> Source: [sk171497](https://support.checkpoint.com/results/sk/sk171497)

# sk171497 - Quantum Edge for Oracle SD-WAN

| Property | Value |
|----------|-------|
| Solution ID | sk171497 |
| Date Created | 2021-02-09 |
| Last Modified | 2023-04-30 |
| Technical Level | General |
| Platform | Oracle Talari |

## Solution

### Requirements

* Quantum Edge R80.20.10 and above
* Oracle SD-WAN Edge Release 9.0 and above
* Oracle Talari E100 Appliance

### Overview

This document outlines the integration between Check Point Quantum Edge (former CloudGuard Edge) and Oracle SD-WAN Edge.  

Check Point Quantum Edge protects branch offices on-premises with top-rated Threat Prevention that can be deployed in minutes and managed by a unified threat prevention and access platform.  

The Oracle SD-WAN Edge is engineered for maximum business impact in an enterprise network. This is achieved by creating failsafe WANs that offer superior application reliability, while unlocking the benefits of network resiliency and scalable bandwidth. The Oracle SD-WAN Edge includes key network services including WAN-OP routing and firewall. The Oracle Communications SD-WAN Edge transforms a traditional WAN into a network that is easy and fast to deploy, offers increased application reliability, security, and performance while leveraging affordable broadband links that are transformed into an enterprise-class infrastructure. It does this by understanding a company's applications and priorities while adapting automatically to changing conditions and demands. The Oracle SD-WAN Edge supports various link types, such as MPLS and broadband Internet, and works well with common services such as WAN optimization.  

Together, Oracle SD-WAN Edge and Check Point deliver a best-of-breed SD-WAN and security platform for enterprises accessing mission-critical internally hosted applications as well as those going directly to the internet for accessing cloud applications.  

### Integration
![C:\Users\jengel\Documents\Alliance Partners\Oracle\SD-WAN\Oracle SD-WAN-Quantum Edge Overview Graphic.png](https://sc1.checkpoint.com/sc/SolutionsStatics/sk171497/Oracle SD-WAN-Quantum Edge Overview Graphic202103261000051.png)

<br />

Quantum Edge runs as a virtual machine on top of the Oracle Talari E100 appliance, providing on-premises protection for both North/South and East/West traffic. This capability protects organizations that must adhere to data privacy, compliance, or location requirements.  

Service chaining is one of the unique features of Oracle SD-WAN, where customers can install a virtual KVM image of a NGFW, this feature is supported on The E100 Oracle SD-WAN Edge device.  

The graphic above shows an example of service chaining a Check Point Quantum Edge virtual firewall on the E100 and allows for local Internet breakout with NGFW protection for Internet/SaaS applications.  

Shown is a typical deployment of the Check Point NGFW. The LAN side of the Security Gateway is internally connected to the WAN link defined in SD-WAN configuration.  

The Check Point VM management port will be bridged to the Oracle SD-WAN physical management port. Both the E100 and the Check Point VM have separate management IP addresses.  

The WAN side of the firewall is bridged with the physical interface on the E100 which is connected to the Internet WAN link.  

Traffic flows from the LAN will first traverse the SD-WAN where the SD-WAN routing policies will forward the traffic to a proper service based on the destination.  

Traffic destined for the Internet will then be accounted for and forwarded to the Quantum Edge, where it is inspected, and NATed to its destination.  

Management of the Quantum Edge security policy can be done in multiple ways:  

* Local Management
* Security Management Server / Multi-Domain Security Management Server
* Smart-1 Cloud Management-as-a-Service (supports Quantum Edge R80.20.10 and above)
* SMP (Security Management Portal) cloud management platform

### Image Downloads

* [Quantum Edge R80.20.15](https://supportcenter.checkpoint.com/supportcenter/portal?action=portlets.DCFileAction&eventSubmit_doGetdcdetails=&fileid=111979) (recommended version)  

* [Quantum Edge R80.20.10](https://supportcenter.checkpoint.com/supportcenter/portal?action=portlets.DCFileAction&eventSubmit_doGetdcdetails=&fileid=109750)

### In-Place Upgrade

* [In-Place Upgrade from R80.20.x to R80.20.15](https://supportcenter.checkpoint.com/supportcenter/portal?action=portlets.DCFileAction&eventSubmit_doGetdcdetails=&fileid=112011)

### Related Information

* [sk161272 - Quantum Edge](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk161272)

<!-- -->

* [sk166513 - Quantum Edge Known Limitations - R80.20.x](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk166513)

<!-- -->

* [Oracle SD-WAN Edge - Check Point VNF Appliance Service Chaining](https://docs.oracle.com/en/industries/communications/sd-wan-edge/9.0/servicechaining/CheckPointVNFServiceChaining.html#GUID-B18B285D-77B8-4692-BF1F-133912325940 "EXTERNAL LINK: Oracle SD-WAN Edge - Check Point VNF Appliance Service Chaining")

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
