sk184394 - Cloud Firewall for KVM Virtualization Platforms
Cloud Firewall for KVM Virtualization Platforms
Product: Cloud Firewall
Version: R81.10 (EOS), R81.20, R82, R82.10
Platform: KVM
Last Modified: 2026-07-02
Solution
Overview
This article describes Check Point Cloud Firewall (formerly CloudGuard Network) solutions for KVM Virtualization Platforms. It provides guidance, best practices, and solutions for known issues.
IMPORTANT: You can configure KVM in many different ways. The configuration depends on your deployment platform. Check Point recommends testing your scenarios and architecture designs before deploying to production.
Also, it is important to note that our solution is expected to work properly on any KVM environment, as long as the kernel version is supported by Gaia (see the supported KVM kernel versions in the HCL), regardless of the exact underlying Linux distribution (RHEL, CentOS, Oracle, Alma Linux, Debian, SUSE, Rocky, etc.).
- Supported Check Point Versions: R81.10, R81.20, R82, R82.10
- Supported KVM Virtualization Platforms: Note: This list is not complete. Other KVM platforms may also work.
- Red Hat OpenShift Virtualization
- Proxmox
- Nutanix
- OpenStack
- HPE VM Essentials
- Equinix Network Edge
- Megaport Virtual Edge
- StackIT
- Cisco NFVIS
- IBM Cloud
- SUSE Harvester
- OVHcloud
- Native KVM for Red Hat, SUSE, CentOS, Debian Operating Systems
- Supported Check Point Deployments:
- Security Management Server
- Multi-Domain Management Server
- Multi-Domain Log Server
- Single Gateway
- High Availability Cluster
- Active/Active Cluster
- Licensing: BYOL (Bring Your Own License) licensing model is applied.
- For Security Gateways, the license quantity must equal the total number of cores assigned to all deployed Cloud Firewall Gateways.
- Available SKUs:
- CPSG-VSEC-VEN-BUN-NGTP-1Y
- CPSG-VSEC-VEN-BUN-NGTX-1Y
- Available SKUs:
- For Security Management Servers, standard licensing requirements apply.
- For Security Gateways, the license quantity must equal the total number of cores assigned to all deployed Cloud Firewall Gateways.
- Supported Network Interface Drivers:
- VIRTIO
- SR-IOV
- Maximum Physical Interfaces:
- 8 physical interfaces
- Prerequisites: Before you begin, make sure that you have:
- Expert knowledge of KVM administration and design
- Downloaded the relevant Cloud Firewall qcow2 images (if required)
- Limitations:
- If your Proxmox host machine uses Intel hardware, and you want to deploy R82.10, you must set the processor type to "host" to avoid a boot loop issue.