- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Announcing Quantum R82.10!
Learn MoreOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hello,
We would like to create FW rules to only authorize HTTP and HTTPS traffic (without decrypt HTTPS traffic) regardless of the port used (standard or not). Is-it something feasible without Application control license?
Thank you very much for your feedback,
Regards
Unlike traditional solutions then Check Point Application Control/URL Filtering do not rely on having the database locally.
They instead have very limited cache at the Appliance level but then rely on connecting from the Gateway to the Cloud to do the categorization.
So in order for AppCtrl/URL to work then it needs to be able to connect to the Check Point Cloud to do the categorization.
IPS can have an offfline update but not the AppCtrl/URL
Thank you for your help, I get from Checkpoint a trial license for testing purposes.
But after that I had an issue. I activated application control & url filtering blade and create a rule to match web browsing traffic (With Any as services). The rule is not matched except if I remove Web browsing application and use instead Any.
Do you how can I troubleshoot this? I didn't find any documentation about application control troubleshooting part.
ATRG for Application Control
Thank you very much,
Thanks to your sk links I think I found the issue explanation. Appi_status.C file show an empty value on variable
app_db_version () and I have this app_update_description :
"Update failed. Gateway can not access internet ('https://secureupdates.checkpoint.com/appi/v4_0_1/gw/Version'). Check connectivity and proxy settings
I didn't understand internet access was also needed on Security Gateway, A proxy was only configured on the management server.
Is there any other way to get application dabatase update without configuring internet access on the gateway ? For example retrieving update from management instead ?
Unlike traditional solutions then Check Point Application Control/URL Filtering do not rely on having the database locally.
They instead have very limited cache at the Appliance level but then rely on connecting from the Gateway to the Cloud to do the categorization.
So in order for AppCtrl/URL to work then it needs to be able to connect to the Check Point Cloud to do the categorization.
IPS can have an offfline update but not the AppCtrl/URL
Ok it's clear, thank you for your help
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 21 | |
| 20 | |
| 16 | |
| 5 | |
| 4 | |
| 4 | |
| 3 | |
| 3 | |
| 3 | |
| 3 |
Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY