Deploy Check Point WAF in the FedRAMP Environment
Check Point WAF is available in a dedicated FedRAMP environment for US Government workloads and for organizations that must meet FedRAMP requirements. Protection, policy management, and the security engines work exactly as in the commercial environment, but the FedRAMP environment is a separate, isolated deployment, and a few deployment options are not yet available there.
Check the limitations below against the application you plan to protect before you onboard it. If any of them does not fit, talk to your Check Point representative first.
Deployment
Deploy as described in Deploy Enforcement Point. Three differences apply in the FedRAMP environment:
Log in to the FedRAMP Infinity Portal (not the commercial portal).
Enter application URLs without an explicit port, and do not point the asset at an existing CloudFront distribution.
Configure log export to your SIEM as part of onboarding, not after it is how your SOC sees WAF events.
Current limitations
A few deployment options available commercially are not yet available in the FedRAMP environment. Check these against the application you plan to protect before you onboard it — if one does not fit, talk to your Check Point representative.
Logs are export-only
Logs are exported to an external destination; they are not shown in the portal's log and event views. Investigations and any flow that starts from a log in the portal happen in your SIEM instead.
In-portal logs planned for Q1 2027
Non-standard ports are not supported
Applications must be served on the standard HTTP/HTTPS ports (80, 443). Move the application behind a standard port before onboarding.
No ETA
Timeouts longer than 9 minutes are not supported
Requests open beyond 9 minutes are terminated — typically large transfers, synchronous report generation, and long-polling endpoints. The fix is on the application side: make long operations asynchronous (return a job ID, let the client poll).
No ETA
Single POP only
One point of presence per deployment: no closer edge for geographically distant users, and no POP-level failover. Multi-region deployment is available in the commercial environment only.
No ETA
Existing CloudFront distributions are not supported
Bring-your-own-CloudFront (BYOC) is unavailable. Check Point WAF provisions and owns the distribution in front of your application, so plan to retire an existing one during cutover.
Last updated
Was this helpful?