> Source: [sk182106](https://support.checkpoint.com/results/sk/sk182106)

# sk182106 - Threat Prevention Software Blades in Security Gateways R82 and higher

| Property | Value |
|----------|-------|
| Solution ID | sk182106 |
| Date Created | 2024-03-17 |
| Last Modified | 2026-03-16 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R82.10, R82 |
| OS | Gaia |

## Solution

### Overview

Starting from R82, when you create a new Security Gateway / Cluster object in Desktop SmartConsole, these Threat Prevention Software Blades are enabled by default:

|------------------------------|---------------------------------------|---------------------------------------------------------------|
| Version of Management Server | Version of Security Gateway / Cluster | Threat Prevention Software Blades that are enabled by default |
| R82 and higher               | R82 and higher                        | * Anti-Bot \& Advanced DNS * Anti-Virus                       |
| R82.10 and higher            | R82.10 and higher                     | * Threat Emulation * Zero Phishing                            |

### Requirements

1. Security Management Server or Multi-Domain Security Management Server R82 and higher.
2. Security Gateway / Cluster Members R82 and higher.
3. In Desktop SmartConsole, go to the **Gateways \& Servers** view, click **New** \> select **Gateway** or **Cluster** \> select **Classic Mode**.

### Supported Objects

* Security Gateway (all hardware platforms, including ElasticXL and Maestro).
* Cluster (all hardware platforms).
* VSNext Virtual Gateway (on ElasticXL or Maestro).

**Note** - Upgraded objects are not affected. For example, if you upgrade a Security Gateway version R81.20, with these Software Blades disabled, then after upgrade to R82, the Software Blades which were disabled prior to the upgrade will remain disabled.

### Known Limitations

* Threat Prevention Software Blades are **not** enabled automatically when you create a new Security Gateway / Cluster object in these ways:

  * In Desktop SmartConsole when you select the **Wizard Mode**.
  * In Web SmartConsole.
  * Using a Management API command ("`add simple-gateway`" / "`add simple-cluster`").
* Threat Prevention Software Blades are **not** enabled automatically on these devices:

  * Standalone (Security Gateway and Security Management Server on the same server).
  * Traditional VSX Gateway and Traditional VSX Virtual System.
  * Quantum Spark Gateway.
  * Full High Availability Cluster (ClusterXL and Security Management Server on the same server).

### How to disable the feature

You can prevent automatic enabling of these Threat Prevention Software Blades on the Management Server.

|-----------------------------------------------------------------------|------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|------------------------------------------------------------------------------------------------------|
| Action                                                                | Instructions                                                                                                                                                                                   | API Reference                                                                                        |
| Prevent automatic enabling of the **Anti-Bot** Software Blade         | Run this Management API command on the Security Management Server / applicable Domain Management Server: `mgmt_cli set threat-advanced-settings auto-enable-anti-bot disabled -r true`         | [Link](https://sc1.checkpoint.com/documents/latest/APIs/index.html#cli/set-threat-advanced-settings) |
| Prevent automatic enabling of the **Anti-Virus** Software Blade       | Run this Management API command on the Security Management Server / applicable Domain Management Server: `mgmt_cli set threat-advanced-settings auto-enable-anti-virus disabled -r true`       | [Link](https://sc1.checkpoint.com/documents/latest/APIs/index.html#cli/set-threat-advanced-settings) |
| Prevent automatic enabling of the **Threat Emulation** Software Blade | Run this Management API command on the Security Management Server / applicable Domain Management Server: `mgmt_cli set threat-advanced-settings auto-enable-threat-emulation disabled -r true` | [Link](https://sc1.checkpoint.com/documents/latest/APIs/index.html#cli/set-threat-advanced-settings) |
| Prevent automatic enabling of the **Zero Phishing** Software Blade    | Run this Management API command on the Security Management Server / applicable Domain Management Server: `mgmt_cli set threat-advanced-settings auto-enable-zero-phishing disabled -r true`    | <Link>                                                                                               |

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
