Reference Architecture

- Use one security VPC for each region to prevent cross-region charges.
- The region's CGNS GWLB/ASG pool inspects the inbound traffic without traversing through the Cloud WAN segments.
- Outbound traffic egresses from the same region the traffic originated from.

### Example Cloud WAN Policy (json format)
```json
{
"version": "2021.12",
"core-network-configuration": {
    "vpn-ecmp-support": true,
    "asn-ranges": [
      "64512-64534"
    ],
    "edge-locations": [
      {
        "location": "us-east-1"
      },
      {
        "location": "us-west-2"
      }
    ]
},
"segments": [
    {
      "name": "development",
      "require-attachment-acceptance": false,
      "isolate-attachments": true
    },
    {
      "name": "production",
      "require-attachment-acceptance": false,
      "isolate-attachments": true
    }
],
"network-function-groups": [
    {
      "name": "nfgchkp",
      "require-attachment-acceptance": false
    }
],
"segment-actions": [
    {
      "action": "send-via",
      "segment": "development",
      "mode": "single-hop",
      "when-sent-to": {
        "segments": [
          "production"
        ],
        "via": {
          "network-function-groups": [
            "nfgchkp"
          ]
        }
    }
],
"attachment-policies": [
    {
      "rule-number": 100,
      "condition-logic": "or",
      "conditions": [
        {
          "type": "tag-value",
          "operator": "equals",
          "key": "Name",
          "value": "attachment-northern-virginia-nfg"
        }
      ],
      "action": {
        "add-to-network-function-group": "nfgchkp"
      }
    }
]
}
```

### Additional Information

- Maximum bandwidth for each VPC attachment: Up to **50 Gbps**
- MTU:
  - Cloud WAN core network supports an MTU of **8500 bytes** for traffic between VPCs.
  - Traffic over VPN connections can have an MTU of **1500 bytes**.
  - Packets larger than 8500 bytes that arrive at the core network are dropped.
  - AWS GWLB itself supports packets up to **8500 bytes**.
