- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi Mates,
We have a Check Point 7K Security Gateway with a Smart Management Server (SMS) running R81.10. IPS, App Control, and URL Filtering blades are activated. We'd like to understand how license expiration for these blades will affect the Security Gateway's operation.
Specifically, will the Security Gateway continue normal operation after the blade licenses expire?
For example, if a rule currently blocks access to facebook.com, will this rule stop working after the App Control or URL Filtering blade license expires, allowing access to Facebook?
Thanks,
When we are talking about AC/URLF, it is not a license but a subscription contract.
You are supposed to have a valid contract in place, but in case it expires and is not renewed in time, you will see policy installation warnings, see positions 8 to 13 from this SK.
After a short grace period, the blade will be disabled, and you will not be able to use it unless the contract is renewed, and the new contract file is applied to the GW.
Specifically, sk56300 says the following:
You must have an Application Control Software Blade contract to use the Application Control Software Blade functionality on a gateway. If a valid Application Control contract is not associated with a gateway, the blade will be disabled.
When this change in functionality occurs, customers will be notified by:
Once you purchase a valid contract, the blade is enabled again.
Important: When an Application Control Blade is disabled due to insufficient contract, all Application Control settings in SmartDashboard do not change. The blade will appear to be active in SmartDashboard; however it will not be active on the gateway.
In lamen terms, AC/URLF rules will not be matched. Would it be AV or IPS, your GW could use the last downloaded data without the possibility of getting the latest updates, but in the case of AC/URLF, gateways are using Threat Cloud in real-time to get the latest categorization for specific URLs and applications, with only limited cache possibilities.
Here is my understanding, but someone can correct me if Im wrong...so if license expires, rule wont stop working, BUT, updates will, meaning you wont get any new ips/urlf database updated, plus you wont be able to install any new policy to the firewalls either.
Andy
References:
https://community.checkpoint.com/t5/General-Topics/What-happens-when-a-license-expires/td-p/56011
See sk44175: You have a 90 days grace period after blade license expires during which all will work as if licensed !
When we are talking about AC/URLF, it is not a license but a subscription contract.
You are supposed to have a valid contract in place, but in case it expires and is not renewed in time, you will see policy installation warnings, see positions 8 to 13 from this SK.
After a short grace period, the blade will be disabled, and you will not be able to use it unless the contract is renewed, and the new contract file is applied to the GW.
Specifically, sk56300 says the following:
You must have an Application Control Software Blade contract to use the Application Control Software Blade functionality on a gateway. If a valid Application Control contract is not associated with a gateway, the blade will be disabled.
When this change in functionality occurs, customers will be notified by:
Once you purchase a valid contract, the blade is enabled again.
Important: When an Application Control Blade is disabled due to insufficient contract, all Application Control settings in SmartDashboard do not change. The blade will appear to be active in SmartDashboard; however it will not be active on the gateway.
In lamen terms, AC/URLF rules will not be matched. Would it be AV or IPS, your GW could use the last downloaded data without the possibility of getting the latest updates, but in the case of AC/URLF, gateways are using Threat Cloud in real-time to get the latest categorization for specific URLs and applications, with only limited cache possibilities.
Most important cleanup rule will be matched after grace period ends... if cleanup is Drop, you will face a little problem..
100%...
Just as temporary solution, apply an eval license, thats what most people do anyway.
Best,
Andy
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 11 | |
| 9 | |
| 9 | |
| 8 | |
| 6 | |
| 3 | |
| 2 | |
| 2 | |
| 2 | |
| 1 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY