> Source: [sk182972](https://support.checkpoint.com/results/sk/sk182972)

# sk182972 - Cloud Firewall for Nutanix AHV - Best Practices, Performance Optimization, and Recommended Topologies 

| Property | Value |
|----------|-------|
| Solution ID | sk182972 |
| Date Created | 2025-01-05 |
| Last Modified | 2026-06-30 |
| Technical Level | General |
| Products | Cloud Firewall |
| Versions | R82.10, R81.20, R82 |
| OS | Gaia |
| Platform | Nutanix |

## Solution

Table of Contents:

* Nutanix Virtual Private Cloud
* Required Components for installation of Cloud Firewall for Nutanix AHV
* Prerequisites
* Recommended Topologies:
  * Tenant VPC Topology
  * Transit VPC Topology
  * Service Insertion 2.0
* Additional Resources

Nutanix Virtual Private Cloud {#Nutanix VPC}
--------------------------------------------

![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk182972/Nut-VPC202509180921091.png)

Nutanix Virtual Private Cloud (**VPC** ) is a cloud computing model that combines the privacy and control of a private cloud with the scalability and flexibility of a public cloud.  

* **Isolation and Security**: Keeps data and applications secure and separate from others.
* **Customizable Networking**: Allows to define your virtual network, including IP ranges and subnets.
* **Scalability**: Easily adjusts resources.
* **Hybrid Integration**: Connects with on-premises data centers for a seamless hybrid cloud.
* **Advanced Features:** Includes NAT, VPN services, and more for enhanced network management.

Required Components for installation of Cloud Firewall for Nutanix AHV {#Required Components}
---------------------------------------------------------------------------------------------

Show / Hide this section  

|----------------------------------------------------------------------|----------------------------------------------------------------------------------------------------------------------------------------------------|
| Component                                                            | Description                                                                                                                                        |
| Security Management Server / Multi-Domain Security Management Server | The Check Point Security Management Server is the basic infrastructure managing Check Point Security Gateways.                                     |
| SmartConsole                                                         | SmartConsole is the new unified application of Check Point's Security Management.                                                                  |
| Nutanix Prism Central                                                | Prism Central is a multi-cluster manager responsible for managing multiple Nutanix Clusters to provide a single, centralized management interface. |

Prerequisites {#Prerequisites}
------------------------------

Show / Hide this section  

### Cloud Firewall Compatibility with Nutanix {#Toggle_doctable3}

|---------------------|---------------------|---------------------------------------------------------|---------------------|
| Nutanix AOS Version | Nutanix AHV Version | Nutanix Additional Component                            | Check Point Version |
| 6.10                | 20230302.102001     | Flow Virtual Networking - 4.0.0                         | R81.20              |
| 6.10.1              | 20230302.103003     | Flow Virtual Networking - 4.0.0                         | R82                 |
| 7.3                 | 10.3                | FVN (SR-IOV) - 6.0.0 FNS NG (Service Insertion) - 5.2.0 | R81.20              |
| 7.5                 | 11.0                | FVN (SR-IOV) - 7.0.0 FNS NG (Service Insertion) - 7.5.0 | R82                 |

Refer to the [Nutanix Compatibility Matrix](https://portal.nutanix.com/page/documents/compatibility-matrix/software) for more information.  

Recommended Topologies: {#Recommended Topologies}
-------------------------------------------------

### Tenant VPC Topology (E-W \& N-S) {#Tenant VPC}

Cloud Firewall Gateways are deployed in a High Availability (Active/Standby) cluster inside Tenant VPC with one data interface, one interface dedicated for Management, and one interface for HA (sync). The VPC policy is configured to reroute the Forward and Reverse traffic through the Cloud Firewall cluster's interface.  

<br />

![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk182972/Nut-Tenant202510201005571.png)  

<br />

|------|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| Item | Description                                                                                                                                                                                                        |
| 1    | The VM (Client) network traffic flows from the endpoint to the external network and reaches the Virtual Router (the logical unit, transparent from the endpoint view).                                             |
| 2    | The Virtual Router reroutes traffic from the client network to the Cloud Firewall ClusterXL for inspection. Traffic is routed back to the Virtual router from the Cloud Firewall cluster after policy enforcement. |
| 3    | Traffic flows to the external network.                                                                                                                                                                             |

<br />

<br />

### Transit VPC Topology (E-W \& N-S) {#Transit VPC}

Cloud Firewall Gateways are deployed in a High Availability (Active/Standby) cluster inside a Transit VPC with one data interface, one interface for Management, and one interface for HA. An Overlay external subnet is created in a Transit VPC and used as External Connectivity for the Cloud Firewall cluster's data interface. The VPC policy is configured to reroute the Forward and Reverse traffic through the Cloud Firewall cluster's interface.  

![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk182972/Nut-Transit202510201007152.png)  

|------|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| Item | Description                                                                                                                                                              |
| 1    | Data from other VPCs (VPC A and VPC B on the diagram) is sent to the external network. Traffic routes to the Virtual Router in the Transit VPC.                          |
| 2    | Virtual Router reroutes traffic to the Cloud Firewall for inspection. Traffic is routed back to the Virtual Router from the Cloud Firewall after the policy enforcement. |
| 3    | Traffic flows to the external network.                                                                                                                                   |

<br />

<br />

<br />

### Service Insertion 2.0 (E-W) {#Service Insertion}

**Prerequisites** :  

|--------------------------|------------------|
| Nutanix Component        | Version          |
| AOS                      | 7.3 and above    |
| Nutanix Prism Central    | pc.7.3 and above |
| Network Controller       | 6.0 and above    |
| Flow Network Security PC | 5.2.0 and above  |

<br />

In Nutanix Flow Network Security, you can direct each defined flow in an application policy through a Network Function. Service Insertion defines a set of Network Function VMs for advanced traffic processing. Network Function can direct network traffic on a specific port to a VM for antivirus scanning and deep packet inspection. Now you can create a pair of Network Function VMs for High Availability, Failover is handled by Nutanix data plane. Using ICMP Health probes to detect if the active Gateway is available

![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk182972/NF-Same-VLAN202509151544092.png)  
Switch ports connected to the Nutanix appliances should be configured as trunk ports, carrying both the management VLAN (native/untagged) and any additional VLANs. Ensure VLAN tagging is consistent between the switch and Nutanix network configuration.  

For additional information and deployment instructions for Service Insertion, follow the [Cloud Firewall for Nutanix Deployment Guide](https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CloudGuard_Network_for_Nutanix_DG/Content/Topics-Nutanix-DG-R81-10-Higher/Service-Insertion-2-0.htm?tocpath=_____6).  

Additional Resources {#Additional Resources}
--------------------------------------------

* [sk158292 - Cloud Firewall for Private Cloud images](https://support.checkpoint.com/results/sk/sk158292)
* [Cloud Firewall for Nutanix Deployment Guide](https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CloudGuard_Network_for_Nutanix_DG/Content/Topics-Nutanix-DG-R81-10-Higher/Introduction.htm)
* [Terraform modules for deploying Check Point Cloud Firewall in Nutanix environments](https://registry.terraform.io/modules/CheckPointSW/cloudguard-network-security/nutanix/latest)
* Youtube - [Cloud Firewall for Nutanix - Deep Dive](https://www.youtube.com/watch?v=G6jibZtmcoM)
* BrightTalk - [Cloud Firewall for Nutanix - Overview, Onboarding, and Best Practices](https://www.brighttalk.com/webcast/16731/651811)

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
