> Source: [sk106496](https://support.checkpoint.com/results/sk/sk106496)

# sk106496 - Software Blades updates on VSX - FAQ

| Property | Value |
|----------|-------|
| Solution ID | sk106496 |
| Date Created | 2015-07-06 |
| Last Modified | 2026-05-24 |
| Technical Level | General |
| Products | Security Gateway, Scalable Platforms |
| Versions | R82.10, R82, R81.20, R81.10 (EOS), R81 (EOS), R82, R81.20, R81.10 (EOS), R81 (EOS) |
| OS | Gaia |

## Solution

This article presents the Frequently Asked Questions concerning the Software Blades supported on VSX.  
Click Here to Show Entire FAQ

IPS
---

Click Here to Show This Section

* Should I enable IPS Software Blade on the VSX Gateway?  
  > You must enable and configure the IPS Software Blade in these objects:
  > 1. VSX Gateway or VSX Cluster (because VS0 handles contract validation for all Virtual Systems).
  >
  > 2. Applicable Virtual Systems.
  >
  > For more information, refer to the:
  > * [VSX Administration Guide](https://support.checkpoint.com/product/359)
  > * [Threat Prevention Administration Guide](https://support.checkpoint.com/product/417)

  <br />

* How do I update the IPS Software Blade?  
  > The updates for IPS Software Blade are downloaded to the Security Management Server / Domain Management Server and then are transferred to the VSX Gateway / VSX Cluster Members during policy installation - the Management Server downloads the IPS update and pushes it to the VSX Gateway / VSX Cluster Members (context of VS0).
  >
  > In SmartConsole, go to the **Security Policies** view \> **Threat Prevention** \> **Policy** \> **Updates** (similar to the description in [sk120255](https://support.checkpoint.com/results/sk/sk120255)). **Make sure to configure the required proxy setting on the Security Management Server.**
  >
  > You can always perform the IPS Software Blade update on the Security Management Server / Domain Management Server either manually, or based on a schedule (configured in SmartConsole).

  <br />

* Are there special instructions for IPS Geo Protection?  
  > * In the versions *R80.20 and above* , use Updatable Objects to configure Geo Policy - see [sk126172](https://support.checkpoint.com/results/sk/sk126172).
  >
  > * In the *R80.10* version, you must enable and configure the IPS Software Blade in these objects:
  >
  >   1. VSX Gateway or VSX Cluster (because VS0 handles contract validation for all Virtual Systems).
  >
  >   2. Applicable Virtual Systems.
  >
  >   The Geo policy is installed as a part of the Access Policy.
  >
  >   The activation mode of Geo policy assigned to a VSX gateway (context of VS0) has to be either in the "Monitor Only" or "Active" mode. This is required for the IPS Geo Protection updates to work on Virtual Systems (VS).
  > * In the versions *R77.30 and lower*, for the IPS Geo Protection updates to work correctly, you must configure the VSX Gateway / VSX Cluster object itself (context of VS0):
  >
  >   1. Enable and configure the IPS Software Blade.
  >   2. Assign an IPS profile, in which the "Action" of Geo Protection is set to either "Detect", or "Prevent".
  >   3. Click OK.
  >   4. Install the Threat Prevention policy.

Application Control and URL Filtering
-------------------------------------

Click Here to Show This Section

* When I enable the Application Control / URL Filtering Software Blade in the Virtual System object, should I also enable this blade in the VSX Gateway object?  
  > Do **not** enable these Software Blades in the VSX Gateway / VSX Cluster object (context of VS0) when you enable these Software Blades in Virtual System objects.

  <br />

* Should I configure proxy settings in VSX Gateway object when I enable the Application Control / URL Filtering Software Blade in Virtual System object?  
  > If your VSX Gateway is connected to the Internet through a Proxy Server, then you must configure the proxy settings in the VSX Gateway / VSX Cluster object.  
  > The VSX Gateway / VSX Cluster Member fetches the update package from the cloud, and then all Virtual System get the update package from the shared directory in the context of VS0: `$FWDIR/appi/update/shared/`

Anti-Bot and Anti-Virus
-----------------------

Click Here to Show This Section

* When I enable the Anti-Bot / Anti-Virus Software Blade in the Virtual System object, should I also enable this blade in the VSX Gateway object?  
  > Yes.
  >
  > Because contracts validation and initialization of default updates parameters are performed from the VSX Gateway itself (context of VS0).

  <br />

* Should I configure proxy settings in VSX Gateway object when I enable the Anti-Bot / Anti-Virus Software Blade in Virtual System object?  
  > If your VSX Gateway is connected to the Internet through a Proxy Server, then you should configure the proxy settings in the VSX Gateway / VSX Cluster object.
  >
  > Each configured Virtual System uses its proxy settings.

  <br />

* Should I install Threat Prevention policy on all Virtual Systems and on the VSX Gateway?  
  > You must install the Threat Prevention policy on these objects:
  > 1. VSX Gateway / VSX Cluster object.
  > 2. Virtual Systems, on which the Anti-Bot / Anti-Virus Software Blade is enabled.

  <br />

* How do I update the Anti-Bot / Anti-Virus Software Blade?  
  > The VSX Gateway / VSX Cluster Member tries to get the Anti-Bot / Anti-Virus updated signatures using its proxy settings.
  > * If it succeeds, then it the updated signatures will be transferred to the Virtual Systems.
  > * If it fails, then each Virtual System will download the updated signatures package from the Internet using its own proxy settings.

  <br />

* Do I need to configure DNS server on VSX Gateway for Anti-Bot / Anti-Virus Software Blade updates?  
  > Yes.
  >
  > Follow these guidelines:
  > * Configure the DNS server(s) in the Operating System settings on VSX Gateway / each VSX Cluster in the context of VS0 (VSX machine itself).  
  >   Note: All Virtual Systems will use the same DNS configuration (it can not be configured per Virtual System).
  > * You must create an explicit security rule for each Virtual System that allows access from Virtual System to the configured DNS Server(s).
  > * If your VSX Gateway is connected to the Internet via Proxy, then you should configure the relevant proxy settings in the VSX Gateway object. Each configured Virtual System will use its own proxy settings.

Threat Emulation
----------------

Click Here to Show This Section

* When I enable the Threat Emulation Software Blade in the Virtual System object, should I also enable this blade in the VSX Gateway object?  
  > No.
  >
  > The VSX Gateway is *not* involved in the Threat Emulation process.

  <br />

* Should I configure proxy settings in VSX Gateway object when I enable the Threat Emulation Software Blade in Virtual System object?   
  > If your VSX Gateway is connected to the Internet via Proxy, then you should configure the relevant proxy settings in the VSX Gateway object.

  <br />

* What are the limitations of Threat Emulation on VSX?  
  > * Virtual System Load Sharing (VSLS) clusters with more than two cluster members is supported in the version R80.10 and higher.
  > * Mail Transfer Agent (MTA) is supported in the version R80.10 and higher.

Threat Extraction
-----------------

Click Here to Show This Section

* When I enable the Threat Extraction Software Blade in the Virtual System object, should I also enable this blade in the VSX Gateway object?  
  > Yes.

  <br />

* How do you use Threat Extraction over the VSX environment?  
  > You must activate the Threat Extraction engine in the VSX Gateway / VSX Cluster object (context of VS0).
  >
  > Every time you reboot a VSX Gateway / VSX Cluster Member (or restart Check Point services with the "`cpstop;cpstart`" commands), each Virtual System pulls its licensing and policy information from the context of VS0.

  <br />

Advanced Networking \& Clustering
---------------------------------

Click Here to Show This Section

* What improvements were added to VSX in R80.20?  
  > * Significant boost to Virtual Systems performance, utilizing up to 32 CoreXL Firewall instances for each Virtual System.
  > * SecureXL Penalty Box supports the contexts of each Virtual System. Refer to [sk74520](https://support.checkpoint.com/results/sk/sk74520).

<br />

General
-------

Click Here to Show This Section

* Are Updatable Objects supported on VSX?  
  > Updatable objects are supported on VSX.
  >
  > Each Virtual System configured with Updatable Objects must have connectivity to "`updates.checkpoint.com`" and "`dl3.checkpoint.com`" to download the package of Updatable Objects.

  <br />

Related Solutions
-----------------

* [sk79700 - VSX supported features](https://support.checkpoint.com/results/sk/sk79700)
* [sk94508 - Recommended Internet Access Settings for Automatic Downloads](https://support.checkpoint.com/results/sk/sk94508)

Product Pages
-------------

**(links to documents, downloads, and applicable SK articles)**

* [VSX](https://support.checkpoint.com/product/359)
* [IPS](https://support.checkpoint.com/product/437)
* [Application Control](https://support.checkpoint.com/product/432)
* [URL Filtering](https://support.checkpoint.com/product/440)
* [Anti-Bot](https://support.checkpoint.com/product/429)
* [Anti-Virus](https://support.checkpoint.com/product/431)
* [Threat Emulation](https://support.checkpoint.com/product/426)
* [Threat Extraction](https://support.checkpoint.com/product/457)

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
