Check Point SASE Internet Access combines on device and cloud delivered protections to give users the fastest, most secure path to the internet. By inspecting traffic locally when possible and leveraging global PoPs when needed, it provides up to 10x faster browsing, more accurate location handling for SaaS and compliance, and stronger privacy by minimizing unnecessary data exposure. With AI driven threat prevention and advanced policy controls, organizations gain tighter security while users enjoy a seamless, high performance internet experience.
Check Point SASE Internet Access eliminates the limitations of traditional cloud-only and on-prem SWGs by delivering a hybrid, on-device-plus-cloud architecture that improves security, privacy, performance, and simplicity. It removes the need to compromise between protection and speed by enabling local on-device inspection when possible and cloud inspection when required, delivering up to 10x faster secure Internet access than cloud-only SWGs. Internet Access is simple to deploy and manage, and can run as a standalone solution or as part of the full Check Point SASE platform, which includes ZTNA, FWaaS, SaaS Security, Browser Security, and SD-WAN.
Key Advantages:
Single-pane-of-glass management for all SASE functions through the Check Point Portal, simplifying administration for AWS environments.
Hybrid on-device + cloud protection provides direct-to-Internet performance for AWS-hosted and SaaS applications, delivering up to 10x faster secure browsing than cloud-only SWGs.
Always-on protection, even off-network or on public Wi-Fi.
Full visibility into user web activity with granular filtering logs.
Category-based web filtering across both cloud inspection and on-device modes.
Support for multiple networks, allowing tailored policies across AWS workloads, branch offices, and remote users.
Split-tunnel traffic protection using on-device inspection to secure traffic that bypasses cloud gateways.
On-device SSL inspection for stronger privacy, no decryption inside third-party cloud centers.
Secure public Wi-Fi usage with multi-layer, AI-driven threat prevention.
Flexible policy controls, including user-based and time-based rules.
Zero infrastructure overhead, no on-prem hardware or maintenance.
Integrated features include Browser Security (DLP, file sanitization, phishing protection, GenAI governance) and SaaS Access Protection for account takeover prevention.
Highlights
HYBRID DEPLOYMENT: While typical deployments are either an on-prem appliance or cloud service, Check Point SASE Internet Access includes both on-device and cloud-based components. They work in concert to provide the highest level of Internet security for corporate users. Internet Access can also work in device- or cloud-only modes, enabling full flexibility for organizations to meet their security needs.
10X FASTER: On-device SSL inspection results in increased speed and a localized browsing experience. Internet Access delivers 10X faster performance, as proven in head-to-head tests.
GRANULAR WEB FILTERING: Check Point SASEs user-centric granular control extends to Web Filtering. Website access rules can be customized for different individuals or groups, and according to time of day. For example, social media sites can be blocked during work hours for all employees except for the social media management team. t team.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
Both dimensions cover Internet Access for 100 users on the Premium package, and you buy them as units under a contract. The difference lies in deployment. The On-Device Premium option secures web traffic directly on user devices. The Hybrid Premium option adds one SASE gateway, combining on-device protection with a network gateway. You pick based on how you want traffic inspected. Pricing scales by the 100-user unit, so you add units as your workforce grows.
Top-of-mind questions for buyers
What counts as one user for billing on these Premium packages?
Each package covers 100 users. A user is a single person you onboard through the cloud console, connecting from managed or unmanaged devices. You buy coverage in blocks of 100 users. To cover more people, you add more 100-user units.
What is the difference between the On-Device and Hybrid Premium options for my bill?
The On-Device option inspects web traffic directly on user devices, so you pay only for 100-user coverage. The Hybrid option adds one SASE gateway, combining on-device inspection with a network gateway. That gateway is bundled into the Hybrid unit, so it raises the per-unit price accordingly.
If my workforce grows beyond 100 users, how does the cost change?
Coverage scales in fixed 100-user blocks. When your headcount passes 100, you add another unit for the next group of users. The added unit charges at the same per-unit rate. There is no partial-block option, so you buy whole 100-user increments.
Request a private offer to receive a custom quote.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Check Point Endpoint Security is a comprehensive solution that unifies prevention, detection and response with unique prevention-first approach powered by ThreatCloud AI. As a consolidated solution, it supports all operating systems in a single client and management console. Because efficiency is crucial for today's challenges, Check Point Endpoint Security is a collaborative solution with easy integration to third parties to augment security effectiveness.
Check Point SASE Private Access provides secure, high-performance Zero Trust access to any application on-prem, in the cloud, or across multiple networks. It connects users, sites, and resources through a full-mesh global backbone with 85+ PoPs, delivering reliable, identity-centric access with device posture checks, network segmentation, and both agent-based and agentless options. Easily deployed in minutes and managed from a unified console, it simplifies remote access while strengthening security.
As organizations scale their SaaS ecosystems, securing sensitive data, identity access, and cross platform integrations becomes increasingly challenging. Check Point SaaS Security is an AI-powered SaaS protection and CASB solution that delivers API-level protection across your entire SaaS environment, providing real-time threat prevention, continuous posture management, identity-risk detection, and full SaaS discovery through a simple, cloud-native deployment.
Threat Prevention API: Integrate Check Point's ThreatCloud AI services to detect various malware types, including advanced malware in email attachments and web downloads, through a simple API.
Reputation API: Utilize Check Point's ThreatCloud AI intelligence to enhance your Security Operations, securing applications and websites with RESTful APIs. The Reputation API allows users to check the reputation of URLs, file hashes, and IP addresses.
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.