Checkpoint Firewall - Specifications
Overview
This page describes the configuration and runtime parameters for Checkpoint Cloudguard. It covers supported flavors and images, interfaces and optional routing (BGP), virtual device parameters, and service-level inputs used during provisioning.
Flavors
The available compute profiles for this VNF are rendered below. Choose a flavor compatible with your selected software image (DPDK images require DPDK-capable flavors).
| Standard | DPDK | |
|---|---|---|
| Small | 2 vCPU 4 GB Mem | 2 vCPU 4 GB Mem |
| Medium | 4 vCPU 8 GB Mem | 4 vCPU 8 GB Mem |
| Large | 8 vCPU 16 GB Mem | 8 vCPU 16 GB Mem |
Software device versions
The software images available for this VNF are shown below. Select the exact image name when creating the virtual device.
- 81.20
Interfaces
The diagram above shows a single virtual device with an Internet-facing interface and an MPLS-VPN interface that aggregates optional VLAN sub-interfaces. In dual deployment mode the platform deploys two virtual devices (one per site).
Common interface behavior:
- The platform assigns a public IPv4 address to the Internet-facing interface; this is a platform-generated output and not provided by the customer during create.
- The MPLS-VPN interface uses VLAN sub-interfaces (101–108). Each VLAN can carry one or more VPN entries.
- BGP is optional and configured per VPN entry when required.
#1 - Internet Interface
The #1 - Internet Interface is the public/Internet-facing interface for the virtual device. The platform allocates a Public IPv4 address and displays it in the portal/API after deployment. Customers do not provide the public address at order time.
#2 - MPLS-VPN interface
The #2 - MPLS-VPN interface is optional and supports VLAN sub-interfaces (VLAN 101..108). For each VLAN you may provide a list of VPN entries to bind that VLAN to one or more MPLS VPNs.
Key items for VLAN sub-interfaces:
- VPN list: one or more VPN entries (min 1, max 99) per VLAN. Each entry identifies the VPN to attach to the VLAN.
- VPN Name: the VPN alias string used by Orange (pattern: alphanumeric, dash or underscore).
- VPN role: one of any-to-any, client, server; choose the role that matches your VPN design.
- Enable BGP: a per-VPN boolean (default false). When enabled, provide the required BGP parameters for that VPN entry.
- AS prepend: an optional integer (1–6). The blueprint documents this parameter as applicable for backup VM scenarios; treat it as a field-level advanced option.
Routing / BGP
The BGP settings are optional and configurable per VPN entry on the MPLS VLANs. When Enable BGP is not selected, no BGP-specific configuration is applied through this setting. If you enable BGP, provide the necessary AS numbers and related parameters; AS prepend is an optional tuning parameter with allowed values 1..6.
Virtual device parameters
Provide these parameters when creating the virtual device:
- VM name (hostname): required. Use a hostname matching the allowed pattern (alphanumeric and hyphen) and up to the platform's length limit.
- VM image: required. Choose one of the images listed in the Software section (for example, Cloudgard_Checkpoint_R81.20 or Cloudgard_Checkpoint_R81.20_DPDK). DPDK image variants require DPDK-capable flavors.
- Flavor: required. Select a flavor that matches your performance needs and is compatible with the chosen image (standard and DPDK flavor families are available).
- Disk size (GB): optional. Specify a root disk size between 16 and 500 GB if you need a non-default volume size.
- VM AS number: optional. Provide an Autonomous System (AS) number if you plan to enable BGP (supports 2-byte and 4-byte AS numbers).
Service-specific parameters
Service-specific parameters are service-level credentials and values injected during provisioning (they are not VM-level network addresses).
-
Admin password
- General meaning: administrator credential for device access.
- For this VNF: the admin password is injected into the cloud-init template and becomes the initial device administrator password.
- Required: yes. Updatable after provisioning: no.
- Customer action: provide a secure password at order time.
-
Maintenance password
- General meaning: credential intended for maintenance or vendor support access.
- For this VNF: injected into cloud-init to satisfy vendor maintenance account requirements.
- Required: yes. Updatable: no.
- Customer action: provide a secure maintenance password if requested by your support teams.
-
SIC KEY
- General meaning: vendor shared key for secure device pairing.
- For this VNF: provide the Checkpoint SIC key only if required by your Checkpoint management process; the platform will inject it into the cloud-init template if supplied.
- Required: no. Updatable: no.
- Customer action: provide only when requested by Checkpoint or your managed services team.
Platform-generated outputs
- Public IPv4 (platform-assigned): the platform assigns a public IPv4 address for the Internet interface. This address appears in deployment results and in the portal/API after provisioning.
Useful links
Licence
Only Bring Your Own Licence (BYOL) type is supported for Fortinet SDWAN. You need to purchase your software licence with Fortinet sales.
Security group
No default security group configured for Fortinet VNE model.