> Source: [sk183294](https://support.checkpoint.com/results/sk/sk183294)

# sk183294 - Cloud Firewall - Terraform Registry Modules

| Property | Value |
|----------|-------|
| Solution ID | sk183294 |
| Date Created | 2025-04-06 |
| Last Modified | 2026-06-22 |
| Technical Level | General |
| Products | Cloud Firewall |
| Versions | R82.10, R81.10 (EOS), R81.20, R82 |
| Platform | VMWare ESX, AWS, Azure, Nutanix, GCP |

## Solution

**Table of Contents:**

* Overview
* Available Modules
* Prerequisites
* Usage
* Upgrading Module Versions

Overview {#TARGET_Overview}
---------------------------

Terraform Registry Modules for Check Point Cloud Firewall automate deployment of security and networking resources across cloud environments. These modules help to deploy cloud infrastructure following security best practices.

Terraform Registry Modules enforce consistent security policies in multi-cloud environments. They support common deployment scenarios such as setting up Virtual Private Clouds (VPCs), subnets, security groups, firewall rules, and other networking components. Pre-configured and customizable templates reduce configuration errors and accelerate secure cloud deployments.

Available Modules {#TARGET_Modules}
-----------------------------------

<br />

|--------------------------------------------------------------------------------------------------------------------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| Platform                                                                                                                 | Description                                                                                                                                                                                           | Link                                                                                                                                                                                                                                                                                                                                                                                                                                |
| **![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk182814/azure202411061625041.jpg)** **Azure**                      | This module creates and manages essential Azure resources for streamlined cloud infrastructure deployment.                                                                                            | |-------------------------------------------------------------------------------------------|-----------------------------------------------------------------------------------------------------------------| | ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk182814/terraform202411111749485.png) | [Terraform module](https://registry.terraform.io/modules/CheckPointSW/cloudguard-network-security/azure/latest) |     |
| **![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk182814/Amazon_Web_Services_Logo202411061625272.svg.png)** **AWS** | This module provisions and manages AWS infrastructure components including VPCs, subnets, security groups, and instances.                                                                             | |-------------------------------------------------------------------------------------------|---------------------------------------------------------------------------------------------------------------| | ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk182814/terraform202411111749485.png) | [Terraform module](https://registry.terraform.io/modules/CheckPointSW/cloudguard-network-security/aws/latest) |         |
| **![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk183294/google-cloud202601111129201.png) GCP**                     | This module automates provisioning of Check Point Cloud Firewalls and Security Management Servers in GCP, including the creation of Virtual Networks and High-Availability architectures.             | |-------------------------------------------------------------------------------------------|---------------------------------------------------------------------------------------------------------------| | ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk182814/terraform202411111749485.png) | [Terraform module](https://registry.terraform.io/modules/CheckPointSW/cloudguard-network-security/gcp/latest) |         |
| **![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk183294/pngegg202506241825363.png)** **VMware**                    | This module automates provisioning of Check Point Cloud Firewalls and Security Management Servers in VMware vSphere environments, simplifying secure infrastructure setup.                            | |-------------------------------------------------------------------------------------------|------------------------------------------------------------------------------------------------------------------| | ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk182814/terraform202411111749485.png) | [Terraform module](https://registry.terraform.io/modules/CheckPointSW/cloudguard-network-security/vmware/latest) |   |
| ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk183294/Nutanix202601041445541.png) **Nutanix**                      | This module automates the creation of Tenant Virtual Private Cloud (VPC), Transit-VPC, Check Point Cloud Firewalls and Security Management servers and more, simplifying secure infrastructure setup. | |-------------------------------------------------------------------------------------------|-------------------------------------------------------------------------------------------------------------------| | ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk182814/terraform202411111749485.png) | [Terraform module](https://registry.terraform.io/modules/CheckPointSW/cloudguard-network-security/Nutanix/latest) | |

<br />

Prerequisites {#TARGET_Prerequisites}
-------------------------------------

Before using Terraform Registry Modules, make sure these requirements are met:

* Terraform is installed (for more information, see the [Terraform Installation Guide](https://developer.hashicorp.com/terraform/tutorials/aws-get-started/install-cli)).

* You have an account with a corresponding cloud provider.

* You have resource provisioning permissions on your cloud account.

Usage {#TARGET_Usage}
---------------------

<br />

Click Here to Show the Entire Article

<br />

### Step 1: Set Environment Variables and Authenticate

Show / Hide this section  
> Authenticate with your cloud provider using CLI.
>
> **AWS Authentication:**
> `export AWS_ACCESS_KEY_ID=your-access-key`  
> `export AWS_SECRET_ACCESS_KEY=your-secret-key`  
> `aws configure`
>
> This allows Terraform authenticate with your AWS account.
>
> **Azure Authentication:**
> `az login`  
> `az account set --subscription "your-subscription-id"`
>
> This allows Terraform authenticate with your Azure subscription.
>
> **GCP Authentication:**
> `gcloud auth application-default login`  
> `gcloud config set project "your-project-id"`
>
> This allows Terraform authenticate with your GCP project.
>
> **VMware Authentication:**
> `export VSPHERE_USER="your_vsphere_username"`  
> `export VSPHERE_PASSWORD="your_vsphere_password"`  
> `export VSPHERE_SERVER="your_vsphere_server"`
>
> This allows Terraform authenticate with your VMware environment.  
>
> **Nutanix Authentication:**   
>
> `export NUTANIX_USER="your_nutanix_username"`  
> `export NUTANIX_PASSWORD="your_nutanix_password"`  
> `export NUTANIX_ENDPOINT="your_prism_central_server"`  
>
> This allows Terraform authenticate with your Nutanix environment.

### Step 2: Initialize Terraform

Show / Hide this section  
> Initialize Terraform to download necessary cloud provider plugins and modules:
> `terraform init`
>
> This command sets up the working directory for Terraform and makes sure that all required dependencies are downloaded.

### Step 3: Choose a Submodule to Deploy

Show / Hide this section  
> Visit [AWS Modules](https://registry.terraform.io/modules/CheckPointSW/cloudguard-network-security/aws/latest), [Azure Modules](https://registry.terraform.io/modules/CheckPointSW/cloudguard-network-security/azure/latest), [GCP modules](https://registry.terraform.io/modules/CheckPointSW/cloudguard-network-security/gcp/latest), [VMware Modules](https://registry.terraform.io/modules/CheckPointSW/cloudguard-network-security/vmware/latest), or [Nutanix Modules](https://registry.terraform.io/modules/CheckPointSW/cloudguard-network-security/Nutanix/latest) documentation and select an appropriate submodule.
>
> Click "submodules" and select one:
> ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk183294/Terraform_submodules202504061413352.png)
>
> Copy the source from the submodule's page:
> ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk183294/Terraform_step3202504061413553.png)

### Step 4: Configure the Module

Show / Hide this section  
> Define the required configuration for the module with input variables and provider information.
>
> **Example for AWS:**
> `provider "aws" {`  
> ` region = "us-east-1"`  
> `}`  
> `# Paste the source`  
> `module "aws_module" {`  
> ` source = "CheckPointSW/cloudguard-network-security/aws..."`  
> ` version = "latest"`  
> ` # Add required variables here`  
> `}`
>
> **Example for Azure:**
> `provider "azurerm" {`  
> ` features {}`  
> `}`  
> `# Paste the source`  
> `module "azure_module" {`  
> ` source = "CheckPointSW/cloudguard-network-security/azure..."`  
> ` version = "latest"`  
> ` # Add required variables here`  
> `}`
>
> **Example for GCP:**
> `provider "google" {`  
> ` credentials = "path/to/service-account-key.json"`  
> ` project = "your-project-id"`  
> ` region = "your-region"`  
> `}`  
> `# Paste the source`  
> `module "example_module" {`  
> ` source = "CheckPointSW/cloudguard-network-security/gcp//modules/{module_name}"`  
> ` version = "{chosen_version}"`  
> ` # Add the required variables here`  
> `}`  
>
> **Example for VMware:**
> `provider "vsphere" {}`  
> `module "example_module" {`  
> ` source = "CheckPointSW/cloudguard-network-security/vmware..."`  
> ` version = "latest"`  
> ` # Add required variables here`  
> `}`
>
> <br />
>
> **Example for Nutanix:**
>
>     provider "nutanix" {} module "example_module" {   source  = "CheckPointSW/cloudguard-network-security/nutanix//modules/{module_name}"   version = "{chosen_version}"   # Add the required inputs } 
>
> Make sure all required variables are provided according to the module's documentation.

### Step 5: Validate the Configuration (Optional)

Show / Hide this section  
> Before applying the configuration, check it for syntax errors:
> `terraform validate`
>
> This command checks for any misconfigurations or errors in "`.tf`" files.

### Step 6: Preview the Execution Plan

Show / Hide this section  
> Run this command to generate and inspect the execution plan:
> `terraform plan`
>
> This allows you to review the changes before applying.

### Step 7: Apply the Configuration

Show / Hide this section  
> Run this command to deploy the infrastructure:
> `terraform apply`
>
> This step provisions the resources defined in the module.
>
> **Note:** The Terraform "apply" command might vary depending on the submodule configurations. Use additional instructions provided in the submodules' documentation to ensure correct usage and handling of the resources.

### Step 8: Verify Deployment

Show / Hide this section  
> Once the deployment is complete, check created resources in your cloud provider's console.

### Step 9: View Module Outputs (Optional)

Show / Hide this section  
> To view the outputs defined by the module, create an `outputs.tf` file with the following structure:
> `output "instance_public_ip" {`  
> ` value = module.aws/azure/gcp/vmware/nutanix_module.instance_public_ip`  
> `}`
>
> Then, run:
> `terraform output`
>
> This prints the relevant outputs to the terminal for reference.

### Step 10: Destroy the Infrastructure (Optional)

Show / Hide this section  
> Run this command to remove the deployed infrastructure if needed:
>
> `terraform destroy`
>
> This deletes all resources managed by Terraform.

Upgrading Module Versions {#TARGET_Upgrading}
---------------------------------------------

<br />

Click Here to Show the Entire Article

<br />

To upgrade to a newer version of the Terraform module, do these steps:

### Step 1: Review Changes in the New Version

Show / Hide this section  
> Before upgrading, check the changelog or release notes of the module to understand what has changed:
>
> * Check the Terraform Registry for updated module documentation.
> * Review breaking changes, new input variables, or updated output values.

### Step 2: Update Module Version

Show / Hide this section  
> Modify the module definition in your Terraform configuration file to use the new version.
>
> **AWS example:**
>
> `module "aws_module" {`  
> ` source = "CheckPointSW/cloudguard-network-security/aws//modules/{module_name}"`  
> ` version = "x.x.x" # Update to the latest stable version`  
> `}`
>
> **Azure example:**
>
> `module "azure_module" {`  
> ` source = "CheckPointSW/cloudguard-network-security/azure//modules/{module_name}"`  
> ` version = "x.x.x" # Update to the latest stable version`  
> `}`
>
> **GCP example:**
>
> `module "gcp_module" {`  
> ` source = "CheckPointSW/cloudguard-network-security/gcp//modules/{module_name}"`  
> ` version = "x.x.x" # Update to the latest stable version`  
> `}`
>
> **VMware example:**
>
> `module "vmware_module" {`  
> ` source = "CheckPointSW/cloudguard-network-security/vmware//modules/{module_name}"`  
> ` version = "x.x.x" # Update to the latest stable version`  
> `}`
> **Nutanix example:** `module "nutanix_module" {`  
> ` source = "CheckPointSW/cloudguard-network-security/nutanix//modules/{module_name}"`  
> ` version = "x.x.x" # Update to the latest stable version`  
> `} `

### Step 3: Initialize and Plan the Upgrade

Show / Hide this section  
> Run these commands to get the new module and check for any unexpected changes:
>
> `terraform init -upgrade`  
> `terraform plan`  
>
> If there are breaking changes, resolve them before proceeding.

### Step 4: Apply the Upgrade

Show / Hide this section  
> Once you confirm that the upgrade is safe, apply the changes:
>
> `terraform apply`

### Step 5: Verify Deployment

Show / Hide this section  
> After upgrading, check the deployed infrastructure to make sure everything functions as expected.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
