sk94508 - Recommended Internet Access Settings for Automatic Downloads

Recommended Internet Access Settings for Automatic Downloads

Product: Multi-Domain Security Management, Security Gateways, Security Management
Version: R80.10 (EOS), R80.20 (EOS), R80.30 (EOS), R80.40 (EOS), R81 (EOS), R81.10 (EOS), R81.20, R82, R82.10
OS: Gaia
Last Modified: 2026-02-16

Solution

Table of Contents:

  1. Introduction
  2. Offline Mode Limitations
    • Blade Contracts
    • SmartConsole
    • General
  3. Offline Mode Scope

Introduction

In the First Time Configuration Wizard on Gaia OS, you have the option to enable or disable automatic downloads of Blade Contracts, Check Point Releases / Hotfixes via CPUSE, and data for complete functionality of Software Blades and features.
It is highly recommended that you keep this option enabled to ensure the smooth operation of Check Point products.

Notes:

If you choose to disable this automatic download feature, the product will not be able to download the packages automatically. In such a case, you will need to manually download and install the desired packages per the information detailed in the relevant articles in the Check Point Support Center.

Offline Mode Limitations

Blade Contracts

Blade Contracts are annual blade licenses. Their renewal, from the UserCenter, is necessary for complete product functionality. If you disable this setting, Blade Contracts cannot be automatically updated. If your local contract is missing or expired, these limitations apply:

Blade / Feature Limitation
Threat Emulation local mode Files will not be emulated.
Data Loss Prevention blade Will operate in Bypass mode if there is no valid contract installed on Security Gateway
(the contract can be installed manually via SmartUpdate, and DLP will enforce its policy on the traffic).
Compliance blade Will not execute scans.
Endpoint Security Policy Management License report in SmartEndpoint will not be accurate.
CPinfo Self-update is not applicable.

SmartConsole

Blade / Feature Limitation
IPS - IPS updates from UserCenter will fail.
Application & URL Filtering - AppWiki will not work.
- No update of "Messages and Actions" frame in Overview view.
- No update of the applications picker in the Policy view.
- Search for categorization of sites via overview tab will fail.
Threat Prevention - ThreatWiki will not work.
- No protections picker in Global Exceptions view.
- No Protections view.
- No search for malware from Overview.
- No RSS feed.
Threat Emulation - No image and file type updates.

General

Offline Mode Scope

Even in Offline mode, if an activated Software Blade requires external services, it will still connect to Check Point Cloud to get the required data:

Blade / Feature Limitation
IPS - Download Geo protection updates
- Download malicious IPs lists
- Validate Blade contract entitlement
Application Control - Download applications database
- Detect social network widgets
- Run and return results of cloud-based application analysis
- Validate Blade contract entitlement
URL Filtering - Download initial local database
- Run and return results of cloud-based categorization
- Validate Blade contract entitlement
HTTPS Inspection - Update bypass list
Anti-Spam,
Anti-Bot,
Anti-Virus
- Download updates to the local signature database
- Run and return results of cloud-based security analysis
- Validate Blade contract entitlement
Compliance - Download latest regulations and best practices
Endpoint Policy Management - Download updates to the malware database
Endpoint Anti-Malware - Run and return results of cloud-based malware categorization
Endpoint Application Control - Download application database
- Run and return results of cloud-based application analysis

This setting on a Management Server applies to all managed Security Gateways (R77 and higher).

To change this setting after completing the First Time Configuration Wizard, refer to:

Related solutions

Article Properties

Access Level: General
Status: Approved
Date Created: 2013-08-22
Last Modified: 2026-02-16