- Products
- Learn
- Local User Groups
- Partners
- More
What's New in R82.10?
Watch HereWhen the Agents Attack
A Live Look at Agentic Exposure Validation
AI Security Masters E8:
Claude Mythos: New Era in Cyber Security
CheckMates Go:
CheckMates Fest
Hi Checkmates,
We are currently redesigning cloud security adoption on AWS, especially in the area of network security.
From the architecture blueprint owned by Check Point and adapting it to the internal design, we see that there are 2 potential designs that we can use:
CloudGuard Network for AWS Auto Scale Group with Transit Gateway and CloudGuard Network for AWS Cross Availability Zone Cluster with Transit Gateway, because we use TGW to connect from Direct Connect and 2 VPCs.
After reading the admin guide, I am still unsure which of the two designs above is suitable for our needs.
Do you guys have any suggestions from Checkmates regarding which design is suitable for us? and what is the difference between the two?
Our situation :
Thanks! 🙂
The recommended solution for E/W and N/S is Gateway Load Balancer Autoscaling.
Admin guide: https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CloudGuard_Network_for_A...
Workshop:
https://unrivaled-melba-1a81a6.netlify.app/
In case Site to Site VPN is required the Cross AZ Cluster should be added to architecture.
Thanks,
Roman
The main difference between Cross-AZ Cluster and AutoScale is VPN.
If you require the CloudGuard Gateways to act as a VPN termination device, then Cross-AZ Cluster is the way to go.
Otherwise, the AutoScale solution would be recommended.
For a comparison of Public Cloud solutions, please see sk178668
Hi @avivs
Thank you for the answer and suggestions.. CMIIW, means both can be used to protect N/S and E/S traffic, right? and the most obvious difference is only from the VPN side?
More details about your specific requirements and what you're trying to achieve might help.
Hi PhoneBoy,
Sorry if my question is not clear enough. The goals is protecting for E/W and N/S traffic that passes through the transit gateway from public, internal via DX.
I see there are 2 suitable solutions as per my post, but I'm looking for which option is the best.
The recommended solution for E/W and N/S is Gateway Load Balancer Autoscaling.
Admin guide: https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CloudGuard_Network_for_A...
Workshop:
https://unrivaled-melba-1a81a6.netlify.app/
In case Site to Site VPN is required the Cross AZ Cluster should be added to architecture.
Thanks,
Roman
In place of the unrivaled melba link above please use this one > https://checkpoint.awsworkshop.io/
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 2 | |
| 2 | |
| 2 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 |
Thu 02 Jul 2026 @ 06:00 PM (CST)
Revolucionando la Seguridad con IA Generativa: Prevención Inteligente en Tiempo RealThu 09 Jul 2026 @ 10:00 AM (CEST)
Schutz souveräner Workloads: Check Point & die AWS European Sovereign CloudThu 09 Jul 2026 @ 11:00 AM (CEST)
The Cloud Architects Series: Check Point Edge Protection SD-WAN & SASETue 14 Jul 2026 @ 10:00 AM (PDT)
AI Security Masters E11: READY OR NOT: Securing the AI Enterprise 3/5 - AI Workforce SecurityThu 30 Jul 2026 @ 10:00 AM (PDT)
AI Security Masters E12: READY OR NOT: Securing the AI Enterprise 4/5 - AI GatewayThu 20 Aug 2026 @ 10:00 AM (PDT)
AI Security Masters E13: READY OR NOT: Securing the AI Ent 5/5 - AI Research & Threat LandscapeTue 14 Jul 2026 @ 10:00 AM (PDT)
AI Security Masters E11: READY OR NOT: Securing the AI Enterprise 3/5 - AI Workforce SecurityThu 30 Jul 2026 @ 10:00 AM (PDT)
AI Security Masters E12: READY OR NOT: Securing the AI Enterprise 4/5 - AI GatewayThu 20 Aug 2026 @ 10:00 AM (PDT)
AI Security Masters E13: READY OR NOT: Securing the AI Ent 5/5 - AI Research & Threat LandscapeThu 02 Jul 2026 @ 06:00 PM (CST)
Revolucionando la Seguridad con IA Generativa: Prevención Inteligente en Tiempo RealAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY