> Source: [sk111013](https://support.checkpoint.com/results/sk/sk111013)

# sk111013 - AWS CloudFormation Templates 

| Property | Value |
|----------|-------|
| Solution ID | sk111013 |
| Date Created | 2016-04-14 |
| Last Modified | 2026-08-18 |
| Technical Level | General |
| Products | Cloud Firewall |
| Versions | R82.10, R81.10 (EOS), R81.20, R82 |
| OS | Gaia |
| Platform | AWS |

## Solution

**[CloudFormation](https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/Welcome.html)**is an Amazon Web Services (AWS) service that enables modeling and setting up resources in AWS in an automated fashion.

The table below lists CloudFormation templates provided and maintained by Check Point that simplify the deployment of Check Point security solutions in AWS.

You can use these templates as-is or as building blocks for customizing your own templates.

**Notes:**

* You must accept the Software Terms of the relevant Check Point Product AMI in the [AWS Marketplace](https://aws.amazon.com/marketplace/) at least once prior to launching the CloudFormation templates. It is not required to actually launch the instance from the Marketplace, but the agreement must be accepted from this location.

* For R81.20 and higher versions, Gateway Load Balancer (GWLB) and Gateway images are unified. They use **the same** Product AMI in the AWS Marketplace.

* Some stacks may "roll back" automatically after 1 hour with an error: "*WaitCondition timed out*". If this happens, check if the Internet access is working, either through AWS (Internet Gateway (IGW) assigned to the VPC, route tables with a default route and assigned to the relevant subnet(s), and Elastic IP (EIP) assigned), or through another method like an external proxy, or route to on-prem, for example.

* If you want to deploy Check Point security solutions in AWS with **Terraform** , use [this Terraform module](https://registry.terraform.io/modules/CheckPointSW/cloudguard-network-security/aws/latest).

**Related solution:** [sk179464 - Cloud Firewall for AWS - Cloud WAN Overview and Integration](https://support.checkpoint.com/results/sk/sk179464)**Table of Contents**  
Click Here to Show the Entire Content

  * Cloud Firewall for AWS Gateway Load Balancer Auto Scale Group  
  (Show / Hide this section)  
  * Auto Scale Group - New Centralized VPC
  * Auto Scale Group - Existing Centralized VPC
  * IAM Role
  * Cloud Firewall for AWS Gateway Load Balancer Auto Scale Group with Transit Gateway  
  (Show / Hide this section)  
  * Auto Scale Group - New Centralized VPC for Transit Gateway
  * Auto Scale Group - Existing Centralized VPC for Transit Gateway
  * Cloud Firewall for AWS Single Gateway  
  (Show / Hide this section)  
  * Single Gateway - New VPC
  * Single Gateway - Existing VPC
  * Cloud Firewall for AWS Cross Availability Zone Cluster  
  (Show / Hide this section)  
  * Cross AZ Cluster - New VPC
  * Cross AZ Cluster - Existing VPC
  * Cloud Firewall for AWS Cross Availability Zone Cluster with Transit Gateway  
  (Show / Hide this section)  
  * Cross AZ Cluster for Transit Gateway - New VPC
  * Cross AZ Cluster for Transit Gateway - Existing VPC
  * Cloud Firewall for AWS Single Availability Zone Cluster  
  (Show / Hide this section)  
  * Single AZ Cluster - New VPC
  * Single AZ Cluster - Existing VPC
  * Cloud Firewall for AWS Auto Scale Group  
  (Show / Hide this section)  
  * Auto Scale Group - Existing VPC
  * Cloud Firewall for AWS Auto Scale Group with Transit Gateway  
  (Show / Hide this section)  
  * Auto Scale Group for Transit Gateway - New VPC
  * Auto Scale Group for Transit Gateway - Existing VPC
* Cloud Firewall for AWS Security Management Server
* Cloud Firewall for AWS Multi-Domain Management Server
  * Cloud Firewall for AWS Standalone  
  (Show / Hide this section)  
  * AWS Standalone - New VPC
  * AWS Standalone - Existing VPC
  * Cloud Firewall WAF  
  (Show / Hide this section)  
  * WAF - New VPC
  * WAF - Existing VPC
  * Cloud Firewall WAF Auto Scaling Group  
  (Show / Hide this section)  
  * WAF Auto Scale Group - New VPC
  * WAF Auto Scale Group - Existing VPC
  * General  
  (Show / Hide this section)  
  * IAM role for Security Management Server
  * Current Check Point AMIs

### Cloud Firewall for AWS Gateway Load Balancer Auto Scale Group (for version R81.20 and higher) {#Auto Scaling Group}

|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| Description                                                                                                                                                                                                                                                                                             | Notes                                                                                                                                                                                                                                                                                                                                                             | Terraform Template                                                                                                                                                                                                                                                                                                                                                                               | CloudFormation Template                                                                                                                                                                                                                                                        | Direct Launch                                                                                                                                                                                                                                                                                               |
| **Auto Scale Group - New Centralized VPC**{#AS Centralized New VPC} Creates a new VPC and deploys a Gateway Load Balancer, a Cloud Firewall Gateway Auto Scaling Group, and, optionally, a Security Management Server into it.                                                                          | Deploys and configures an AWS Auto Scaling group configured for Gateway Load Balancer in a Centralized Security VPC. For more details, refer to [Cloud Firewall for AWS Gateway Load Balancer Auto Scale Group Deployment Guide](https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CloudGuard_Network_for_AWS_Gateway_Load_Balancer_ASG/Default.htm) | [![](https://sc1.checkpoint.com/sc/images/download-m.png) AWS Global](https://registry.terraform.io/modules/checkpointsw/cloudguard-network-security/aws/latest/submodules/gwlb_master) [![](https://sc1.checkpoint.com/sc/images/download-m.png) AWS China](https://registry.terraform.io/modules/CheckPointSW/china-cloudguard-network-security/aws/latest/submodules/gwlb_master)             | [![](https://sc1.checkpoint.com/sc/images/download-m.png) AWS Global](https://cgi-cfts.s3.amazonaws.com/gwlb/gwlb-master.yaml) [![](https://sc1.checkpoint.com/sc/images/download-m.png) AWS China](https://cgns-china-cft.s3.amazonaws.com/gwlb/gwlb-master.yaml)             | [![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk111013/ChatGPT Image Jun 4, 2026, 01_25_47 PM202606041330103.png)](https://console.aws.amazon.com/cloudformation/home#/stacks/create/review?templateURL=https://cgi-cfts.s3.amazonaws.com/gwlb/gwlb-master.yaml)                                      |
| **Auto Scale Group - Existing Centralized VPC**{#AS Centralized Existing VPC} Deploys a Gateway Load Balancer, Cloud Firewall Gateway Auto Scaling Group, and optionally a Security Management Server into an existing VPC.                                                                             | Deploys and configures an AWS Auto Scaling group configured for Gateway Load Balancer in a Centralized Security VPC. For more details, refer to [Cloud Firewall for AWS Gateway Load Balancer Auto Scale Group Deployment Guide](https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CloudGuard_Network_for_AWS_Gateway_Load_Balancer_ASG/Default.htm) | [![](https://sc1.checkpoint.com/sc/images/download-m.png) AWS Global](https://registry.terraform.io/modules/checkpointsw/cloudguard-network-security/aws/latest/submodules/gwlb) [![](https://sc1.checkpoint.com/sc/images/download-m.png) AWS China](https://registry.terraform.io/modules/CheckPointSW/china-cloudguard-network-security/aws/latest/submodules/gwlb)                           | [![](https://sc1.checkpoint.com/sc/images/download-m.png) AWS Global](https://cgi-cfts.s3.amazonaws.com/gwlb/gwlb.yaml) [![](https://sc1.checkpoint.com/sc/images/download-m.png) AWS China](https://cgns-china-cft.s3.amazonaws.com/gwlb/gwlb.yaml)                           | [![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk111013/ChatGPT Image Jun 4, 2026, 01_25_47 PM202606041330103.png)](https://console.aws.amazon.com/cloudformation/home#/stacks/create/review?templateURL=https://cgi-cfts.s3.amazonaws.com/gwlb/gwlb.yaml)                                             |
| **IAM Role**{#AS IAM Role} Create an IAM role for the Security Management Server managing the Gateway Load Balancer Auto Scale Group instances in your account, preconfigured with all required permissions. For more details, refer to [sk122074](https://support.checkpoint.com/results/sk/sk122074). | Deploy an IAM role for Cloud Firewall for AWS Gateway Load Balancer Auto Scale Group solutions.                                                                                                                                                                                                                                                                   | [![](https://sc1.checkpoint.com/sc/images/download-m.png) AWS Global](https://registry.terraform.io/modules/checkpointsw/cloudguard-network-security/aws/latest/submodules/cme_iam_role_gwlb) [![](https://sc1.checkpoint.com/sc/images/download-m.png) AWS China](https://registry.terraform.io/modules/CheckPointSW/china-cloudguard-network-security/aws/latest/submodules/cme_iam_role_gwlb) | [![](https://sc1.checkpoint.com/sc/images/download-m.png) AWS Global](https://cgi-cfts.s3.amazonaws.com/gwlb/cme-iam-role-gwlb.yaml) [![](https://sc1.checkpoint.com/sc/images/download-m.png) AWS China](https://cgns-china-cft.s3.amazonaws.com/gwlb/cme-iam-role-gwlb.yaml) | [![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk111013/ChatGPT Image Jun 4, 2026, 01_25_47 PM202606041330103.png)](https://console.aws.amazon.com/cloudformation/home#/stacks/create/review?templateURL=https://cgi-cfts.s3.amazonaws.com/gwlb/cme-iam-role-gwlb.yaml&stackName=Check-Point-IAM-Role) |

### Cloud Firewall for AWS Gateway Load Balancer Auto Scale Group with Transit Gateway (for version R81.20 and higher) {#Auto Scaling Group TGW}

|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                       | Notes                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   | Terraform Template                                                                                                                                                                                                                                                                                                                                                                           | CloudFormation Template                                                                                                                                                                                                                                                    | Direct Launch                                                                                                                                                                                                                                                                                 |
| **Auto Scale Group (2-arm Architecture) - New Centralized VPC for Transit Gateway**{#AS TGW New VPC} Creates a new VPC and deploys a Gateway Load Balancer, a Cloud Firewall Gateway Auto Scaling Group with two-arm architecture, and, optionally, a Security Management Server and Gateway Load Balancer Endpoints for each AZ in the Transit Gateway. Removes the NAT Gateway dependency. The Lambda function attaches each gateway's public interface and Elastic IP address. | Deploys and configures an AWS Auto Scaling group configured for Gateway Load Balancer in a Centralized Security VPC for Transit Gateway. Prerequisites: * R82 with Jumbo Hotfix Take 9 and higher * R82.10 with Jumbo Hotfix Take 3 and higher. Currently supports IPv4 only. For more details, refer to the [Cloud Firewall for AWS Gateway Load Balancer Auto Scale Group Deployment Guide](https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CloudGuard_Network_for_AWS_Gateway_Load_Balancer_ASG/Content/Topics-AWS-GWLB-ASG-DG/Deploying-Two-Arm-GWLB-Security-VPC-for-TGW.htm?tocpath=Deploying%20a%20Two-Arm%20GWLB%20Security%20VPC%20for%20Transit%20Gateway%7C_____0#Deploying_a_Two-Arm_GWLB_Security_VPC_for_Transit_Gateway). | [![](https://sc1.checkpoint.com/sc/images/download-m.png) AWS Global](https://registry.terraform.io/modules/CheckPointSW/cloudguard-network-security/aws/latest/submodules/tgw_gwlb_dual_arm_master)                                                                                                                                                                                         | [![](https://sc1.checkpoint.com/sc/images/download-m.png) AWS Global](https://cgi-cfts.s3.us-east-1.amazonaws.com/gwlb/tgw-gwlb-dual-arm-master.yaml)                                                                                                                      | [![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk111013/ChatGPT Image Jun 4, 2026, 01_25_47 PM202606041330103.png)](https://console.aws.amazon.com/cloudformation/home#/stacks/create/review?templateURL=https://cgi-cfts.s3.us-east-1.amazonaws.com/gwlb/tgw-gwlb-dual-arm-master.yaml) |
| **Auto Scale Group (2-arm Architecture) - Existing Centralized VPC for Transit Gateway**{#AS TGW New VPC} Deploys a Gateway Load Balancer, Cloud Firewall Gateway Auto Scaling Group with two-arm architecture, and optionally a Security Management Server and Gateway Load Balancer Endpoints for each AZ, for Transit Gateway into an existing VPC. Removes the NAT Gateway dependency. The Lambda function attaches each gateway's public interface and Elastic IP address.   | Deploys and configures an AWS Auto Scaling group configured for Gateway Load Balancer in a Centralized Security VPC for Transit Gateway. Prerequisites: * R82 with Jumbo Hotfix Take 9 and higher * R82.10 with Jumbo Hotfix Take 3 and higher. Currently supports IPv4 only. For more details, refer to the [Cloud Firewall for AWS Gateway Load Balancer Auto Scale Group Deployment Guide](https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CloudGuard_Network_for_AWS_Gateway_Load_Balancer_ASG/Content/Topics-AWS-GWLB-ASG-DG/Deploying-Two-Arm-GWLB-Security-VPC-for-TGW.htm?tocpath=Deploying%20a%20Two-Arm%20GWLB%20Security%20VPC%20for%20Transit%20Gateway%7C_____0#Deploying_a_Two-Arm_GWLB_Security_VPC_for_Transit_Gateway). | [![](https://sc1.checkpoint.com/sc/images/download-m.png) AWS Global](https://registry.terraform.io/modules/CheckPointSW/cloudguard-network-security/aws/latest/submodules/tgw_gwlb_dual_arm)                                                                                                                                                                                                | [![](https://sc1.checkpoint.com/sc/images/download-m.png) AWS Global](https://cgi-cfts.s3.us-east-1.amazonaws.com/gwlb/tgw-gwlb-dual-arm.yaml)                                                                                                                             | [![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk111013/ChatGPT Image Jun 4, 2026, 01_25_47 PM202606041330103.png)](https://console.aws.amazon.com/cloudformation/home#/stacks/create/review?templateURL=https://cgi-cfts.s3.us-east-1.amazonaws.com/gwlb/tgw-gwlb-dual-arm.yaml)        |
| **Auto Scale Group - New Centralized VPC for Transit Gateway**{#AS TGW New VPC} Creates a new VPC and deploys a Gateway Load Balancer, a Cloud Firewall Gateway Auto Scaling Group, and, optionally, a Security Management Server, Gateway Load Balancer Endpoints, and NAT Gateways for each AZ in the Transit Gateway.                                                                                                                                                          | Deploys and configures an AWS Auto Scaling group configured for Gateway Load Balancer in a Centralized Security VPC for Transit Gateway. For more details, refer to [Cloud Firewall for AWS Gateway Load Balancer Auto Scale Group Deployment Guide](https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CloudGuard_Network_for_AWS_Gateway_Load_Balancer_ASG/Default.htm)                                                                                                                                                                                                                                                                                                                                                                   | [![](https://sc1.checkpoint.com/sc/images/download-m.png) AWS Global](https://registry.terraform.io/modules/checkpointsw/cloudguard-network-security/aws/latest/submodules/tgw_gwlb_master) [![](https://sc1.checkpoint.com/sc/images/download-m.png) AWS China](https://registry.terraform.io/modules/CheckPointSW/china-cloudguard-network-security/aws/latest/submodules/tgw_gwlb_master) | [![](https://sc1.checkpoint.com/sc/images/download-m.png) AWS Global](https://cgi-cfts.s3.amazonaws.com/gwlb/tgw-gwlb-master.yaml) [![](https://sc1.checkpoint.com/sc/images/download-m.png) AWS China](https://cgns-china-cft.s3.amazonaws.com/gwlb/tgw-gwlb-master.yaml) | [![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk111013/ChatGPT Image Jun 4, 2026, 01_25_47 PM202606041330103.png)](https://console.aws.amazon.com/cloudformation/home#/stacks/create/review?templateURL=https://cgi-cfts.s3.amazonaws.com/gwlb/tgw-gwlb-master.yaml)                    |
| **Auto Scale Group - Existing Centralized VPC for Transit Gateway**{#AS TGW Existing VPC} Deploys a Gateway Load Balancer, Cloud Firewall Gateway Auto Scaling Group, and optionally a Security Management Server, Gateway Load Balancer Endpoints, and NAT Gateways for each AZ, for Transit Gateway into an existing VPC.                                                                                                                                                       | Deploys and configures an AWS Auto Scaling group configured for Gateway Load Balancer in a Centralized Security VPC for Transit Gateway. For more details, refer to [Cloud Firewall for AWS Gateway Load Balancer Auto Scale Group Deployment Guide](https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CloudGuard_Network_for_AWS_Gateway_Load_Balancer_ASG/Default.htm)                                                                                                                                                                                                                                                                                                                                                                   | [![](https://sc1.checkpoint.com/sc/images/download-m.png) AWS Global](https://registry.terraform.io/modules/checkpointsw/cloudguard-network-security/aws/latest/submodules/tgw_gwlb) [![](https://sc1.checkpoint.com/sc/images/download-m.png) AWS China](https://registry.terraform.io/modules/CheckPointSW/china-cloudguard-network-security/aws/latest/submodules/tgw_gwlb)               | [![](https://sc1.checkpoint.com/sc/images/download-m.png) AWS Global](https://cgi-cfts.s3.amazonaws.com/gwlb/tgw-gwlb.yaml) [![](https://sc1.checkpoint.com/sc/images/download-m.png) AWS China](https://cgns-china-cft.s3.amazonaws.com/gwlb/tgw-gwlb.yaml)               | [![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk111013/ChatGPT Image Jun 4, 2026, 01_25_47 PM202606041330103.png)](https://console.aws.amazon.com/cloudformation/home#/stacks/create/review?templateURL=https://cgi-cfts.s3.amazonaws.com/gwlb/tgw-gwlb.yaml)                           |

### Cloud Firewall for AWS Single Gateway (for version R81.10 and higher) {#Security Gateway}

|------------------------------------------------------------------------------------------------------|------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| Description                                                                                          | Notes                                                                                                                                                                                                                                          | Terraform Template                                                                                                                                                                                                                                                                                                                                                                         | CloudFormation Template                                                                                                                                                                                                                                                        | Direct Launch                                                                                                                                                                                                                                                                                              |
| **Single Gateway - New VPC**{#SG New VPC} Creates a new VPC and deploys a Security Gateway into it.  | Deploys and configures a Security Gateway. To deploy the Security Gateway for automatic provisioning, refer to [sk131434](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk131434). | [![](https://sc1.checkpoint.com/sc/images/download-m.png) AWS Global](https://registry.terraform.io/modules/checkpointsw/cloudguard-network-security/aws/latest/submodules/gateway_master) [![](https://sc1.checkpoint.com/sc/images/download-m.png) AWS China](https://registry.terraform.io/modules/CheckPointSW/china-cloudguard-network-security/aws/latest/submodules/gateway_master) | [![](https://sc1.checkpoint.com/sc/images/download-m.png) AWS Global](https://cgi-cfts.s3.amazonaws.com/gateway/gateway-master.yaml) [![](https://sc1.checkpoint.com/sc/images/download-m.png) AWS China](https://cgns-china-cft.s3.amazonaws.com/gateway/gateway-master.yaml) | [![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk111013/ChatGPT Image Jun 4, 2026, 01_25_47 PM202606041330103.png)](https://console.aws.amazon.com/cloudformation/home#/stacks/create/review?templateURL=https://cgi-cfts.s3.amazonaws.com/gateway/gateway-master.yaml&stackName=Check-Point-Gateway) |
| **Single Gateway - Existing VPC**{#SG Existing VPC} Deploys a Security Gateway into an existing VPC. | Deploys and configures a Security Gateway. To deploy the Security Gateway for automatic provisioning, refer to [sk131434](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk131434). | [![](https://sc1.checkpoint.com/sc/images/download-m.png) AWS Global](https://registry.terraform.io/modules/checkpointsw/cloudguard-network-security/aws/latest/submodules/gateway) [![](https://sc1.checkpoint.com/sc/images/download-m.png) AWS China](https://registry.terraform.io/modules/CheckPointSW/china-cloudguard-network-security/aws/latest/submodules/gateway)               | [![](https://sc1.checkpoint.com/sc/images/download-m.png) AWS Global](https://cgi-cfts.s3.amazonaws.com/gateway/gateway.yaml) [![](https://sc1.checkpoint.com/sc/images/download-m.png) AWS China](https://cgns-china-cft.s3.amazonaws.com/gateway/gateway.yaml)               | [![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk111013/ChatGPT Image Jun 4, 2026, 01_25_47 PM202606041330103.png)](https://console.aws.amazon.com/cloudformation/home#/stacks/create/review?templateURL=https://cgi-cfts.s3.amazonaws.com/gateway/gateway.yaml&stackName=Check-Point-Gateway)        |

### Cloud Firewall for AWS Cross Availability Zone Cluster (for version R81.20 and higher) {#Cross Availability Zone Cluster}

|----------------------------------------------------------------------------------------------------------------------------------------------------------|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| Description                                                                                                                                              | Notes                                                                                                                                                                                                                                                                                      | Terraform Template                                                                                                                                                                                                                                                                                                                                                                                           | CloudFormation Template                                                                                                                                                                                                                                                                          | Direct Launch                                                                                                                                                                                                                                                                                                           |
| **Cross AZ Cluster - New VPC**{#Cross AZ Cluster New VPC} Creates a new VPC and deploys a Cross Availability Zone Cluster of Security Gateways into it.  | Deploys two Security Gateways, each in a different Availability Zone. For more details, refer to [Cloud Firewall for AWS Cross Availability Zone Cluster Deployment Guide](https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CloudGuard_for_AWS_Cross_AZ_Cluster/Default.htm) | [![](https://sc1.checkpoint.com/sc/images/download-m.png) AWS Global](https://registry.terraform.io/modules/CheckPointSW/cloudguard-network-security/aws/latest/submodules/cross_az_cluster_master) [![](https://sc1.checkpoint.com/sc/images/download-m.png) AWS China](https://registry.terraform.io/modules/CheckPointSW/china-cloudguard-network-security/aws/latest/submodules/cross_az_cluster_master) | [![](https://sc1.checkpoint.com/sc/images/download-m.png) AWS Global](https://cgi-cfts.s3.amazonaws.com/cluster/cross-az-cluster-master.yaml) [![](https://sc1.checkpoint.com/sc/images/download-m.png) AWS China](https://cgns-china-cft.s3.amazonaws.com/cluster/cross-az-cluster-master.yaml) | [![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk111013/ChatGPT Image Jun 4, 2026, 01_25_47 PM202606041330103.png)](https://console.aws.amazon.com/cloudformation/home#/stacks/create/review?templateURL=https://cgi-cfts.s3.amazonaws.com/cluster/cross-az-cluster-master.yaml&stackName=Check-Point-XAZ-Cluster) |
| **Cross AZ Cluster - Existing VPC**{#Cross AZ Cluster Existing VPC} Deploys a Cross Availability Zone Cluster of Security Gateways into an existing VPC. | Deploys two Security Gateways, each in a different Availability Zone. For more details, refer to [Cloud Firewall for AWS Cross Availability Zone Cluster Deployment Guide](https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CloudGuard_for_AWS_Cross_AZ_Cluster/Default.htm) | [![](https://sc1.checkpoint.com/sc/images/download-m.png) AWS Global](https://registry.terraform.io/modules/CheckPointSW/cloudguard-network-security/aws/latest/submodules/cross_az_cluster) [![](https://sc1.checkpoint.com/sc/images/download-m.png) AWS China](https://registry.terraform.io/modules/CheckPointSW/china-cloudguard-network-security/aws/latest/submodules/cross_az_cluster)               | [![](https://sc1.checkpoint.com/sc/images/download-m.png) AWS Global](https://cgi-cfts.s3.amazonaws.com/cluster/cross-az-cluster.yaml) [![](https://sc1.checkpoint.com/sc/images/download-m.png) AWS China](https://cgns-china-cft.s3.amazonaws.com/cluster/cross-az-cluster.yaml)               | [![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk111013/ChatGPT Image Jun 4, 2026, 01_25_47 PM202606041330103.png)](https://console.aws.amazon.com/cloudformation/home#/stacks/create/review?templateURL=https://cgi-cfts.s3.amazonaws.com/cluster/cross-az-cluster.yaml&stackName=Check-Point-XAZ-cluster)        |

### Cloud Firewall for AWS Cross Availability Zone Cluster with Transit Gateway (for version R81.20 and higher) {#Transit Gateway Cross Availability Zone Cluster}

|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| Description                                                                                                                                                                                                     | Notes                                                                                                                                                                                                                                                                                                                      | Terraform Template                                                                                                                                                                                                                                                                                                                                                                                                   | CloudFormation Template                                                                                                                                                                                                                                                                                  | Direct Launch                                                                                                                                                                                                                                                                                                                   |
| **Cross AZ Cluster for Transit Gateway - New VPC**{#Cross AZ Cluster TGW New VPC} Creates a new VPC and deploys a Cross Availability Zone Cluster of Security Gateways configured for Transit Gateway into it.  | Deploys two Security Gateways, each in a different Availability Zone, configured for Transit Gateway. For more details, refer to [Cloud Firewall for AWS Cross Availability Zone Cluster Deployment Guide](https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CloudGuard_for_AWS_Cross_AZ_Cluster/Default.htm) | [![](https://sc1.checkpoint.com/sc/images/download-m.png) AWS Global](https://registry.terraform.io/modules/checkpointsw/cloudguard-network-security/aws/latest/submodules/tgw_cross_az_cluster_master) [![](https://sc1.checkpoint.com/sc/images/download-m.png) AWS China](https://registry.terraform.io/modules/CheckPointSW/china-cloudguard-network-security/aws/latest/submodules/tgw_cross_az_cluster_master) | [![](https://sc1.checkpoint.com/sc/images/download-m.png) AWS Global](https://cgi-cfts.s3.amazonaws.com/cluster/tgw-cross-az-cluster-master.yaml) [![](https://sc1.checkpoint.com/sc/images/download-m.png) AWS China](https://cgns-china-cft.s3.amazonaws.com/cluster/tgw-cross-az-cluster-master.yaml) | [![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk111013/ChatGPT Image Jun 4, 2026, 01_25_47 PM202606041330103.png)](https://console.aws.amazon.com/cloudformation/home#/stacks/create/review?templateURL=https://cgi-cfts.s3.amazonaws.com/cluster/tgw-cross-az-cluster-master.yaml&stackName=Check-Point-TGW-XAZ-Cluster) |
| **Cross AZ Cluster for Transit Gateway - Existing VPC**{#Cross AZ Cluster TGW Existing VPC} Deploys a Cross Availability Zone Cluster of Security Gateways configured for Transit Gateway into an existing VPC. | Deploys two Security Gateways, each in a different Availability Zone, configured for Transit Gateway. For more details, refer to [Cloud Firewall for AWS Cross Availability Zone Cluster Deployment Guide](https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CloudGuard_for_AWS_Cross_AZ_Cluster/Default.htm) | [![](https://sc1.checkpoint.com/sc/images/download-m.png) AWS Global](https://registry.terraform.io/modules/checkpointsw/cloudguard-network-security/aws/latest/submodules/tgw_cross_az_cluster) [![](https://sc1.checkpoint.com/sc/images/download-m.png) AWS China](https://registry.terraform.io/modules/CheckPointSW/china-cloudguard-network-security/aws/latest/submodules/tgw_cross_az_cluster)               | [![](https://sc1.checkpoint.com/sc/images/download-m.png) AWS Global](https://cgi-cfts.s3.amazonaws.com/cluster/tgw-cross-az-cluster.yaml) [![](https://sc1.checkpoint.com/sc/images/download-m.png) AWS China](https://cgns-china-cft.s3.amazonaws.com/cluster/tgw-cross-az-cluster.yaml)               | [![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk111013/ChatGPT Image Jun 4, 2026, 01_25_47 PM202606041330103.png)](https://console.aws.amazon.com/cloudformation/home#/stacks/create/review?templateURL=https://cgi-cfts.s3.amazonaws.com/cluster/tgw-cross-az-cluster.yaml&stackName=Check-Point-TGW-XAZ-Cluster)        |

### Cloud Firewall for AWS Single Availability Zone Cluster (for version R81.10 and higher) {#Security Cluster}

|---------------------------------------------------------------------------------------------------------------|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| Description                                                                                                   | Notes                                                                                                                                                                                                                                                                                       | Terraform Template                                                                                                                                                                                                                                                                                                                                                                         | CloudFormation Template                                                                                                                                                                                                                                                        | Direct Launch                                                                                                                                                                                                                                                                                              |
| **Single AZ Cluster - New VPC**{#Single AZ Cluster New VPC} Creates a new VPC and deploys a Cluster into it.  | Deploys and configures two Security Gateways as a Cluster. For more details, refer to the [Cloud Firewall for AWS Single Availability Zone Cluster Deployment Guide](https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CloudGuard_Network_for_AWS_Single_AZ_Cluster/Default.htm). | [![](https://sc1.checkpoint.com/sc/images/download-m.png) AWS Global](https://registry.terraform.io/modules/CheckPointSW/cloudguard-network-security/aws/latest/submodules/cluster_master) [![](https://sc1.checkpoint.com/sc/images/download-m.png) AWS China](https://registry.terraform.io/modules/CheckPointSW/china-cloudguard-network-security/aws/latest/submodules/cluster_master) | [![](https://sc1.checkpoint.com/sc/images/download-m.png) AWS Global](https://cgi-cfts.s3.amazonaws.com/cluster/cluster-master.yaml) [![](https://sc1.checkpoint.com/sc/images/download-m.png) AWS China](https://cgns-china-cft.s3.amazonaws.com/cluster/cluster-master.yaml) | [![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk111013/ChatGPT Image Jun 4, 2026, 01_25_47 PM202606041330103.png)](https://console.aws.amazon.com/cloudformation/home#/stacks/create/review?templateURL=https://cgi-cfts.s3.amazonaws.com/cluster/cluster-master.yaml&stackName=Check-Point-Cluster) |
| **Single AZ Cluster - Existing VPC**{#Single AZ Cluster Existing VPC} Deploys a Cluster into an existing VPC. | Deploys and configures two Security Gateways as a Cluster. For more details, refer to the [Cloud Firewall for AWS Single Availability Zone Cluster Deployment Guide](https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CloudGuard_Network_for_AWS_Single_AZ_Cluster/Default.htm). | [![](https://sc1.checkpoint.com/sc/images/download-m.png) AWS Global](https://registry.terraform.io/modules/CheckPointSW/cloudguard-network-security/aws/latest/submodules/cluster) [![](https://sc1.checkpoint.com/sc/images/download-m.png) AWS China](https://registry.terraform.io/modules/CheckPointSW/china-cloudguard-network-security/aws/latest/submodules/cluster)               | [![](https://sc1.checkpoint.com/sc/images/download-m.png)AWS Global](https://cgi-cfts.s3.amazonaws.com/cluster/cluster.yaml) [![](https://sc1.checkpoint.com/sc/images/download-m.png)AWS China](https://cgns-china-cft.s3.amazonaws.com/cluster/cluster.yaml)                 | [![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk111013/ChatGPT Image Jun 4, 2026, 01_25_47 PM202606041330103.png)](https://console.aws.amazon.com/cloudformation/home#/stacks/create/review?templateURL=https://cgi-cfts.s3.amazonaws.com/cluster/cluster.yaml&stackName=Check-Point-Cluster)        |

### Cloud Firewall for AWS Auto Scale Group (for version R81.10 and higher) {#Security Gateway Auto Scaling}

|--------------------------------------------------------------------------------------------------------------------------------|------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| Description                                                                                                                    | Notes                                                                                                                                                                                                                                                                                                | Terraform Template                                                                                                                                                                                                                                                                                                                                                                             | CloudFormation Template                                                                                                                                                                                                                                                                | Direct Launch                                                                                                                                                                                                                                                                                                                             |
| **Auto Scale Group - New VPC**Deploys an Auto Scaling group of Security Gateways into a new VPC.{#AS Existing VPC}             | Deploys and configures the Security Gateways as an AWS Auto Scaling group. For more details, refer to the [Cloud Firewall for AWS Auto Scale Group Deployment Guide](https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CloudGuard_Network_for_AWS_AutoScaling_DeploymentGuide/Default.htm) | [![](https://sc1.checkpoint.com/sc/images/download-m.png) AWS Global](https://registry.terraform.io/modules/CheckPointSW/cloudguard-network-security/aws/latest/submodules/autoscale_master) [![](https://sc1.checkpoint.com/sc/images/download-m.png) AWS China](https://registry.terraform.io/modules/CheckPointSW/china-cloudguard-network-security/aws/latest/submodules/autoscale_master) | [![](https://sc1.checkpoint.com/sc/images/download-m.png) AWS Global](https://cgi-cfts.s3.amazonaws.com/autoscale/autoscale-master.yaml) [![](https://sc1.checkpoint.com/sc/images/download-m.png) AWS China](https://cgns-china-cft.s3.amazonaws.com/autoscale/autoscale-master.yaml) | [![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk111013/ChatGPT Image Jun 4, 2026, 01_25_47 PM202606041330103.png)](https://us-east-1.console.aws.amazon.com/cloudformation/home?region=us-east-1#/stacks/quickcreate?templateURL=https://cgi-cfts.s3.amazonaws.com/autoscale/autoscale-master.yaml&stackName=Check-Point-AutoScale) |
| **Auto Scale Group - Existing VPC**{#AS Existing VPC} Deploys an Auto Scaling group of Security Gateways into an existing VPC. | Deploys and configures the Security Gateways as an AWS Auto Scaling group. For more details, refer to the [Cloud Firewall for AWS Auto Scale Group Deployment Guide](https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CloudGuard_Network_for_AWS_AutoScaling_DeploymentGuide/Default.htm) | [![](https://sc1.checkpoint.com/sc/images/download-m.png) AWS Global](https://registry.terraform.io/modules/CheckPointSW/cloudguard-network-security/aws/latest/submodules/autoscale) [![](https://sc1.checkpoint.com/sc/images/download-m.png) AWS China](https://registry.terraform.io/modules/CheckPointSW/china-cloudguard-network-security/aws/latest/submodules/autoscale)               | [![](https://sc1.checkpoint.com/sc/images/download-m.png) AWS Global](https://cgi-cfts.s3.amazonaws.com/autoscale/autoscale.yaml) [![](https://sc1.checkpoint.com/sc/images/download-m.png) AWS China](https://cgns-china-cft.s3.amazonaws.com/autoscale/autoscale.yaml)               | [![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk111013/ChatGPT Image Jun 4, 2026, 01_25_47 PM202606041330103.png)](https://console.aws.amazon.com/cloudformation/home#/stacks/create/review?templateURL=https://cgi-cfts.s3.amazonaws.com/autoscale/autoscale.yaml&stackName=Check-Point-Security-Gateway-AutoScaling)              |

### Cloud Firewall for AWS Auto Scale Group with Transit Gateway (for version R81.10 and higher) {#Transit Gateway Auto Scaling Group}

|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| Description                                                                                                                                                                                                                                                     | Notes                                                                                                                                                                                                                                                                                                                                           | Terraform Template                                                                                                                                                                                                                                                                                                                                                                                | CloudFormation Template                                                                                                                                                                                                                                                            | Direct Launch                                                                                                                                                                                                                                                                                                        |
| **Auto Scale Group for Transit Gateway - New VPC**{#AS New VPC TGW} Creates a new VPC and deploys an Auto Scaling group of Security Gateways configured for Transit Gateway into it, and an optional, preconfigured Security Management Server to manage them.  | Deploys and configures the Security Gateways as an AWS Auto Scaling group configured for Transit Gateway. For more details, refer to [Cloud Firewall for AWS Auto Scale Group with Transit Gateway Deployment Guide](https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CloudGuard_AWS_AutoScale_with_Transit_Gateway/Default.htm). | [![](https://sc1.checkpoint.com/sc/images/download-m.png) AWS Global](https://registry.terraform.io/modules/CheckPointSW/cloudguard-network-security/aws/latest/submodules/tgw_asg_master) [![](https://sc1.checkpoint.com/sc/images/download-m.png) AWS China](https://registry.terraform.io/modules/CheckPointSW/china-cloudguard-network-security/aws/latest/submodules/tgw_asg_master) <br /> | [![](https://sc1.checkpoint.com/sc/images/download-m.png) AWS Global](https://cgi-cfts.s3.amazonaws.com/autoscale/tgw-asg-master.yaml) [![](https://sc1.checkpoint.com/sc/images/download-m.png) AWS China](https://cgns-china-cft.s3.amazonaws.com/autoscale/tgw-asg-master.yaml) | [![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk111013/ChatGPT Image Jun 4, 2026, 01_25_47 PM202606041330103.png)](https://console.aws.amazon.com/cloudformation/home#/stacks/create/review?templateURL=https://cgi-cfts.s3.amazonaws.com/autoscale/tgw-asg-master.yaml&stackName=Check-Point-TGW-AutoScaling) |
| **Auto Scale Group for Transit Gateway - Existing VPC**{#AS Existing VPC TGW} Deploys an Auto Scaling group of Security Gateways configured for Transit Gateway into an existing VPC, and an optional, preconfigured Security Management Server to manage them. | Deploys and configures the Security Gateways as an AWS Auto Scaling group configured for Transit Gateway. For more details, refer to [Cloud Firewall for AWS Auto Scale Group with Transit Gateway Deployment Guide](https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CloudGuard_AWS_AutoScale_with_Transit_Gateway/Default.htm). | [![](https://sc1.checkpoint.com/sc/images/download-m.png) AWS Global](https://registry.terraform.io/modules/CheckPointSW/cloudguard-network-security/aws/latest/submodules/tgw_asg) [![](https://sc1.checkpoint.com/sc/images/download-m.png) AWS China](https://registry.terraform.io/modules/CheckPointSW/china-cloudguard-network-security/aws/latest/submodules/tgw_asg)                      | [![](https://sc1.checkpoint.com/sc/images/download-m.png) AWS Global](https://cgi-cfts.s3.amazonaws.com/autoscale/tgw-asg.yaml) [![](https://sc1.checkpoint.com/sc/images/download-m.png) AWS China](https://cgns-china-cft.s3.amazonaws.com/autoscale/tgw-asg.yaml)               | [![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk111013/ChatGPT Image Jun 4, 2026, 01_25_47 PM202606041330103.png)](https://console.aws.amazon.com/cloudformation/home#/stacks/create/review?templateURL=https://cgi-cfts.s3.amazonaws.com/autoscale/tgw-asg.yaml&stackName=Check-Point-TGW-AutoScaling)        |

### Cloud Firewall for AWS Security Management Server (for version R81.10 and higher) {#Security Management Server}

|----------------------------------------------------------------|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| Description                                                    | Notes                                                                                                                                                                                                           | Terraform Template                                                                                                                                                                                                                                                                                                                                                                               | CloudFormation Template                                                                                                                                                                                                                                                                              | Direct Launch                                                                                                                                                                                                                                                                                                                                |
| Deploys a Security Management Server into a **new VPC**.       | Deploys and configures a Security Management Server. For more details, refer to [sk130372](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk130372). | [![](https://sc1.checkpoint.com/sc/images/download-m.png) AWS Global](https://registry.terraform.io/modules/CheckPointSW/cloudguard-network-security/aws/latest/submodules/management_master) [![](https://sc1.checkpoint.com/sc/images/download-m.png) AWS China](https://registry.terraform.io/modules/CheckPointSW/china-cloudguard-network-security/aws/latest/submodules/management_master) | [![](https://sc1.checkpoint.com/sc/images/download-m.png) AWS Global](https://cgi-cfts.s3.us-east-1.amazonaws.com/management/management-master.yaml) [![](https://sc1.checkpoint.com/sc/images/download-m.png) AWS China](https://cgns-china-cft.s3.amazonaws.com/management/management-master.yaml) | [![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk111013/ChatGPT Image Jun 4, 2026, 01_25_47 PM202606041330103.png)](https://us-east-1.console.aws.amazon.com/cloudformation/home?region=us-east-1#/stacks/quickcreate?templateURL=https://cgi-cfts.s3.amazonaws.com/management/management-master.yaml&stackName=Check-Point-Management) |
| Deploys a Security Management Server into an **existing VPC**. | Deploys and configures a Security Management Server. For more details, refer to [sk130372](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk130372). | [![](https://sc1.checkpoint.com/sc/images/download-m.png) AWS Global](https://registry.terraform.io/modules/CheckPointSW/cloudguard-network-security/aws/latest/submodules/management) [![](https://sc1.checkpoint.com/sc/images/download-m.png) AWS China](https://registry.terraform.io/modules/CheckPointSW/china-cloudguard-network-security/aws/latest/submodules/management)               | [![](https://sc1.checkpoint.com/sc/images/download-m.png) AWS Global](https://cgi-cfts.s3.amazonaws.com/management/management.yaml) [![](https://sc1.checkpoint.com/sc/images/download-m.png) AWS China](https://cgns-china-cft.s3.amazonaws.com/management/management.yaml)                         | [![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk111013/ChatGPT Image Jun 4, 2026, 01_25_47 PM202606041330103.png)](https://console.aws.amazon.com/cloudformation/home#/stacks/create/review?templateURL=https://cgi-cfts.s3.amazonaws.com/management/management.yaml&stackName=Check-Point-Management)                                 |

### Cloud Firewall for AWS Multi-Domain Management Server (for version R81.10 and higher) {#Multi-Domain Management Server}

|-------------------------------------------------------------------------|--------------------------------------------------------------------------------------------------------------------------------------------------------------|----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| Description                                                             | Notes                                                                                                                                                        | Terraform Template                                                                                                                                                                                                                                                                                                                                                   | CloudFormation Template                                                                                                                                                                                                                                        | Direct Launch                                                                                                                                                                                                                                                                                  |
| Deploys a Multi-Domain Security Management Server into an existing VPC. | Deploys and configures a Multi-Domain Security Management Server. For more details, refer to [sk143213](https://support.checkpoint.com/results/sk/sk143213). | [![](https://sc1.checkpoint.com/sc/images/download-m.png) AWS Global](https://registry.terraform.io/modules/CheckPointSW/cloudguard-network-security/aws/latest/submodules/mds) [![](https://sc1.checkpoint.com/sc/images/download-m.png) AWS China](https://registry.terraform.io/modules/CheckPointSW/china-cloudguard-network-security/aws/latest/submodules/mds) | [![](https://sc1.checkpoint.com/sc/images/download-m.png) AWS Global](https://cgi-cfts.s3.amazonaws.com/management/mds.yaml) [![](https://sc1.checkpoint.com/sc/images/download-m.png) AWS China](https://cgns-china-cft.s3.amazonaws.com/management/mds.yaml) | [![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk111013/ChatGPT Image Jun 4, 2026, 01_25_47 PM202606041330103.png)](https://console.aws.amazon.com/cloudformation/home#/stacks/create/review?templateURL=https://cgi-cfts.s3.amazonaws.com/management/mds.yaml&stackName=Check-Point-MDS) |

### Cloud Firewall for AWS Standalone (for version R81.10 and higher) {#Standalone Deployment}

|--------------------------------------------------------------------------------------------------------------------------------------------|--------------------------------------------------------------------------|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| Description                                                                                                                                | Notes                                                                    | Terraform Template                                                                                                                                                                                                                                                                                                                                                                               | CloudFormation Template                                                                                                                                                                                                                                                              | Direct Launch                                                                                                                                                                                                                                                                                                    |
| **AWS Standalone - New VPC**{#Standalone New VPC} Creates a new VPC and deploys a Standalone or manually configurable instance into it.    | Deploys and configures a Standalone or a manually configurable instance. | [![](https://sc1.checkpoint.com/sc/images/download-m.png) AWS Global](https://registry.terraform.io/modules/CheckPointSW/cloudguard-network-security/aws/latest/submodules/standalone_master) [![](https://sc1.checkpoint.com/sc/images/download-m.png) AWS China](https://registry.terraform.io/modules/CheckPointSW/china-cloudguard-network-security/aws/latest/submodules/standalone_master) | [![](https://sc1.checkpoint.com/sc/images/download-m.png) AWS Global](https://cgi-cfts.s3.amazonaws.com/gateway/standalone-master.yaml) [![](https://sc1.checkpoint.com/sc/images/download-m.png) AWS China](https://cgns-china-cft.s3.amazonaws.com/gateway/standalone-master.yaml) | [![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk111013/ChatGPT Image Jun 4, 2026, 01_25_47 PM202606041330103.png)](https://console.aws.amazon.com/cloudformation/home#/stacks/create/review?templateURL=https://cgi-cfts.s3.amazonaws.com/gateway/standalone-master.yaml&stackName=Check-Point-Standalone) |
| **AWS Standalone - Existing VPC**{#Standalone Existing VPC} Deploys a Standalone or a manually configurable instance into an existing VPC. | Deploys and configures a Standalone or a manually configurable instance. | [![](https://sc1.checkpoint.com/sc/images/download-m.png) AWS Global](https://registry.terraform.io/modules/CheckPointSW/cloudguard-network-security/aws/latest/submodules/standalone) [![](https://sc1.checkpoint.com/sc/images/download-m.png) AWS China](https://registry.terraform.io/modules/CheckPointSW/china-cloudguard-network-security/aws/latest/submodules/standalone)               | [![](https://sc1.checkpoint.com/sc/images/download-m.png) AWS Global](https://cgi-cfts.s3.amazonaws.com/gateway/standalone.yaml) [![](https://sc1.checkpoint.com/sc/images/download-m.png) AWS China](https://cgns-china-cft.s3.amazonaws.com/gateway/standalone.yaml)               | [![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk111013/ChatGPT Image Jun 4, 2026, 01_25_47 PM202606041330103.png)](https://console.aws.amazon.com/cloudformation/home#/stacks/create/review?templateURL=https://cgi-cfts.s3.amazonaws.com/gateway/standalone.yaml&stackName=Check-Point-Standalone)        |

### Cloud Firewall WAF (formerly AppSec) {#CloudGuard Infinity Next Gateway}

|------------------------------------------------------------------------------------------------------------|------------------------------------------------------------|---------------------------------------------------------------------------------|----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| Description                                                                                                | Notes                                                      | CloudFormation Template                                                         | Direct Launch                                                                                                                                                                                                                                                                                                              |
| **WAF - New VPC**{#WAF New VPC} Creates a new VPC and deploys a CloudGuard Infinity Next Gateway into it.  | Deploys and configures a CloudGuard Infinity Next Gateway. | [AWS Marketplace](https://aws.amazon.com/marketplace/pp/prodview-wctbkjip42idi) | [![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk111013/ChatGPT Image Jun 4, 2026, 01_25_47 PM202606041330103.png)](https://console.aws.amazon.com/cloudformation/home#/stacks/create/review?templateURL=https://cgi-cfts.s3.amazonaws.com/waap/waap-gateway-master.yaml&stackName=Check-Point-Infinity-Next-Gateway) |
| **WAF - Existing VPC**{#WAF Existing VPC} Deploys a CloudGuard Infinity Next Gateway into an existing VPC. | Deploys and configures a CloudGuard Infinity Next Gateway. | [AWS Marketplace](https://aws.amazon.com/marketplace/pp/prodview-wctbkjip42idi) | [![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk111013/ChatGPT Image Jun 4, 2026, 01_25_47 PM202606041330103.png)](https://console.aws.amazon.com/cloudformation/home#/stacks/create/review?templateURL=https://cgi-cfts.s3.amazonaws.com/waap/waap-gateway.yaml&stackName=Check-Point-Infinity-Next-Gateway)        |

### Cloud Firewall WAF (formerly AppSec) Auto Scaling Group {#CloudGuard Infinity Next Gateway Auto Scaling Group}

|--------------------------------------------------------------------------------------------------------------------|-------------------------------------------------------------------|---------------------------------------------------------------------------------|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| Description                                                                                                        | Notes                                                             | CloudFormation Template                                                         | Direct Launch                                                                                                                                                                                                                                                                                                                  |
| **WAF Auto Scale Group - New VPC**{#WAF AS New VPC} Creates a new VPCand deploys the Auto Scaling Group into it.   | Deploys and configures a WAF Gateway as an AWS Auto Scaling Group | [AWS Marketplace](https://aws.amazon.com/marketplace/pp/prodview-wctbkjip42idi) | [![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk111013/ChatGPT Image Jun 4, 2026, 01_25_47 PM202606041330103.png)](https://console.aws.amazon.com/cloudformation/home#/stacks/quickcreate?templateURL=https://cgi-cfts.s3.amazonaws.com/waap/waap-autoscale-master.yaml&stackName=Check-Point-Infinity-Next-Gateway-Asg) |
| **WAF Auto Scale Group - Existing VPC**{#WAF AS Existing VPC} Deploys the Auto Scaling Group into an existing VPC. | Deploys and configures a WAF Gateway as an AWS Auto Scaling Group | [AWS Marketplace](https://aws.amazon.com/marketplace/pp/prodview-wctbkjip42idi) | [![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk111013/ChatGPT Image Jun 4, 2026, 01_25_47 PM202606041330103.png)](https://console.aws.amazon.com/cloudformation/home#/stacks/quickcreate?templateURL=https://cgi-cfts.s3.amazonaws.com/waap/waap-autoscale.yaml&stackName=Check-Point-Infinity-Next-Gateway-Asg)        |

### General {#General}

|----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| Description                                                                                                                                                                                                                                                                                              | Terraform Template                                                                                                                                                                                                                                                                                                                                                                     | CloudFormation Template                                                                                                                                                                                                                                                                                                                               | Direct Launch                                                                                                                                                                                                                                                                                         |
| **IAM role for Security Management Server**{#IAM SMS} Creates an IAM role in your account preconfigured with permissions to manage resources. For more details, refer to [sk122074](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk122074). | [![](https://sc1.checkpoint.com/sc/images/download-m.png) AWS Global](https://registry.terraform.io/modules/CheckPointSW/cloudguard-network-security/aws/latest/submodules/cme_iam_role) [![](https://sc1.checkpoint.com/sc/images/download-m.png) AWS China](https://registry.terraform.io/modules/CheckPointSW/china-cloudguard-network-security/aws/latest/submodules/cme_iam_role) | [![](https://sc1.checkpoint.com/sc/images/download-m.png) AWS Global](https://cgi-cfts.s3.amazonaws.com/iam/cme-iam-role.yaml) [![](https://sc1.checkpoint.com/sc/images/download-m.png) AWS China](https://console.amazonaws.cn/cloudformation/home#/stacks/create/review?templateURL=https://cgns-china-cft.s3.amazonaws.com/iam/cme-iam-role.yaml) | [![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk111013/ChatGPT Image Jun 4, 2026, 01_25_47 PM202606041330103.png)](https://console.aws.amazon.com/cloudformation/home#/stacks/create/review?templateURL=https://cgi-cfts.s3.amazonaws.com/iam/cme-iam-role.yaml&stackName=Check-Point-IAM-Role) |
| **Current Check Point AMIs**{#AMIs} A helper template that returns the latest Check Point AMIs in a given region.                                                                                                                                                                                        | [![](https://sc1.checkpoint.com/sc/images/download-m.png) AWS Global](https://registry.terraform.io/modules/CheckPointSW/cloudguard-network-security/aws/latest/submodules/amis) [![](https://sc1.checkpoint.com/sc/images/download-m.png) AWS China](https://registry.terraform.io/modules/CheckPointSW/china-cloudguard-network-security/aws/latest/submodules/amis)                 | [![](https://sc1.checkpoint.com/sc/images/download-m.png) AWS Global](https://cgi-cfts.s3.amazonaws.com/utils/amis.yaml) [![](https://sc1.checkpoint.com/sc/images/download-m.png) AWS China](https://cgns-china-cft.s3.amazonaws.com/utils/amis.yaml)                                                                                                | [![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk111013/ChatGPT Image Jun 4, 2026, 01_25_47 PM202606041330103.png)](https://console.aws.amazon.com/cloudformation/home#/stacks/create/review?templateURL=https://cgi-cfts.s3.amazonaws.com/utils/amis.yaml&stackName=Check-Point-AMIs)           |

CloudFormation templates for previous versions are available in the [Cloud Firewall Network Security GitHub repository](https://github.com/CheckPointSW/CloudGuardIaaS/tree/master/deprecated/aws/templates).

**Note:**CloudFormation Templates are often referred to as CFTs by customers and partners.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
