AWS | Check Point WAF

Overview

If you are deploying a CloudGuard WAF AppSec Gateway to protect an existing production website, we recommend you also read the HOW-TO guide for this particular deployment.

CloudGuard WAF can be deployed as either a single virtual machine or Auto-Scaling Group in AWS. It acts as a reverse proxy where before / after you can deploy AWS Load Balancers:

When deploying an auto-scaling group, the external load balancer is deployed automatically.

Installation

Follow these steps to deploy CloudGuard WAF in AWS using a supplied CloudFormation Template:

Step 1: AWS Console Log in

Log in to AWS Console and select the relevant region.

Step 2: Activate CloudGuard WAF through the AWS Marketplace (Once per Region)

Search for CloudGuard WAF in AWS Marketplace. During activation, a form with a field to select one of the AWS regions, is shown. Select the region in which you wish to deploy CloudGuard WAF's Gateway.

Step 3: Verify required permissions

Verify that you have the required IAM permissions:

If you want AutoScaling setup:

If you want to store certificates in AWS:

Step 4: Deployment using CloudFormation

Choose one of three deployment options :

VPC Network Configuration

EC2 Instance Configuration

Check Point Settings

Advanced Settings

Auto Scaling Group Settings

Creating the stack in AWS takes about 6-8 minutes. When the CloudGuard WAF EC2 loads it will automatically connect to Check Point, register using the token you provided and fetch your policy. If successful, you will see a green notification bar in this portal with a message that your Agent/Gateway successfully connected.

Troubleshooting Tips