- Products
- Learn
- Local User Groups
- Partners
- More
The State of Ransomware Q1 2026
Key Trends and Their Impact
Good, Better, Best:
Prioritizing Defenses Against Credential Abuse
AI Security Masters E7:
How CPR Broke ChatGPT's Isolation and What It Means for You
Blueprint Architecture for Securing
The AI Factory & AI Data Center
Call For Papers
Your Expertise. Our Stage
CheckMates Go:
CheckMates Fest
I have an 1800 Appliance QUANTUM SPARK.
When installing the Threat Policy I see this warning:
Threat Prevention requires the topology to be defined.
At least one internal, one external, and no undefined interfaces are required.
Incorrectly defined topology impacts performance and security.
Please install both Access Control and Threat Prevention policies after fixing the topology. Prevention policies after fixing the topology.
I checked my topology and I have all interfaces except one configured as Internal and one as External.
There are no undefined interfaces
1. Does this warning mean that the Threat blades will not function at all while the warning persists? If not, what exactly does it mean?
2. What is the solution for this?
I would open a TAC case to understand why you are getting this error, given this configuration.
An undefined (or not properly defined) topology may cause additional traffic to be inspected (for example, when “protected scope” is used in your policy).
I don't use external / DMZ restriction in Threat policy and profiles.
Does this warning has any effect in my case?
As far as I know, it won't.
However, I'd still double check with TAC here.
I actually checked my notes from few years ago and I remember this EXACT message with one customer and TAC informed us that while it does not cause those blades to malfunction (if you will), it may have impact on the performance. I would definitely contact TAC to correct it.
Andy
I looked at your screenshot again and I find it odd warning would mention undefined interfaces, as I dont see any of those there.
Andy
I only see sk’s related to vsx gateways and older version. No other info I can find regarding this so I would also advise to open TAC case. If you are not running latest version it is worth updating the fw. This is also solid base for TAC case. Also still could be mgmt issue so do not forget to check this system and update
Compare the list of defined interfaces in the gateway topology to the list of interfaces you can see from the Gaia web interface. Are you sure there is not an extra interface defined in Gaia that does not appear in the topology definition? Such as an interface that is configured but not plugged in or used?
Thanks for the idea. I checked in Gaia and there is no additional interface, however, when I click on get all interfaces, interface LAN2 is added although it is not configured in Gaia.
I tried to assign IP and remove it - but the SC still adding this LAN2 interface.
Run on cli:
clish
show configuration
and compare the interfaces with LAN2 if you see any difference
add gre tunnel id "0" ttl "0"
set interface "LAN2" auto-negotiation "on" mtu "1500" link-speed "10/half" 802dot1x-authentication "off" 802dot1x-
re-authentication-frequency "0" lan-mac-filtering "on"
set dhcp server interface "LAN2" dns "auto"
set interface-alias "LAN2" mask-length "0" state "off"
set interface "LAN2" lan-access "accept" lan-access-track "none"
set interface "LAN2" enable-port-mirroring "off" port "none"
set interface "LAN2" exclude-from-dns-proxy "off"
set dhcp server interface "LAN2" assign-addresses-for-known-hosts-only "off"
set dhcp server interface "LAN2" lease-time "4"
set interface "LAN2" hotspot "off"
add gre tunnel id "0" ttl "0"
FW3> show interfaces
name : LAN2
ipv4-address:
status: off
Sounds like an issue with LAN2 default Sync IF: https://support.checkpoint.com/results/sk/sk52500
Interesting. I'll look into it and update
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 34 | |
| 10 | |
| 9 | |
| 9 | |
| 9 | |
| 8 | |
| 8 | |
| 6 | |
| 5 | |
| 5 |
Tue 12 May 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: Check Point Cloud Firewall delivered as a serviceWed 13 May 2026 @ 11:00 AM (EDT)
TechTalk: The State of Ransomware Q1 2026: Key Trends and Their ImpactThu 14 May 2026 @ 07:00 PM (EEST)
Under the Hood: Presentando Check Point Cloud Firewall como ServicioTue 12 May 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: Check Point Cloud Firewall delivered as a serviceTue 19 May 2026 @ 06:00 PM (IDT)
AI Security Masters E8 - Claude Mythos: New Era in Cyber SecurityAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY