> Source: [sk183726](https://support.checkpoint.com/results/sk/sk183726)

# sk183726 - Enhancing Cloud Security with CloudGuard Network in AWS Local Zones

| Property | Value |
|----------|-------|
| Solution ID | sk183726 |
| Date Created | 2025-08-01 |
| Last Modified | 2026-04-09 |
| Technical Level | General |
| Products | Cloud Firewall |
| Versions | R82.10, R81.20, R82 |
| OS | Gaia |
| Platform | AWS |

## Solution

Introduction
------------

As organizations move latency-sensitive applications to the edge of the cloud, **AWS Local Zones** extend AWS infrastructure closer to end users. By providing compute, storage, and select AWS services near major population centers, Local Zones support ultra-low-latency workloads while maintaining integration with the parent AWS Region.

What Are AWS Local Zones?
-------------------------

AWS Local Zones are infrastructure deployments that place compute, storage, and other services closer to large population centers. Each Local Zone is an extension of a parent AWS Region and is managed using standard AWS tools, APIs, and governance models.

* Ultra-low latency for edge workloads
* Local data processing for compliance-sensitive applications
* Improved user experience for real-time applications

Why Secure AWS Local Zones?
---------------------------

* **Expanded Attack Surface**- Decentralized workloads increase exposure points.
* **Latency Constraints** -Centralized inspection may introduce unacceptable delays.
* **Compliance Requirements**- Some Local Zones require localized inspection and data control.

Security controls must extend to the Local Zone so that protection follows the workload.

CloudGuard Network - Securing AWS Local Zones
---------------------------------------------

### 1. Dynamic Local Zone Detection and Enforcement

* Dynamic support for Local Zone Availability Zones (for example, `us-west-2-lax-1a`)
* Elastic IP allocation using the appropriate Network Border Group

### 2. Inline Threat Prevention at the Edge

* Low-latency traffic inspection within the Local Zone
* IPS, Application Control, URL Filtering, and Identity Awareness
* Zero-trust enforcement and zero-day protections at the edge

### 3. Unified Visibility and Management

* Centralized management using Smart-1 Cloud or SmartConsole
* Real-time policy monitoring and compliance auditing

Getting Started
---------------

1. Go to [sk111013 -- AWS CloudFormation Templates](https://support.checkpoint.com/results/sk/sk111013) to obtain the CloudFormation templates.
2. Confirm the supported instance and volume types for the selected Local Zone.
3. Deploy CloudGuard Network using the validated template.
4. Allocate and associate Elastic IPs in the appropriate Network Border Group (if required).
5. Integrate the Security Gateway with Smart-1 Cloud or an on-premises Security Management Server.

Supported CloudGuard Network Deployments
----------------------------------------

The following CloudGuard Network deployments are supported in AWS Local Zones (for **R81.20 and higher**):

* **Single Gateway**
* **Single Availability Zone Cluster**

Deployment templates and guidance are available in [sk111013 -- AWS CloudFormation Templates](https://support.checkpoint.com/results/sk/sk111013).

Important Deployment Considerations for Local Zones
---------------------------------------------------

### 1. Verify Local Zone Feature Support

* Each Local Zone supports a limited set of instance types and EBS volume types.
* **Example:** Perth, Australia (`ap-southeast-2-per-1a`) supports only specific instance types (for example, `c5.2xlarge`) and volume types (for example, `gp2`).
* Deploying unsupported instance or volume types results in CloudFormation failure.

For more information, see [AWS Local Zones Feature Support Matrix](https://aws.amazon.com/about-aws/global-infrastructure/localzones/features/).

### 2. Elastic IP (EIP) Deployment in Local Zones

When deploying a public Elastic IP (EIP) in a Local Zone, the EIP must be allocated within the **Network Border Group** corresponding to the Local Zone (for example, `us-west-2-lax-1`).

* CloudFormation templates support allocation of EIPs within the appropriate Network Border Group.
* If automatic allocation is not used, EIPs can be allocated and associated manually after deployment.

#### Manual EIP Allocation (If Required)

1. Open the AWS Console and navigate to **EC2 ? Elastic IPs**.
2. Select **Allocate Elastic IP**.
3. Choose the correct **Network Border Group** for the Local Zone.
4. Associate the EIP with the deployed CloudGuard Network instance.

Allocating an EIP in a different Network Border Group than the instance's Local Zone causes association failures.

AWS Reference Documentation
---------------------------

* [Hybrid Inspection Architectures with AWS Local Zones](https://aws.amazon.com/blogs/networking-and-content-delivery/hybrid-inspection-architectures-with-aws-local-zone/)
* [VPC User Guide -- Local Zones](https://docs.aws.amazon.com/vpc/latest/userguide/local-zone.html)
* [How AWS Local Zones Work](https://docs.aws.amazon.com/local-zones/latest/ug/how-local-zones-work.html)
* [Local Zone Feature Support Matrix](https://aws.amazon.com/about-aws/global-infrastructure/localzones/features/)

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
