# Threat Prevention Software Blades in Security Gateways R82 and higher

Product: Anti-Bot, Anti-Virus, Threat Emulation, Zero Phishing  
Version: R82, R82.10  
OS: Gaia  
Last Modified: 2026-03-16

## Solution

### Overview

Starting from R82, when you create a new Security Gateway / Cluster object in Desktop SmartConsole, these Threat Prevention Software Blades are enabled by default:

|     |     |     |
| --- | --- | --- |
| Version of<br>Management Server | Version of<br>Security Gateway / Cluster | Threat Prevention Software Blades<br>that are enabled by default |
| R82 and higher | R82 and higher | - Anti-Bot & Advanced DNS<br>- Anti-Virus |
| R82.10 and higher | R82.10 and higher | - Threat Emulation<br>- Zero Phishing |

### Requirements

1. Security Management Server or Multi-Domain Security Management Server R82 and higher.
2. Security Gateway / Cluster Members R82 and higher.
3. In Desktop SmartConsole, go to the **Gateways & Servers** view, click **New** > select **Gateway** or **Cluster** > select **Classic Mode**.

### Supported Objects

- Security Gateway (all hardware platforms, including ElasticXL and Maestro).
- Cluster (all hardware platforms).
- VSNext Virtual Gateway (on ElasticXL or Maestro).

**Note** - Upgraded objects are not affected. For example, if you upgrade a Security Gateway version R81.20, with these Software Blades disabled, then after upgrade to R82, the Software Blades which were disabled prior to the upgrade will remain disabled.

### Known Limitations

- Threat Prevention Software Blades are **not** enabled automatically when you create a new Security Gateway / Cluster object in these ways:
  - In Desktop SmartConsole when you select the **Wizard Mode**.
  - In Web SmartConsole.
  - Using a Management API command ("`add simple-gateway`" / "`add simple-cluster`").
- Threat Prevention Software Blades are **not** enabled automatically on these devices:
  - Standalone (Security Gateway and Security Management Server on the same server).
  - Traditional VSX Gateway and Traditional VSX Virtual System.
  - Quantum Spark Gateway.
  - Full High Availability Cluster (ClusterXL and Security Management Server on the same server).

### How to disable the feature

You can prevent automatic enabling of these Threat Prevention Software Blades on the Management Server.

|     |     |     |
| --- | --- | --- |
| Action | Instructions | API Reference |
| Prevent automatic enabling of the **Anti-Bot** Software Blade | Run this Management API command on the Security Management Server / applicable Domain Management Server:<br>`mgmt_cli set threat-advanced-settings auto-enable-anti-bot disabled -r true` | [Link](https://sc1.checkpoint.com/documents/latest/APIs/index.html#cli/set-threat-advanced-settings) |
| Prevent automatic enabling of the **Anti-Virus** Software Blade | Run this Management API command on the Security Management Server / applicable Domain Management Server:<br>`mgmt_cli set threat-advanced-settings auto-enable-anti-virus disabled -r true` | [Link](https://sc1.checkpoint.com/documents/latest/APIs/index.html#cli/set-threat-advanced-settings) |
| Prevent automatic enabling of the **Threat Emulation** Software Blade | Run this Management API command on the Security Management Server / applicable Domain Management Server:<br>`mgmt_cli set threat-advanced-settings auto-enable-threat-emulation disabled -r true` | [Link](https://sc1.checkpoint.com/documents/latest/APIs/index.html#cli/set-threat-advanced-settings) |
| Prevent automatic enabling of the **Zero Phishing** Software Blade | Run this Management API command on the Security Management Server / applicable Domain Management Server:<br>`mgmt_cli set threat-advanced-settings auto-enable-zero-phishing disabled -r true` | [Link](https://support.checkpoint.com/results/sk/Link) |

## Article Properties

Access Level: General  
Status: Approved  
Date Created: 2024-03-17  
Last Modified: 2026-03-16
