> Source: [sk121312](https://support.checkpoint.com/results/sk/sk121312)

# sk121312 - Contracts show as expired for URL Filtering , Application Control  and/or IPS  blades on a particular VS instance

| Property | Value |
|----------|-------|
| Solution ID | sk121312 |
| Date Created | 2017-11-06 |
| Last Modified | 2020-10-14 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |
| OS | Gaia |

## Symptoms

- * SmartView Monitor shows the following for URL Filtering and/or Application Control: **`Subscription Status: Expired, `
  `
  Subscription Expiration: null`**

* The *cpstat urlf -f subscription_status* command run within the problematic VS instance shows ***contract expired***.
* The *cpstat urlf -f update_status* command run within the problematic VS instance shows:

  **` Update status: failed `
  `
  Update description: Update failed. Gateway can not access internet... Check connectivity and proxy settings.`
  `
  Next update description: The next try will be within one hour.`**
* *cplic print* and SmartUpdate confirm that contracts are valid on the Security Management station and on Security Gateway(s).
* The instructions in [sk83520](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk83520) were already followed; connectivity from both the VS0 and the problematic VS instance to Check Point servers is working correctly.

## Cause

The URL Filtering and/or Application Control blades are not enabled on VS0.

[![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk121312/for_sk1711051953.jpg)](https://sc1.checkpoint.com/sc/SolutionsStatics/sk121312/for_sk1711051953.jpg)

Even though the [Application Control and URL Filtering R77 Versions Administration Guide](https://sc1.checkpoint.com/documents/R77/CP_R77_ApplicationControlURLFiltering_WebAdminGuide/html_frameset.htm) states, in the chapter entitled "Using Application and URL Filtering with VSX," that these blades do not have to be enabled on the VSX Gateway (VS0), this statement does not apply to contract validation purposes.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
