- Products
- Learn
- Local User Groups
- Partners
- More
Quantum Spark Management Unleashed!
Introducing Check Point Quantum Spark 2500:
Smarter Security, Faster Connectivity, and Simpler MSP Management!
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
SharePoint CVEs and More!
Greetings,
Does anyone know how to successfully apply and run Autonomous Threat Prevention on Security Gateways with only an NGTP license?
According to sk163593, you don't need a full NGTX/SBNT license to use Autonomous Threat Prevention:
https://support.checkpoint.com/results/sk/sk163593
And that is indeed the case. Autonomous Threat Prevention works just fine with NGTP, but Smart Console constantly complains about the Security Gateway not having a valid Threat Emulation or Threat Extraction license.
This makes sense as we are running the "Perimeter (recommended)" profile in the Autonomous Threat Prevention Policy, which tries to enable and utilise both Threat Emulation and Threat Extraction.
But there seems to be no way for us to disable these blades. You can't choose what blades to run on the Security Gateway object. You choose Autonomous Threat Prevention or Custom Threat Prevention, which lets you manually select blades.
No apparent settings within the Autonomous Threat Prevention Policy let you disable specific blades. The closest thing I've found is to go to Autonomous Policy -> Settings -> Advanced Settings and add Sandbox and Sanitization with "Off" as an override. But this doesn't change anything regarding Smart Console complaining about no valid Threat Emulation or Threat Extraction license on the Security Gateway.
I even tried to create a global exception disabling both blades in the policy. But it's still complaining. I tried to re-create this in my LAB, and it's the same behaviour. I can't locate any meaningful information in the ATRG SK for Autonomous Threat Prevention or anything in the R81.10 or R81.20 Threat Prevention Administration Guides.
How is one expected to deploy and run Autonomous Threat Prevention with only NGTP and no NGTX/SBNT license on the Security Gateway? Do you have to ignore the red warning on the object in Smart Console??
In sk167109: Autonomous Threat Prevention Management integration Release Updates > List of Resolved Issues and New Features per Update we find:
Update 13 (15 July 2021) | |
ODU-154 | The License absence warning may be shown to NGTP licensed users. |
Can you verify that you use no older version ?
Thanks for the rapid response. The management and Security Group have direct access to updates.checkpoint.com, so this should update automatically. I did verify it, and it does seem to be the case:
MGMT:
BUNDLE_GOT_TPCONF_MGMT_AUTOUPDATE Take: 36
BUNDLE_DC_INFRA_AUTOUPDATE Take: 30
BUNDLE_GOT_MGMT_AUTOUPDATE Take: 108
GW:
BUNDLE_GOT_TPCONF_AUTOUPDATE Take: 111
I suppose this might be related to the appliances shipped with NGTX/SNBT the first year. When running cplic print the contract coverage is mentioning both Threat Extraction, and Threat Emulation with expiration dates Dec 2022.
# ID Expiration SKU
===+===========+============+====================
1 | T5T5094 | 9Dec2022 | CPSB-TEX-7000-PLUS-1Y
+-----------+------------+--------------------
===+===========+============+====================
5 | T410YT9 | 9Dec2022 | CPSB-TE-7000-PLUS-1Y
+-----------+------------+--------------------
Might it be that Autonomous Threat Prevention starts complaining due to this? If there were no contract for either, to begin with, it wouldn't complain. I suppose I have to contact Account Services to have them remove the expired Threat Emulation and Threat Extraction from the license/contracts?
I am a bit confused here. Do you have a valid contract in the UserCenter?
Hi, @_Val_
There are no valid contracts for Threat Emulation or Threat Extraction. The customer has never intended to go beyond NGTP. But these CPAP-SG7000 appliances included NGTX/SBNT the first year.
We have deployed Autonomous Threat Prevention from the get-go. But ever since the contracts for Threat Emulation and Threat Extraction expired in December 2022, Smart Console has been nagging them about expired licenses for Threat Emulation and Threat Extraction.
What I'm trying to achieve is to keep using Autonomous Threat Prevention but to have this red warning regarding no license for Threat Emulation and Threat Extraction go away. They have no intention of renewing these two blades, so having the warning is rather misleading and annoying.
Ok, cristal clear now. ATP includes TX/TE as part of the profiles. Technically, you already use just partial functionality of ATP.
Personally, I do not see there too many options. Try checking with TAC what can be done, but I am pretty sure the answer will be "ATP is not supported to run partial config without TX".
@_Val_
That would be awkward, considering how the sk163593 - Autonomous Threat Prevention Management states:
Q: Do we need a special license?
A: No. You need the standard NGTP/NGTX licenses.
Ref: https://support.checkpoint.com/results/sk/sk163593
I am looking into the Threat Prevention admin guide, and it clearly states that File protection requires sandboxing. Also, all pre-defined profiles are set with TE/TX active. Finally, the GW side settings clearly have Sandboxing there.
You can use "Custom Threat Prevention" and uncheck TX/TE, but it will not be autonomous anymore. Worth checking with TAC, regardless.
Actually, I think there is a way.
You can turn off TE and TX in the advanced properties of ATP. Try this and let me know if it helps:
Sadly I've already tried this without any luck. I also created a global exception disabling the TE and TX blade. But no dice.
Please open a TAC case.
So the issue is not resolved in the current take, it seems - worth asking TAC...
@G_W_Albrecht There is nothing to resolve, the license is not there in the first place. SK you mentioned is about false message about a missing license when it is in place.
Why would sk163593 - Autonomous Threat Prevention Management even mention NGTP if you will be getting warnings nonstop if you don't have NGTX/SBNT?
I think this is specific for this Security Group as a result of expired contracts for TE and TX in place. I'd bet if these contracts didn't show, it would work with NGTP just fine without any warnings. Without TE and TX functionality, of course.
Answered above. You have a point, there is a way to turn sandboxing and other properties off.
May removing the expired contracts would help ? But i only know sk105757...
No, it reads: The License absence warning may be shown to NGTP licensed users.
Hello everyone,
Is there anything new on this?
I also find the messages very annoying and many customers therefore want to go back to the old scheme and not use Autonoumous.
has anyone found a way to get rid of the messages?
Best regards
Hi,
I’ve forwarded this issue to the relevant owner in R&D.
Let’s see what solution they might suggest.
Thanks,
Tal
Hi @Tal_Paz-Fridman ,
thank you.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
2 | |
1 |
Wed 10 Sep 2025 @ 11:00 AM (EDT)
Quantum Spark Management Unleashed: Hands-On TechTalk for MSPs Managing SMB NetworksFri 12 Sep 2025 @ 10:00 AM (CEST)
CheckMates Live Netherlands - Sessie 38: Harmony Email & CollaborationTue 16 Sep 2025 @ 02:00 PM (EDT)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - AmericasWed 17 Sep 2025 @ 04:00 PM (AEST)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - APACWed 17 Sep 2025 @ 03:00 PM (CEST)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - EMEAWed 10 Sep 2025 @ 11:00 AM (EDT)
Quantum Spark Management Unleashed: Hands-On TechTalk for MSPs Managing SMB NetworksFri 12 Sep 2025 @ 10:00 AM (CEST)
CheckMates Live Netherlands - Sessie 38: Harmony Email & CollaborationTue 16 Sep 2025 @ 02:00 PM (EDT)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - AmericasWed 17 Sep 2025 @ 04:00 PM (AEST)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - APACWed 17 Sep 2025 @ 03:00 PM (CEST)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - EMEAAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY