This is due to the fact that the connection will be allowed to proceed by default before an initial categorization has been received for a newly-visited site, whose categorization is not already in the firewall's cache. In SmartConsole under Manage and Settings...Blades...Application Control & URL Filtering...Check Point Online Web Service...Website Categorization Mode try changing the selected option from Background to Hold and see if that helps. Note that on this screen you can also control whether the firewall will fail-open or fail-closed if the URL Categorization service encounters a problem.
--
Second Edition of my "Max Power" Firewall Book
Now Available at http://www.maxpowerfirewalls.com
Attend my 60-minute "Be your Own TAC: Part Deux" Presentation
Exclusively at CPX 2025 Las Vegas Tuesday Feb 25th @ 1:00pm