# Cloud Firewall for KVM Virtualization Platforms

**Product:** Cloud Firewall  
**Version:** R81.10 (EOS), R81.20, R82, R82.10  
**Platform:** KVM  
**Last Modified:** 2026-07-02

## Solution

### Overview

This article describes Check Point Cloud Firewall (formerly CloudGuard Network) solutions for KVM Virtualization Platforms. It provides guidance, best practices, and solutions for known issues.

**IMPORTANT:** You can configure KVM in many different ways. The configuration depends on your deployment platform. Check Point recommends testing your scenarios and architecture designs before deploying to production.

Also, it is important to note that our solution is expected to work properly on any KVM environment, **as long as the kernel version is supported by Gaia** (see the supported KVM kernel versions in the [HCL](https://www.checkpoint.com/support-services/hcl/#virtual-machines)), regardless of the exact underlying Linux distribution (RHEL, CentOS, Oracle, Alma Linux, Debian, SUSE, Rocky, etc.).

- **Supported Check Point Versions:** R81.10, R81.20, R82, R82.10
- **Supported KVM Virtualization Platforms:** **Note:** This list is not complete. Other KVM platforms may also work.
  - Red Hat OpenShift Virtualization  
  - Proxmox  
  - Nutanix  
  - OpenStack  
  - HPE VM Essentials  
  - Equinix Network Edge  
  - Megaport Virtual Edge  
  - StackIT  
  - Cisco NFVIS  
  - IBM Cloud  
  - SUSE Harvester  
  - OVHcloud  
  - Native KVM for Red Hat, SUSE, CentOS, Debian Operating Systems
- **Supported Check Point Deployments:**
  - Security Management Server  
  - Multi-Domain Management Server  
  - Multi-Domain Log Server  
  - Single Gateway  
  - High Availability Cluster  
  - Active/Active Cluster
- **Licensing:** BYOL (Bring Your Own License) licensing model is applied.
  - For Security Gateways, the license quantity must equal the total number of cores assigned to all deployed Cloud Firewall Gateways.
    - Available SKUs:
      - CPSG-VSEC-VEN-BUN-NGTP-1Y
      - CPSG-VSEC-VEN-BUN-NGTX-1Y  
  - For Security Management Servers, standard licensing requirements apply.
- **Supported Network Interface Drivers:**
  - VIRTIO  
  - SR-IOV
- **Maximum Physical Interfaces:**
  - 8 physical interfaces
- **Prerequisites:** Before you begin, make sure that you have:
  - Expert knowledge of KVM administration and design  
  - Downloaded the relevant Cloud Firewall qcow2 images (if required)
    - See [sk158292 - Cloud Firewall for Private Cloud images](https://support.checkpoint.com/results/sk/sk158292 "sk158292 - CloudGuard Network Security for Private Cloud images")
- **Limitations:**
  - If your Proxmox host machine uses Intel hardware, and you want to deploy R82.10, you must set the processor type to "host" to avoid a boot loop issue.
