Assuming your Security Management has Internet access, IPS can function entirely offline.
This is because IPS utilizes signatures that can be loaded to the gateways.
Application Control also has signatures, but some elements of Application Control require Internet connectivity to function.
However, if your Security Management and Gateways have no Internet access, there is a special procedure and process to obtain and install the various signatures for IPS, App Control, and other blades.
Your Check Point account team can assist you in getting the necessary authorization and sharing with you the relevant procedure.
Depending on the blades, there are some limitations of running entirely offline, some of which can be mitigated through the use of a Private ThreatCloud appliance (a separate purchase).
More information on this solution here: Check Point Private ThreatCloud