- Products
- Learn
- Local User Groups
- Partners
- More
Step Into the Future of
AI-Powered Cyber Security
The State of Ransomware Q1 2026
Key Trends and Their Impact
AI Security Masters E8:
Claude Mythos: New Era in Cyber Security
Blueprint Architecture for Securing
The AI Factory & AI Data Center
Call For Papers
Your Expertise. Our Stage
CheckMates Go:
CheckMates Fest
Hello,
We would like to create FW rules to only authorize HTTP and HTTPS traffic (without decrypt HTTPS traffic) regardless of the port used (standard or not). Is-it something feasible without Application control license?
Thank you very much for your feedback,
Regards
Unlike traditional solutions then Check Point Application Control/URL Filtering do not rely on having the database locally.
They instead have very limited cache at the Appliance level but then rely on connecting from the Gateway to the Cloud to do the categorization.
So in order for AppCtrl/URL to work then it needs to be able to connect to the Check Point Cloud to do the categorization.
IPS can have an offfline update but not the AppCtrl/URL
Thank you for your help, I get from Checkpoint a trial license for testing purposes.
But after that I had an issue. I activated application control & url filtering blade and create a rule to match web browsing traffic (With Any as services). The rule is not matched except if I remove Web browsing application and use instead Any.
Do you how can I troubleshoot this? I didn't find any documentation about application control troubleshooting part.
ATRG for Application Control
Thank you very much,
Thanks to your sk links I think I found the issue explanation. Appi_status.C file show an empty value on variable
app_db_version () and I have this app_update_description :
"Update failed. Gateway can not access internet ('https://secureupdates.checkpoint.com/appi/v4_0_1/gw/Version'). Check connectivity and proxy settings
I didn't understand internet access was also needed on Security Gateway, A proxy was only configured on the management server.
Is there any other way to get application dabatase update without configuring internet access on the gateway ? For example retrieving update from management instead ?
Unlike traditional solutions then Check Point Application Control/URL Filtering do not rely on having the database locally.
They instead have very limited cache at the Appliance level but then rely on connecting from the Gateway to the Cloud to do the categorization.
So in order for AppCtrl/URL to work then it needs to be able to connect to the Check Point Cloud to do the categorization.
IPS can have an offfline update but not the AppCtrl/URL
Ok it's clear, thank you for your help
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 27 | |
| 12 | |
| 11 | |
| 7 | |
| 7 | |
| 6 | |
| 6 | |
| 6 | |
| 6 | |
| 5 |
Tue 12 May 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: Check Point Cloud Firewall delivered as a serviceWed 13 May 2026 @ 11:00 AM (EDT)
TechTalk: The State of Ransomware Q1 2026: Key Trends and Their ImpactThu 14 May 2026 @ 07:00 PM (EEST)
Under the Hood: Presentando Check Point Cloud Firewall como ServicioTue 12 May 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: Check Point Cloud Firewall delivered as a serviceTue 19 May 2026 @ 06:00 PM (IDT)
AI Security Masters E8 - Claude Mythos: New Era in Cyber SecurityAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY