diff --git a/china/aws/images/launch.png b/china/aws/images/launch.png new file mode 100755 index 00000000..b16d779c Binary files /dev/null and b/china/aws/images/launch.png differ diff --git a/china/aws/images/step1_aws.png b/china/aws/images/step1_aws.png new file mode 100755 index 00000000..a626c705 Binary files /dev/null and b/china/aws/images/step1_aws.png differ diff --git a/china/aws/images/step2_aws.png b/china/aws/images/step2_aws.png new file mode 100755 index 00000000..aeebc82a Binary files /dev/null and b/china/aws/images/step2_aws.png differ diff --git a/china/aws/templates/README.md b/china/aws/templates/README.md new file mode 100644 index 00000000..ca3d533b --- /dev/null +++ b/china/aws/templates/README.md @@ -0,0 +1,454 @@ +
The table below lists CloudFormation templates provided and maintained by Check Point that simplify the deployment of Check Point security solutions in AWS.
+You can use these templates as-is or as building blocks for customizing your own templates.
+Notes:
+You must accept the Software Terms of the relevant Check Point Product AMI in the AWS Marketplace at least once prior to launching the CloudFormation templates. It is not required to actually launch the instance from the Marketplace, but the agreement must be accepted from this location.
+此模板中的镜像使用“西云数据”发布的最新版本镜像文件,使用此模板前请先在AWS中国镜像市场订阅相关镜像,使用西云数据镜像部署的产品需要联系Check Point与AWS的销售已得到正确的许可证
+国际版AWS使用的CloudFormation Templates请直接访问Check Point官网SK111013 Check Point SK111013 +
+For R81.20 and higher versions, Gateway Load Balancer (GWLB) and Gateway images are unified. They use the same Product AMI in the AWS Marketplace.
+Table of Contents
+ +| Description | +Notes | +Version | +Terraform Template | +CloudFormation Template Download | +Direct Launch | +
| Deploys and configures an AWS Auto Scaling group configured for Gateway Load Balancer in a Centralized Security VPC. For more details, refer to CloudGuard Network for AWS Centralized Gateway Load Balancer R80.40 Deployment Guide |
+Creates a new VPC and deploys into it a Gateway Load Balancer, Check Point CloudGuard IaaS Security Gateway Auto Scaling Group, and optionally a Security Management Server. | +R81.20 R82 |
+|||
| Deploys a Gateway Load Balancer, Check Point CloudGuard IaaS Security Gateway Auto Scaling Group, and optionally a Security Management Server into an existing VPC. | +|||||
| Deploys and configures an AWS Auto Scaling group configured for Gateway Load Balancer in a Centralized Security VPC for Transit Gateway. For more details, refer to CloudGuard Network for AWS Gateway Load Balancer Security VPC for Transit Gateway R80.40 Deployment Guide |
+Creates a new VPC and deploys into it a Gateway Load Balancer, Check Point CloudGuard IaaS Security Gateway Auto Scaling Group, and optionally a Security Management Server, Gateway Load Balancer Endpoints and NAT Gateways for each AZ, for Transit Gateway. | +R81.20 R82 |
+|||
| Deploys a Gateway Load Balancer, Check Point CloudGuard IaaS Security Gateway Auto Scaling Group, and optionally a Security Management Server, Gateway Load Balancer Endpoints and NAT Gateways for each AZ, for Transit Gateway into an existing VPC. | +
| Description | +Notes | +Version | +Terraform Template | +CloudFormation Template Download | +Direct Launch | +
| Deploys and configures a Security Gateway. To deploy the Security Gateway so that it will be automatically provisioned, refer to sk131434. |
+Creates a new VPC and deploys a Security Gateway into it. | +R81.20 R81.10 R82 |
+![]() |
+![]() |
+![]() |
+
| Deploys a Security Gateway into an existing VPC. | +![]() |
+![]() |
+![]() |
+
+
| Description | +Notes | +Version | +Terraform Template | +CloudFormation Template Download | +Direct Launch | +
| Deploys and configures two Security Gateways as a Cluster. For more details, refer to the CloudGuard Network for AWS Security Cluster R80.20 and Higher Deployment Guide. |
+Creates a new VPC and deploys a Cluster into it. | +R81.20 R81.10 R82 |
+![]() |
+![]() |
+![]() |
+
| Deploys a Cluster into an existing VPC. | +![]() |
+![]() |
+![]() |
+
+
| Description | +Notes | +Version | +Terraform Template | +CloudFormation Template Download | +Direct Launch | +
| Deploys and configures the Security Gateways as an AWS Auto Scaling group. For more details, refer to the CloudGuard Network Auto Scaling for AWS R80.20 and Higher Deployment Guide. |
+Deploys an Auto Scaling group of Security Gateways into an existing VPC. | +R81.20 R81.10 R82 |
+![]() |
+![]() |
+![]() |
+
+
| Description | +Notes | +Version | +Terraform Template | +CloudFormation Template Download | +Direct Launch | +
| Deploys and configured the Security Gateways as an AWS Auto Scaling group configured for Transit Gateway. For more details, refer to AWS Transit Gateway R80.10 and above Deployment Guide. |
+Creates a new VPC and deploys an Auto Scaling group of Security Gateways configured for Transit Gateway into it, and an optional, preconfigured Security Management Server to manage them. | +R81.20 R81.10 R82 |
+![]() |
+![]() |
+![]() |
+
| Deploys an Auto Scaling group of Security Gateways configured for Transit Gateway into an existing VPC, and an optional, preconfigured Security Management Server to manage them. | +![]() |
+![]() |
+![]() |
+
| Description | +Notes | +Version | +Terraform Template | +CloudFormation Template Download | +Direct Launch | +
|
+ Deploys two Security Gateways, each in a different Availability Zone. |
+Creates a new VPC and deploys a Cross Availability Zone Cluster of Security Gateways into it. | +R81.20 R82 |
+![]() |
+![]() |
+![]() |
+
| Deploys a Cross Availability Zone Cluster of Security Gateways into an existing VPC. | +![]() |
+![]() |
+![]() |
+||
|
+ Deploys two Security Gateways, each in a different Availability Zone. |
+Creates a new VPC and deploys a Cross Availability Zone Cluster of Security Gateways into it. | +R81.10 R81 R80.40 |
++ | ![]() |
+![]() |
+
| Deploys a Cross Availability Zone Cluster of Security Gateways into an existing VPC. | +![]() |
+![]() |
+
| Description | +Notes | +Version | +Terraform Template | +CloudFormation Template Download | +Direct Launch | +
|
+ Deploys two Security Gateways, each in a different Availability Zone, configured for Transit Gateway. +For more details, refer to Cross Availability Zone Cluster for AWS R81.20 Administration Guide + |
+Creates a new VPC and deploys a Cross Availability Zone Cluster of Security Gateways configured for Transit Gateway into it. | +R81.20 R82 |
+![]() |
+![]() |
+![]() |
+
| Deploys a Cross Availability Zone Cluster of Security Gateways configured for Transit Gateway into an existing VPC. | +![]() |
+![]() |
+![]() |
+||
|
+ Deploys two Security Gateways, each in a different Availability Zone, configured for Transit Gateway. +For more details, refer to CloudGuard Transit Gateway High Availability for AWS R80.40 Administration Guide + |
+Creates a new VPC and deploys a Cross Availability Zone Cluster of Security Gateways configured for Transit Gateway into it. | +R81.10 R81 R80.40 |
++ | ![]() |
+![]() |
+
| Deploys a Cross Availability Zone Cluster of Security Gateways configured for Transit Gateway into an existing VPC. | +![]() |
+![]() |
+
| Description | +Notes | +Version | +Terraform Template | +CloudFormation Template Download | +Direct Launch | +
| Deploys and configures a Security Management Server. For more details, refer to sk130372. |
+Deploys a Security Management Server into an existing VPC. | +R81.20 R81.10 R82 |
+![]() |
+![]() |
+![]() |
+
+
| Description | +Notes | +Version | +Terraform Template | +CloudFormation Template Download | +Direct Launch | +
| Deploys and configures a Multi-Domain Security Management Server.
+ For more details, refer to sk143213. + |
+Deploys a Multi-Domain Security Management Server into an existing VPC. | +R81.20 R81.10 R82 |
+![]() |
+![]() |
+![]() |
+
| Description | +CloudFormation Template Download | +Terraform Template | +Direct Launch | +
| Create an Instance profile for Security Management Server + Creates an Instance profile in your account preconfigured with permissions to manage resources. +For more details, refer to sk122074. + |
+![]() |
+![]() |
+![]() |
+
| Current Check Point AMIs
+ A helper template that returns the latest Check Point AMIs in a given region. + |
+![]() |
++ | ![]() |
+
CloudFormation templates for previous versions can be found in the CloudGuard Network Security GitHub repository.
+Notes:
+| Description | +Notes | +Direct Launch | +
|---|---|---|
|
+ Deploys and configures the Security Gateways as an AWS Auto Scaling group. For more details, refer to the CloudGuard Network Auto Scaling for AWS R80.20 and Higher Deployment Guide . + |
+ Deploys an Auto Scaling group of Security Gateways into an existing VPC. | +![]() |
+
| Description | +Notes | +Direct Launch | +
|---|---|---|
|
+ Deploys and configures two Security Gateways as a Cluster. For more details, refer to the CloudGuard Network for AWS Security Cluster R80.20 and Higher Deployment Guide. + |
+ Creates a new VPC and deploys a Cluster into it. | +![]() |
+
| Deploys a Cluster into an existing VPC. | +![]() |
+
| Description | +Notes | +Direct Launch | +
|---|---|---|
|
+ Deploys two Security Gateways, each in a different Availability Zone. For more details, refer to Cross Availability Zone Cluster for AWS R81.20 Administration Guide. + |
+ Creates a new VPC and deploys a Cross Availability Zone Cluster of Security Gateways into it. | +![]() |
+
| Deploys a Cross Availability Zone Cluster of Security Gateways into an existing VPC. | +![]() |
+
| Description | +Direct Launch | +
|---|---|
|
+ Create an IAM role for Security Management Server + Creates an IAM role in your account preconfigured with permissions to manage resources. + For more details, refer to sk122074 . + |
+ ![]() |
+
|
+ Current Check Point AMIs + A helper template that returns the latest Check Point AMIs in a given region. + |
+ ![]() |
+
| Description | +Notes | +Direct Launch | +
|---|---|---|
|
+ Deploys two Security Gateways, each in a different Availability Zone. For more details, refer to CloudGuard Transit Gateway High Availability for AWS R80.40 Administration Guide. + |
+ Creates a new VPC and deploys a Cross Availability Zone Cluster of Security Gateways into it. | +![]() |
+
| Deploys a Cross Availability Zone Cluster of Security Gateways into an existing VPC. | +![]() |
+
| Description | +Notes | +Direct Launch | +
|---|---|---|
|
+ Deploys and configures an AWS Auto Scaling group configured for Gateway Load Balancer in a Centralized Security VPC. For more details, refer to CloudGuard Network for AWS Centralized Gateway Load Balancer R80.40 Deployment Guide. + |
+ Creates a new VPC and deploys into it a Gateway Load Balancer, Check Point CloudGuard IaaS Security Gateway Auto Scaling Group, and optionally a Security Management Server. | +![]() |
+
|
+ Deploys and configures an AWS Auto Scaling group configured for Gateway Load Balancer in a Centralized Security VPC. For more details, refer to CloudGuard Network for AWS Centralized Gateway Load Balancer R80.40 Deployment Guide. + |
+ Deploys a Gateway Load Balancer, Check Point CloudGuard IaaS Security Gateway Auto Scaling Group, and optionally a Security Management Server into an existing VPC. | +![]() |
+
|
+ Deploys and configures an AWS Auto Scaling group configured for Gateway Load Balancer in a Centralized Security VPC for Transit Gateway. For more details, refer to CloudGuard Network for AWS Gateway Load Balancer Security VPC for Transit Gateway R80.40 Deployment Guide. + |
+ Creates a new VPC and deploys into it a Gateway Load Balancer, Check Point CloudGuard IaaS Security Gateway Auto Scaling Group, and optionally a Security Management Server, Gateway Load Balancer Endpoints and NAT Gateways for each AZ, for Transit Gateway. | +![]() |
+
|
+ Deploys and configures an AWS Auto Scaling group configured for Gateway Load Balancer in a Centralized Security VPC for Transit Gateway. For more details, refer to CloudGuard Network for AWS Gateway Load Balancer Security VPC for Transit Gateway R80.40 Deployment Guide. + |
+ Deploys a Gateway Load Balancer, Check Point CloudGuard IaaS Security Gateway Auto Scaling Group, and optionally a Security Management Server, Gateway Load Balancer Endpoints and NAT Gateways for each AZ, for Transit Gateway into an existing VPC. | +![]() |
+
|
+ Deploys and configures a Quick Start AWS Auto Scaling Group configured for Gateway Load Balancer in a Centralized Security VPC, and Servers in Servers VPC For more details, refer to CloudGuard Network for AWS Centralized Gateway Load Balancer R80.40 Deployment Guide. + |
+ Creates a new Security VPC with Gateway Load Balancer, Check Point CloudGuard IaaS Security Gateway Auto Scaling Group, Servers' VPC with Gateway Load Balancer Endpoints (1 per Availability Zone), Application Load Balancer in Servers' VPC, Servers and optionally a Security Management Server. + | ![]() |
+
|
+ Deploys and configures a Quick Start AWS Auto Scaling Group configured for Gateway Load Balancer in a Centralized Security VPC, and Servers in Servers VPC. For more details, refer to CloudGuard Network for AWS Centralized Gateway Load Balancer R80.40 Deployment Guide. + |
+ Deploys a Gateway Load Balancer, Check Point CloudGuard IaaS Security Gateway Auto Scaling Group, optionally a Security Management Server into an existing Security VPC, Gateway Load Balancer Endpoints (1 per Availability Zone), Application Load Balancer and Servers into an existing Servers' VPC. + | +![]() |
+
| Description | +Notes | +Direct Launch | +
|---|---|---|
|
+ Deploys and configures a Security Management Server. For more details, refer to sk130372. + |
+ Deploys a Security Management Server into an existing VPC. | +![]() |
+
| Description | +Notes | +Direct Launch | +
|---|---|---|
|
+ Deploys and configures a Multi-Domain Security Management Server. For more details, refer to sk143213. + |
+ Deploys a Multi-Domain Security Management Server into an existing VPC. | +![]() |
+
| Description | +Notes | +Direct Launch | +
|---|---|---|
|
+ Deploys and configures a Security Gateway. To deploy the Security Gateway so that it will be automatically provisioned, refer to sk131434. + |
+ Creates a new VPC and deploys a Security Gateway into it. | +![]() |
+
| Deploys a Security Gateway into an existing VPC. | +![]() |
+
| Description | +Notes | +Direct Launch | +
|---|---|---|
|
+ Deploys and configured the Security Gateways as an AWS Auto Scaling group configured for Transit Gateway. For more details, refer to AWS Transit Gateway R80.10 and above Deployment Guide. + |
+ Creates a new VPC and deploys an Auto Scaling group of Security Gateways configured for Transit Gateway into it, and an optional, preconfigured Security Management Server to manage them. | +![]() |
+
| Deploys an Auto Scaling group of Security Gateways configured for Transit Gateway into an existing VPC, and an optional, preconfigured Security Management Server to manage them. | +![]() |
+
| Description | +Notes | +Direct Launch | +
|---|---|---|
|
+ Deploys two Security Gateways, each in a different Availability Zone, configured for Transit Gateway. For more details, refer to Cross Availability Zone Cluster for AWS R81.20 Administration Guide. + |
+ Creates a new VPC and deploys a Cross Availability Zone Cluster of Security Gateways configured for Transit Gateway into it. | +![]() |
+
| Deploys a Cross Availability Zone Cluster of Security Gateways configured for Transit Gateway into an existing VPC. | +![]() |
+
| Description | +Notes | +Direct Launch | +
|---|---|---|
|
+ Deploys two Security Gateways, each in a different Availability Zone, configured for Transit Gateway. For more details, refer to CloudGuard Transit Gateway High Availability for AWS R80.40 Administration Guide. + |
+ Creates a new VPC and deploys a Cross Availability Zone Cluster of Security Gateways configured for Transit Gateway into it. | +![]() |
+
| Deploys a Cross Availability Zone Cluster of Security Gateways configured for Transit Gateway into an existing VPC. | +![]() |
+