> Source: [sk44175](https://support.checkpoint.com/results/sk/sk44175)

# sk44175 - IPS Software Blade contracts 

| Property | Value |
|----------|-------|
| Solution ID | sk44175 |
| Date Created | 2010-02-10 |
| Last Modified | 2024-11-24 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R82, R81.20, R81.10 (EOS), R81 (EOS) |

## Solution

**Table of Contents:**

* Overview
* Contract requirements
* Notifications about insufficient contract coverage
* What happens when there is no IPS contract
* Example scenarios
* FAQ

### Overview {#TOC01}

> The IPS Software Blade is a Service Blade that requires annual renewal to enforce IPS protections and download protection updates from the Check Point IPS Update Service. The IPS updates are required to protect against the most recent vulnerabilities and exploits.
>
> The IPS Software Blade verifies renewal information for every Security Gateway and reduces IPS functionality if the IPS contract is expired.
>
> This document explains:
>
> * How to view the status of IPS contracts in all your gateways
> * What the notifications mean that are provided about missing or expiring contracts
> * How the enforcement mechanism detects invalid or missing contracts

### Contract requirements {#TOC02}

> Each Security Gateway needs to be covered by an IPS contract to use IPS Protections. The contract covers both Protections which are provided "out-of-the-box" as well as new Protections downloaded from Check Point IPS Update Service. The IPS contract covers all protections of the IPS Software Blade.
>
> Without a valid IPS contract, the gateway is not entitled to use any IPS protections.
>
> There are 8 types of IPS Software Blade contracts:
>
> |-------------------------------|-------------------------------------------------------------------------------------------------------|
> | Contract                      | Description                                                                                           |
> | CPSB-IPS-XL-\<# of years\>    | This contract covers high end appliances and software packages.                                       |
> | CPSB-IPS-L-\<# of years\>     | This contract covers large-sized appliances and software packages.                                    |
> | CPSB-IPS-M-\<# of years\>     | This contract covers mid-sized appliances and software packages.                                      |
> | CPSB-IPS-S-\<# of years\>     | This contract covers small appliances and software packages.                                          |
> | CPSB-IPS-XL-\<# of years\>-HA | This contract covers select appliances and software packages. "HA" stands for High Availability.      |
> | CPSB-IPS-L-\<# of years\>-HA  | This contract covers large-sized appliances and software packages. "HA" stands for High Availability. |
> | CPSB-IPS-M-\<# of years\>-HA  | This contract covers mid-sized appliances and software packages. "HA" stands for High Availability.   |
> | CPSB-IPS-S-\<# of years\>-HA  | This contract covers small appliances and software packages. "HA" stands for High Availability.       |
>
> **Note** - Refer to the online [Product Catalog](https://catalog.checkpoint.com/) to determine the appropriate contract for your product.
>
> Contracts are always associated with licenses or containers. Each contract, including the IPS Software Blade, must be attached to a Blade Container or to a valid Security Gateway license.
>
> When contracts are purchased, they appear in the relevant User Center account.
>
> Example:
>
> ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk44175/picture1.JPG)
>
> When you click on a container, you will be able to see the contracts associated with it.
>
> Example:
>
> ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk44175/picture2.JPG)

### Notifications about insufficient contract coverage {#TOC03}

> The best way to view the complete license and contract coverage status is:
>
> * In versions R81 and higher:
>
>   In SmartConsole \> on the left navigation panel, click the **Gateways \& Servers** view \> in the top panel, click the Security Gateway / Cluster object \> in the bottom panel, click the **Licenses** tab.
> * In versions R80.40 and lower:
>
>   In SmartUpdate. It shows:
>   * A list of all expired and about-to-expire licenses and contracts.
>
>   * All expired contracts appear in red in the **Licenses and Contracts** view.
>
>     Example:
>
>     ![](https://sc1.checkpoint.com/sc//SolutionsStatics/sk44175/R8020SmartUpdate1902110700.png)
>
> There are additional notifications, so you can understand the contract coverage status easily:
>
> 1. **The 'Alerts' tab**
>
>    In SmartConsole \> on the left navigation panel, click the **Gateways \& Servers** view \> in the top panel, click the Security Gateway / Cluster object \> in the bottom panel, click the **Alerts** tab.
>    This tab shows an alert when a Security Gateway / Cluster has invalid or insufficient IPS contract coverage. A different warning appears when contracts are about to expire.
> 2. **The 'Install Policy' window**
>
>    During policy installation, this window shows alerts with contract statuses.
>
>    Examples:
>    * *On \<DATE\>, IPS protection set will be limited to protections installed before \<DATE\>*
>
>    * *The policy includes changes to services that have an expired contract or a contract that is about to expire.
>      Services with expired contracts have limited functionality.*

### What happens when there is no IPS contract {#TOC04}

> You must have an IPS Software Blade contract to use the full IPS Software Blade functionality on a Security Gateway.
>
> **If a valid license with a valid IPS contract is not installed on a Security Gateway, then the Security Gateway does not enforce IPS protections at all.**
>
> If a license or an IPS contract expire on a Security Gateway, you are notified in these ways in SmartConsole:
>
> * A warning message appears during policy installation.
> * An Audit Log appears after policy installation with the message that IPS protections were disabled.
>
> After you purchase and install a valid license with a valid contract, all previously disabled IPS protections begin working again.
>
> **Note:** When IPS protections are disabled as a result of a contract issue, the IPS protection's settings in SmartConsole do not change. The IPS protection will appear to be active in SmartConsole. However, it will not be active on the Security Gateway.
>
> On the Management Server, you can download IPS updates even when some Security Gateways have contract issues.
>
> You must enter your User Center credentials, so that the contract data can be automatically updated on the Security Management Server.

### Example scenarios {#TOC05}

> 1. **New installation**
>
>    After a clean installation, each Security Gateway and each Management Server includes a trial license. This license allows all Security Gateway functionality for 15-days. This lets all Security Gateways managed by this Security Management server to use all IPS protections.
>
>    After the trial license expires, a grace period starts (see below, Scenario #3), in which the IPS protections still work, but warnings are issued regarding the missing/expired contracts. When the grace period is over, IPS protections added after the installation date are disabled off on all Security Gateways that do not have a valid contract, as described above.
> 2. **Evaluation contracts**
>
>    The IPS Software Blade can be evaluated for a specified period of time with an Evaluation contract. Evaluation contracts are treated the same as "regular" contracts, and they allow prospective customers to use all IPS protections on the Security Gateway, on which they are installed for the duration of the 30-day evaluation contract. When the grace period is over, IPS protections added after the installation date are disabled, as described above.
> 3. **IPS Software Blade Grace Period**
>
>    Grace periods are periods after the IPS Software Blade license expires, in which the IPS protections will still be active and no restrictions are made, but warnings are issued regarding the missing contracts. The grace period is set for 60 days for R77.x versions and 90 days for R8x versions, starting from the latest contract expiration date on that Security Gateway. The grace periods are calculated per Security Gateway individually.

### FAQ {#TOC06}

> 1. **Q. How is the contract information updated?**
>
>    **A.** When purchasing a new IPS blade contract, the contract is added to your User Center account. In most cases, the contract will already be associated to a container (a Security Gateway). If this is not the case - you need to manually associate it.
>
>    On the Security Management Server, a task is running every 6 hours (by default) which updates the license and contract information from the User Center account into the Security Management Server. It is also possible to manually update the information from the SmartConsole (R81 and higher) / SmartUpdate (R80.40 and lower). Because every contract is associated with a container (or Security Gateway) license, it is also required to make sure all relevant Security Gateways have valid licenses as well before updating the contracts information). The automatic contract update task requires Internet connectivity from the Security Management Server. If the Security Management Server does not have Internet connectivity, see the instructions below.
> 2. **Q. I have just manually installed a new Security Gateway, or a new contract. I install the policy, but why do I still see a warning about missing or expired contract for that Security Gateway?**
>
>    **A.** The contract information is update in several points in time: during the periodic scheduled update (by default - every 6 hours and when updating the User Center credentials in SmartConsole). The update process may take a few minutes to complete, so allow up to 10 minutes for the contract information to be reflected in the system.
> 3. **Q. What are the IPS contract requirements in cluster environments?**
>
>    **A.** All members of the same cluster must run the same Security Policy. Specifically, they must use the same IPS policy. If one of the cluster members does not have a valid IPS contract, then IPS will be turned off on the ENTIRE CLUSTER to avoid certain connectivity problems. Make sure all cluster members have valid IPS contracts.
> 4. **Q. How are the IPS contracts managed in a Multi-Domain Management environment?**
>
>    **A.** IPS contracts are managed per Domain Management Server. The Multi-Domain Server neither checks nor alerts on missing or expired IPS contracts. All the IPS contracts should be available on the Domain Management Server (or the directly on the Security Gateways), and all the notifications are provided through the Domain Management Servers.
> 5. **Q. What should I do if my Security Management Server is not connected to the Internet?**
>
>    **A.** If the Security Management Server does not have Internet connectivity, there are 2 alternatives for updating the IPS contracts:
>    * If the SmartConsole client computer has Internet connectivity - use SmartConsole (R81 and higher) / SmartUpdate (R80.40 and lower) to perform online contract update.
>
>    * If the SmartConsole clients also does not have Internet connectivity, you can still update the contracts as follows:
>
>      1. From a computer connected to the Internet, log in to <https://usercenter.checkpoint.com> \> go to the **Products** page, and choose the containers to which the contracts are associated.
>
>      2. From the menu to the right, click "**Save file**". The file produced contains the updated license for this container. Save it on this computer.
>
>      3. Copy the downloaded file to the SmartConsole client computer.
>
>      4. Add the contracts from the file you just copied:
>
>         * In SmartConsole (R81 and higher):  
>           On the left navigation panel, click the **Gateways \& Servers** view \> in the top panel, click the Security Gateway / Cluster object \> in the bottom panel, click the **Licenses** tab \> click **Add** \> click **License File** \> select the file you just copied.
>         * In SmartUpdate (R80.40 and lower):  
>           At the top left corner, click the **Lunch Menu** button \> click **Licenses \& Contracts** \> click **Update Contracts** \> click **From File** \> select the file you just copied.
>
>      You should perform this routine manually every time you renew a contract or add a new gateway to the Security Management Server / Domain Management Server.
> 6. **Q. How can I configure the automatic contracts update to work through a proxy?**
>
>    **A.** The automatic update process is performed on the Security Management Server. There are three ways to configure a proxy server for the Security Management Server:
>    * To configure a proxy server only for IPS updates:
>
>      On the left navigation panel, click the **Security Policies** view \> in the top middle panel, click **Threat Prevention** \> in the bottom middle panel click **Updates** \> at the top, on the yellow notification, click **Configure proxy** \> configure the required proxy server and proxy port \> click **OK**.
>
>      ![](https://sc1.checkpoint.com/sc//SolutionsStatics/sk44175/proxy1907090915.png)
>    * To configure a proxy server for all outbound connections from the Security Management Server:
>
>      On the left navigation panel, click the **Gateways \& Servers** view \> in the top panel, double-click the Security Mangement Server object \> in the left tree, expand the **Network Management** section \> click the **Proxy** page \> configure the required proxy server and proxy port \> click **OK**.
>    * To configure a proxy server for all outbound connections from the Security Management Server and from all managed Security Gateways:
>
>      In the top left corner, click the **Menu** button \> click **Global properties** \> click the **Proxy** page \> configure the required proxy server and proxy port \> click **OK** \> install the Access Control Policy on all managed Security Gateways:
>
>      ![](https://sc1.checkpoint.com/sc//SolutionsStatics/sk44175/r80proxy1902110453.png)

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
