Checkpoint Firewall - Specifications
Overview
This page describes the configuration and runtime parameters for Checkpoint Cloudguard. It covers supported flavors and images, interfaces and optional routing (BGP), virtual device parameters, and service-level inputs used during provisioning.
Flavors
The available compute profiles for this VNF are rendered below. Choose a flavor compatible with your selected software image (DPDK images require DPDK-capable flavors).
| Standard | DPDK | |
|---|---|---|
| Small | 2 vCPU 4 GB Mem | 2 vCPU 4 GB Mem |
| Medium | 4 vCPU 8 GB Mem | 4 vCPU 8 GB Mem |
| Large | 8 vCPU 16 GB Mem | 8 vCPU 16 GB Mem |
Software device versions
The software images available for this VNF are shown below. Select the exact image name when creating the virtual device.
- 81.20
Interfaces
The diagram above shows a single virtual device with an Internet-facing interface and an MPLS-VPN interface that aggregates optional VLAN sub-interfaces. In dual deployment mode the platform deploys two virtual devices (one per site).
Common interface behavior:
- The platform assigns a public IPv4 address to the Internet-facing interface; this is a platform-generated output and not provided by the customer during create.
- The MPLS-VPN interface uses VLAN sub-interfaces (101–108). Each VLAN can carry one or more VPN entries.
- BGP is optional and configured per VPN entry when required.
#1 - Internet Interface
The #1 - Internet Interface is the public/Internet-facing interface for the virtual device. The platform allocates a Public IPv4 address and displays it in the portal/API after deployment. Customers do not provide the public address at order time.