> Source: [sk184394](https://support.checkpoint.com/results/sk/sk184394)

# sk184394 - Cloud Firewall for KVM Virtualization Platforms

| Property | Value |
|----------|-------|
| Solution ID | sk184394 |
| Date Created | 2025-12-02 |
| Last Modified | 2026-08-17 |
| Technical Level | General |
| Products | Cloud Firewall |
| Versions | R82.10, R81.10 (EOS), R81.20, R82 |
| Platform | KVM |

## Solution

### Overview

This article describes Check Point Cloud Firewall (formerly CloudGuard Network) solutions for KVM Virtualization Platforms. It provides guidance, best practices, and solutions for known issues.  

**IMPORTANT:** You can configure KVM in many different ways. The configuration depends on your deployment platform. Check Point recommends testing your scenarios and architecture designs before deploying to production.  

Also, it is important to note that our solution is expected to work properly on any KVM environment, **as long as the kernel version is supported by Gaia** (see the supported KVM kernel versions in the [HCL](https://www.checkpoint.com/support-services/hcl/#virtual-machines)), regardless of the exact underlying Linux distribution (RHEL, CentOS, Oracle, Alma Linux, Debian, SUSE, Rocky, etc.)  

* **Supported Check Point Versions:**R81.10, R81.20, R82, R82.10
* **Supported KVM Virtualization Platforms:** **Note:** This list is not complete. Other KVM platforms may also work.
  * Red Hat OpenShift Virtualization
  * Proxmox
  * Nutanix
  * OpenStack
  * HPE VM Essentials
  * Equinix Network Edge
  * Megaport Virtual Edge
  * StackIT
  * IONOS
  * Cisco NFVIS
  * IBM Cloud
  * SUSE Harvester
  * OVHcloud
  * Native KVM for Red Hat, SUSE, CentOS, Debian Operating Systems
* **Supported Check Point Deployments:**   
  * Security Management Server
  * Multi-Domain Management Server
  * Multi-Domain Log Server
  * Single Gateway
  * High Availability Cluster
  * Active/Active Cluster
* **Licensing:** BYOL (Bring Your Own License) licensing model is applied.
  * For Security Gateways, the license quantity must equal the total number of cores assigned to all deployed Cloud Firewall Gateways.
    *
      * Available SKUs:
        * CPSG-VSEC-VEN-BUN-NGTP-1Y
        * CPSG-VSEC-VEN-BUN-NGTX-1Y
  * For Security Management Servers, standard licensing requirements apply.
* **Supported Network Interface Drivers:**
  * VIRTIO
  * SR-IOV
* **Maximum Physical Interfaces:**
  * 10 physical interfaces (additional interface support coming soon)
    * For R82, a fix is available to support additional physical interfaces, please follow [SK185133](https://support.checkpoint.com/results/sk/sk185133)
* **Prerequisites:** Before you begin, make sure that you have:
  * Expert knowledge of KVM administration and design
  * Downloaded the relevant Cloud Firewall qcow2 images (if required)
    * See [sk158292 - Cloud Firewall for Private Cloud images](https://support.checkpoint.com/results/sk/sk158292 "sk158292 - CloudGuard Network Security for Private Cloud images")
* **Limitations:**
  * If your Proxmox host machine uses Intel hardware, and you want to deploy R82.10, you must set the processor type to "host" to avoid a boot loop issue.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
