Auto-create Checkpoint Firewall
Auto-create Checkpoint Firewall provisions a full Checkpoint NGFW stack into your VPC in one wizard. Use it when you need a managed next-gen firewall at the edge of a production network without building the hosts by hand.
What the wizard provisions
The wizard deploys four roles from a single Basic Configuration:
- Master — the active firewall gateway.
- Slave — a standby gateway, created only when you enable High Availability (HA).
- SMS — the Security Management Server that manages policy.
- Jump — a jump host with the management software image pre-installed.
Before you start
Provisioning fails if your VPC lacks free capacity. Read Checkpoint Firewall prerequisites and architecture first — it lists the free isolate subnets and public IPs you need, and explains how the four roles fit together.
Choose your path
- Fast path — you have provisioned firewalls before: Create a Checkpoint Firewall.
- Guided path — first time, or you want the HA and non-HA flows side by side: Tutorial: create a Checkpoint Firewall.
note
Only the Checkpoint firewall type is available today. Fortinet and Palo Alto are not yet supported.