- Products
- Learn
- Local User Groups
- Partners
- More
Step Into the Future of
AI-Powered Cyber Security
The State of Ransomware Q1 2026
Key Trends and Their Impact
AI Security Masters E8:
Claude Mythos: New Era in Cyber Security
Blueprint Architecture for Securing
The AI Factory & AI Data Center
Call For Papers
Your Expertise. Our Stage
CheckMates Go:
CheckMates Fest
For IPS in particular you can just run ips off on the gateway to instantly turn it off. If policy is reinstalled or the firewall rebooted IPS will be back on, current state can be checked with ips stat.
For the other elements of Threat Prevention I suppose you could unload the TP policy on the gateway with fw amw unload but be warned I have not tried doing this on a production firewall.
For Application Control and URL Filtering, I don't think there is a way to disable these on the fly without a policy reinstall to the gateway.
Then of course if you just want to turn your firewall into a pure router with no enforcement, no NAT, no antispoofing etc you could always do this which will cause an outage:
fw unloadlocal
echo 1 > /proc/sys/net/ipv4/ip_forward
--
My book "Max Power: Check Point Firewall Performance Optimization"
now available via http://maxpowerfirewalls.com.
About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY