- CheckMates
- :
- Products
- :
- Quantum
- :
- SMB Gateways (Spark)
- :
- NGFW Licensing in Locally Managed SMB - URL Filter...
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
NGFW Licensing in Locally Managed SMB - URL Filtering? No?
Alright, we have NGFW Licensing now on the new 1500 series...
What I know from maintrain (and this chart) is that NGFW contains like - [FW, IPS, APPI, IPSec VPN, Content Awareness]
But in Locally Managed SMB... the blade settings is that we either have APPI&URLF both enabled, or only URLF enabled. So.. I'm not sure of the exact behavior we will have here.
Centrally managed is easy to understand because we can select blades individually 😛
So...if we want to use APPI, we need both APPI&URL enabled, but simply URLF wont work?
I've been looking up documents, and engaging with CP reps but.. don't have a precise answer yet.
Though the 1500 datasheet shows the same as maintrain.. URLF not included.
Is any one familiar about it?
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
When you do not have a URLF license (i.e. because you have an NGFW license), then you cannot use functions that rely on URLF.
Specifically, that means you cannot use URL Filtering categories in your rulebase.
You can still use App Control categories or custom URLs in application definitions, as that will be covered by App Control (covered by NGFW).
Note this is exactly how it works on non-SMB appliances as well.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
the license allows you to have both and then you can fine tune it and choose just URLF. can you please explain what exactly you need?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Shlomi,
From datasheets describing NGFW, we see it doesn't include URLF. (and I know I maybe asking something obvious...)
In locally managed mode, I assume having APPI On means URLF is also enabled... where we can't just have ONLY APPI enabled.
So does this mean that when we have NGFW license and want to use APPI, we will have both APPI/URLF enabled though URLF will not be licensed? I'm concerned as in Licensing, and system resource perspectives...
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
When you do not have a URLF license (i.e. because you have an NGFW license), then you cannot use functions that rely on URLF.
Specifically, that means you cannot use URL Filtering categories in your rulebase.
You can still use App Control categories or custom URLs in application definitions, as that will be covered by App Control (covered by NGFW).
Note this is exactly how it works on non-SMB appliances as well.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi PhoneBoy,
Thanks, your explanation made most of my concerns clear 🙂
Btw, from your comments I was wondering how can I distinguish between URLF categories and APPI categories tags?
(For e.g in SmartConsole, application categories shows all category tags...)
Or maybe you mean by only applications that these categories are tagged to are controllable by the policy?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Clearly you won't be able to use categories that are entirely URL Filtering, but you should be able to use the "apps" in a given category.
This list might help: https://www.checkpoint.com/urlcat/appcontrol.htm
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
"Clearly you won't be able to use categories that are entirely URL Filtering, but you should be able to use the "apps" in a given category."
Just the right answer I needed 🙂
I'm all clear now. Thanks again for your help!
