> Source: [sk171710](https://support.checkpoint.com/results/sk/sk171710)

# sk171710 - Cloud Firewall for Equinix Network Edge

| Property | Value |
|----------|-------|
| Solution ID | sk171710 |
| Date Created | 2021-01-26 |
| Last Modified | 2026-06-22 |
| Technical Level | General |
| Products | Cloud Firewall |
| Versions | R81.20, R82 |
| OS | Gaia |
| Platform | Equinix Network Edge |

## Solution

Overview {#overview}
--------------------

[Equinix Network Edge](https://www.equinix.com/services/edge-services/network-edge/ "Equinix Network Edge Service") provides virtual network services that run on a modular infrastructure platform, optimized for instant deployment and interconnection of network services. With Network Edge, deploy, scale, and connect secure virtual network services at the edge in your Equinix tenant. No additional hardware is needed.  

Check Point Cloud Firewall delivers advanced, multi-layered threat prevention to protect your assets from malware and sophisticated threats. Cloud Firewall for Equinix Network Edge allows you to easily and seamlessly secure your workloads while providing secure connectivity across your cloud and on-premises environments.

**You can manage a Cloud Firewall hosted in Equinix Network Edge in several ways, including:**

* Centrally managed, in which the Security Management Server is located on-premises or in a public or private cloud
* Centrally managed by Check Point Smart-1 Cloud

**The Equinix marketplace offer for Cloud Firewall includes:**

* Single Gateway
* Redundant Devices(Single Gateways in physically separate datacenters in the same region)  
  * **NOTE:** Select this option when needing to create a Cluster
    * Both Active/Standby and Active/Active clusters **are** supported

To automatically distribute Cloud Firewall BYOL-type licenses, use the Cloud Firewall Central Licensing tool. For details, refer to the [Cloud Firewall Central License Tool Administration Guide.](https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CloudGuard_Central_License_Tool_Admin_Guide/Content/Topics-Central-License-Tool/Overview.htm)

For more details on available VM sizes refer to the [Equinix Customer Documentation.](https://docs.equinix.com/en-us/Content/Interconnection/NE/deploy-guide/CheckPoint/NE-CheckPoint-specs.htm)

**Licensing:** BYOL only  

* Supported SKUs:
  * CPSG-VSEC-VEN-BUN-NGTP
  * CPSG-VSEC-VEN-BUN-NGTX

**Known Limitations:**

* 8 Interfaces (support for more interfaces is on the roadmap)
* VLAN interfaces are not supported
* R82.10 support coming soon

<br />

Configuration Steps
-------------------

1. Log in to your Equinix account at [portal.equinix.com](https://portal.equinix.com)

   ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk171710/Equinix Fabric-001202309280955091.png)
2. Select **Network Edge** from the left-hand navigation pane:  
   ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk171710/Equinix Fabric-002202506111712222.1.png)
3. Select **Check Point** from the **Vendor Packages** screen  

   ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk171710/Equinix Fabric-004202309281011281.png)  

   <br />

4. Select **Redundant Device \> Create a redundant pair of devices... \> Begin Creating Edge Devices**   
   ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk171710/Equinix Fabric-003202309281015022.png)  

   <br />

5. Select Metro location and Billing Account \> **Next: Device Details**   
   ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk171710/Equinix Fabric-005202206231428381.png)  

   <br />

6. Select the instance size and term length  

   ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk171710/Equinix Fabric-006202309281018003.png)  

   <br />

7. Give your deployment a device name(***identifier used in Equinix Portal only*** ) and Host Names for each cluster member.  
   - Select your Software Version(***R81.20 or higher...R80.40 is End of Life*** )  
   - Select your WAN/SSH interface(***default is eth0*** )  
   - Input your email address that you want notified when the instance is ready for use and for ongoing maintenance or incident notifications  
   - Select **Next: Additional Services**   

   ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk171710/Equinix Fabric-007202506051156311.png)  

   <br />

8. **Finish configuring the devices** - Add username **admin** for use within Gaia(***additional users can be added post setup*** )  
   - Select and existing public key or add a new public key  
   - Add or create a public key  
   - Assign or create an Access Control List for the WAN interface  
   - Request additional Bandwidth as needed  
   - Select **Next: Review**   
   ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk171710/Equinix Fabric-008202206231516094.png)  

   <br />

9. Select **Review and Accept Order Terms, Accept the Terms and Conditions, and select Accept**   

   ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk171710/Equinix Fabric-009202206231520475.png)  

   <br />

10. Select **Create Virtual Device** ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk171710/Equinix Fabric-010202309281049511.png)  

    **Note** that provisioning may up to 60 minutes(typically around 30 minutes). An email is sent to the email you provided above when the Cloud Firewall is ready for use.   

    ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk171710/Equinix Fabric-0112021062808304814.png)  

    <br />

11. After receiving the email stating that your gateways are ready, log back in to the Equinix portal.  

12. Navigate to your **Virtual Device Inventory**

    ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk171710/Equinix Fabric-012202206241114011.png)  

    ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk171710/Equinix Fabric-012001202206241115482.png)
13. Click on each cluster member and record the public IP that has been assigned  

    ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk171710/Equinix Fabric-013202106291518252.png)  

    ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk171710/Equinix Fabric-014202206241122523.png)  

    <br />

14. Use this public IP addresses to access your Security Gateways via SSH using the username and public key you provided during step #8.  

15. Give your username a password  
    **set user <username> password** \> hit Enter and set the password  

16. Set the expert password  
    **set expert-password** \> hit Enter and set the password  

17. Save the changes: **save config**  

18. Enter the Expert mode: **`expert`**
19. Set the SIC key that will allow you to communicate with your Security Management Server: **cpconfig**
20. Select option 5 ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk171710/Equinix Fabric-015202106291541141.png)

21. Enter **Y** to agree to change the Activation Key(SIC)  

22. Enter **Y** again to agree to continue, set the Activation Key(SIC)  

23. For cluster members, you must also enable cluster membership(***Option 6 above*** ), when complete select option 9 and press **Enter**   

    ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk171710/Equinix Fabric-017202106291550434.png)  

    <br />

24. The Cloud Firewall will restart its services.  

25. Apply the Recommended Jumbo Hotfix for your version. Log in to your Cloud Firewall using the public IP address used above at https://x.x.x.x using the user name and password you created via your SSH session.   

    ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk171710/Equinix Fabric-018202506131654341.png)  

    <br />

26. Navigate down the left side and select **Status and Actions**   

27. If a Jumbo Hotfix is available it will present itself in this dialog box ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk171710/Equinix Fabric-020202506131701095.png)

28. Right-click the hotfix and select **Install Update** , select OK to complete the install. Cloud Firewall will reboot when complete.  
    ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk171710/Equinix Fabric-021202506131700514.png)  

    <br />

29. At this point you can define the interfaces that will be clustered. For each clustered interface you also must create a **Device Link** inside the Equinix Network Edge portal  
    ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk171710/Equinix Fabric-022202206241144331.png)  

30. Select your cluster members and click **Next: Device Link Details**   
    ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk171710/Equinix Fabric-022202206241151314.png)  

31. Give your Device Link a descriptive name and select the interfaces from each cluster member that need to be linked and click **Next: Review**   
    ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk171710/Equinix Fabric-023202206241155265.png)  

32. Click **Submit**
33. Repeat the the Device Link setup for each interface that needs to be clustered  
    * **NOTE:** One of these interfaces will need to set as **Cluster + Sync** in your cluster configuration in SmartConsole.  

34. At this point your gateway is ready to be attached to your Check Point Security Management Server to set your Security Policy, NAT, Topology, etc.

Performance
-----------

|-------------------------------------------------------------|-------------|-------------|-------------|--------------|
| ### Test Coverage / Number of vCPUs                         | **2 vCPUs** | **4 vCPUs** | **8 vCPUs** | **12 vCPUs** |
| **Firewall only**                                           | 7.1 Gbps    | 10 Gbps\*   | 10 Gbps\*   | 10 Gbps\*    |
| **Firewall + IPS**                                          | 4.4 Gbps    | 7.6 Gbps    | 10 Gbps\*   | 10 Gbps\*    |
| **NGFW** **(Firewall + IPS + Application Control)**         | 3.4 Gbps    | 6.1 Gbps    | 10 Gbps\*   | 10 Gbps\*    |
| **NGTP** **(NGFW + URL Filtering + Anti-Virus + Anti-Bot)** | 1.25 Gbps   | 2.2 Gbps    | 4.2 Gbps    | 6 Gbps       |

\* Equinix Network Edge has a max throughput of 10 Gbps per network connection...architectures can be built to work around this limit.  
- Performance is limited by the amount of bandwidth allocated to the security gateway  

Related Information
-------------------

* [Equinix Network Edge Datacenter Locations](https://docs.equinix.com/en-us/Content/Interconnection/NE/user-guide/NE-metros.htm)

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
