> Source: [sk122519](https://support.checkpoint.com/results/sk/sk122519)

# sk122519 - Cloud Firewall for AWS - Amazon GuardDuty Integration

| Property | Value |
|----------|-------|
| Solution ID | sk122519 |
| Date Created | 2018-01-25 |
| Last Modified | 2026-04-27 |
| Technical Level | General |
| Products | Cloud Firewall |
| Versions | R82.10, R81.10 (EOS), R81.20, R82 |
| Platform | AWS |

## Solution

**Table of Contents:**

* (1) Overview
* (2) Prerequisites
* (3) Configuration of the Security Policy
* (4) Register Check Point's GuardDuty Lambda function to tag suspicious EC2 instances
* (5) Reinstating traffic for blocked instances

(1) Overview {#Overview}
------------------------

Amazon GuardDuty is a managed threat detection service that continuously monitors for malicious or unauthorized behavior to help you protect your AWS accounts and workloads. Read more about Amazon GuardDuty [here](https://aws.amazon.com/guardduty/).

When GuardDuty identifies a threat, a CloudWatch Event triggers the execution of the Lambda function deployed via a CloudFormation template. The Lambda function will then tag the EC2 instance associated with the threat.

Check Point Cloud Firewall (formerly CloudGuard Network Security) applies the security policy, and the Security Gateways enforce it automatically, without manual intervention, on instances tagged with the tag key you have chosen. This is done to mitigate any risk immediately when it appears (Check Point Security Management and your AWS environment are fully synced using [CloudGuard Controller](https://support.checkpoint.com/results/sk/sk181842)).

This solution is Check Point's recommended practice: a CloudFormation template creates a CloudWatch Event that matches GuardDuty Findings and a Lambda function that is triggered by the event and tags the suspicious instances. This allows Check Point and AWS mutual customers to benefit from a self-service, automatic, and adaptive solution that detects and prevents malicious activity in real time.

(2) Prerequisites {#Prerequisites}
----------------------------------

1. Amazon GuardDuty is enabled in the AWS account.

2. Monitored resources are protected by Check Point Cloud Firewall Gateway(s), managed with a Smart Management Server, and Cloud Firewall for AWS is configured to integrate with the AWS account. Read more on how to configure CloudGuard Controller to integrate with your AWS account [here](http://downloads.checkpoint.com/dc/download.htm?ID=54943).

3. One of the EC2 instances in the environment is tagged with a tag of your choosing. Note the tag key, as it will be used later in the configuration. e.g. chkp-GuardDuty.{#tag}

(3) Configuration of the Security Policy {#Configuration of the Security Policy}
--------------------------------------------------------------------------------

Configure a Security Policy to drop traffic to and from an AWS EC2 instance identified as suspicious by GuardDuty:

1. Open Smart Console.
2. Under the relevant policy, create a new rule in the desired position.
3. In the newly created rule, if you wish to block outgoing traffic from the identified instances, click on the plus icon in the **Source** column. If you wish to block incoming traffic to the identified instances, click on the plus ion in the **Destination** column. If you wish to block both outgoing and incoming traffic, create two separate rules.![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk122519/11801290734.png)
4. Click on the 'Import...' icon and choose your AWS Data Center:![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk122519/21801300235.png)
5. Under Tags, find the key of the tag created in section (2), step 3. Make sure to choose the entry with **Tag Key** in the **Type in Server** column, and not Tag Value.
6. Click on the plus icon to the left of the entry.
7. In the **Action** column, select **Drop**.
8. Configure the remaining rule and install the policy.

(4) Register Check Point's GuardDuty Lambda function to tag suspicious EC2 instances {#Register Check Point's GuardDuty Lambda function to tag suspicious EC2 instances}
------------------------------------------------------------------------------------------------------------------------------------------------------------------------

Deploy the Check Point CloudFormation template to register the Lambda function that tags suspicious instances identified by Amazon GuardDuty with the predefined tag key:

1. Use the following CloudFormation template to deploy the Check GuardDuty Lambda:
   * Either download the template from:

     <https://s3.amazonaws.com/CloudFormationTemplate/chkp-gd.yaml>
   * Or directly launch the template from the CloudFormation portal by clicking here:

     [![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk112575/Launch_Stack_button.png)](https://console.aws.amazon.com/cloudformation/home#/stacks/create/review?templateURL=https%3A%2F%2Fs3.amazonaws.com%2FCloudFormationTemplate%2Fchkp-gd.yaml&stackName=Check-Point-GuardDuty "Click the image to directly launch the template from the Cloud Formation portal")
2. Fill the **Tag key** field with the tag key you have used in section (2), step 3. This will be used as the key in the key-value tag added to EC2 instances that are identified by GuardDuty. The tag value will contain the reason provided by GuardDuty for issuing the finding. Read more about Amazon GuardDuty Findings [here](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_findings.html).
3. Choose the severity of GuardDuty alerts that will trigger the Lambda function. Read more about Severity Levels for GuardDuty Findings [here](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_findings.html#guardduty_findings-severity).
4. Deploy the template.

(5) Reinstating traffic for a blocked instance {#Reinstating traffic for blocked instances}
-------------------------------------------------------------------------------------------

The Lambda function tags the EC2 instance associated with the threat found by Amazon GuardDuty as follows:

* Tag key: the tag key you have specified.
* Tag value: the reason provided by GuardDuty for issuing the finding.

If you have inspected the reason provided by GuardDuty as described in the tag value and wish to reinstate traffic for the EC2 instance, manually remove the tag:

1. Open the [Amazon EC2 console](https://signin.aws.amazon.com/signin?redirect_uri=https%3A%2F%2Fconsole.aws.amazon.com%2Fec2%2Fv2%2Fhome%3Fstate%3DhashArgs%2523%26isauthcode%3Dtrue&client_id=arn%3Aaws%3Aiam%3A%3A015428540659%3Auser%2Fec2&forceMobileApp=0).
2. In the left navigation pane, choose **Instances**.
3. Select the instance for which you wish to reinstate traffic.
4. Select the **Tags** tab.
5. Click **Add/Edit Tags**.
6. Click on the X icon to the right of Tag key you have specified.
7. Click **Save**.

No additional configuration is required on the Management Server or the Security Gateways.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
