sk94508 - Recommended Internet Access Settings for Automatic Downloads
Recommended Internet Access Settings for Automatic Downloads
Product: Multi-Domain Security Management, Security Gateways, Security Management
Version: R80.10 (EOS), R80.20 (EOS), R80.30 (EOS), R80.40 (EOS), R81 (EOS), R81.10 (EOS), R81.20, R82, R82.10
OS: Gaia
Last Modified: 2026-02-16
Solution
Table of Contents:
- Introduction
- Offline Mode Limitations
- Blade Contracts
- SmartConsole
- General
- Offline Mode Scope
Introduction
In the First Time Configuration Wizard on Gaia OS, you have the option to enable or disable automatic downloads of Blade Contracts, Check Point Releases / Hotfixes via CPUSE, and data for complete functionality of Software Blades and features.
It is highly recommended that you keep this option enabled to ensure the smooth operation of Check Point products.
Notes:
- The type of downloaded data may change from version to version.
- Before the Check Point Quantum Security Gateway and/or Management Server can automatically download the necessary software packages from the Check Point cloud, your device must share the following technical data with Check Point:
- The installed license
- The installed software version
- The hardware platform, MAC Address, and Serial Number
If you choose to disable this automatic download feature, the product will not be able to download the packages automatically. In such a case, you will need to manually download and install the desired packages per the information detailed in the relevant articles in the Check Point Support Center.
Offline Mode Limitations
Blade Contracts
Blade Contracts are annual blade licenses. Their renewal, from the UserCenter, is necessary for complete product functionality. If you disable this setting, Blade Contracts cannot be automatically updated. If your local contract is missing or expired, these limitations apply:
Blade / Feature Limitation Threat Emulation local mode Files will not be emulated. Data Loss Prevention blade Will operate in Bypass mode if there is no valid contract installed on Security Gateway
(the contract can be installed manually via SmartUpdate, and DLP will enforce its policy on the traffic).Compliance blade Will not execute scans. Endpoint Security Policy Management License report in SmartEndpoint will not be accurate. CPinfo Self-update is not applicable.
SmartConsole
Blade / Feature Limitation IPS - IPS updates from UserCenter will fail. Application & URL Filtering - AppWiki will not work.
- No update of "Messages and Actions" frame in Overview view.
- No update of the applications picker in the Policy view.
- Search for categorization of sites via overview tab will fail.Threat Prevention - ThreatWiki will not work.
- No protections picker in Global Exceptions view.
- No Protections view.
- No search for malware from Overview.
- No RSS feed.Threat Emulation - No image and file type updates.
General
- Trusted Certificate Authorities (CAs) list will not be updated.
- No update of Check Point certificate bundle.
- Relevant upgrade packages will not be shown by CPUSE Agent (in Gaia Portal / Gaia Clish).
Offline Mode Scope
Even in Offline mode, if an activated Software Blade requires external services, it will still connect to Check Point Cloud to get the required data:
Blade / Feature Limitation IPS - Download Geo protection updates
- Download malicious IPs lists
- Validate Blade contract entitlementApplication Control - Download applications database
- Detect social network widgets
- Run and return results of cloud-based application analysis
- Validate Blade contract entitlementURL Filtering - Download initial local database
- Run and return results of cloud-based categorization
- Validate Blade contract entitlementHTTPS Inspection - Update bypass list Anti-Spam,
Anti-Bot,
Anti-Virus- Download updates to the local signature database
- Run and return results of cloud-based security analysis
- Validate Blade contract entitlementCompliance - Download latest regulations and best practices Endpoint Policy Management - Download updates to the malware database Endpoint Anti-Malware - Run and return results of cloud-based malware categorization Endpoint Application Control - Download application database
- Run and return results of cloud-based application analysis
This setting on a Management Server applies to all managed Security Gateways (R77 and higher).
To change this setting after completing the First Time Configuration Wizard, refer to:
- For R81.20 and higher: sk175504 - How to configure Check Point software to upload data to Check Point / download data from Check Point in versions R81.20 and higher
- For R81.10 and lower: sk111080 - How to configure Check Point software to upload data to Check Point / download data from Check Point in versions R81.10 and lower
Related solutions
- sk175504 - How to configure Check Point software to upload data to Check Point / download data from Check Point in versions R81.20 and higher
- sk111080 - How to configure Check Point software to upload data to Check Point / download data from Check Point in versions R81.10 and lower
- sk106251 - How to configure Security Gateway to accept its own traffic only to Check Point online services
- sk94509 - Recommended Internet Access Settings for Uploading Data
Article Properties
Access Level: General
Status: Approved
Date Created: 2013-08-22
Last Modified: 2026-02-16