> Source: [sk56300](https://support.checkpoint.com/results/sk/sk56300)

# sk56300 - How to check if a Check Point Firewall is covered by an Application Control Software Blade contract in User Center

| Property | Value |
|----------|-------|
| Solution ID | sk56300 |
| Date Created | 2010-10-27 |
| Last Modified | 2026-09-19 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R82, R81.20, R81.10 (EOS), R81 (EOS) |

## Solution

**Table of Contents**

* Overview
  * Licensing and Contracts
  * Application Control Software Blade
* How to verify the status of Application Control contracts in all your Check Point Firewalls
  * Evaluation Contracts
* Notifications about insufficient contract coverage
* What happens when there is no Application Control contract
  * New Installation or Upgrade of R75
  * When using Evaluation Contracts
  * Grace Period
* FAQ

{#2}Overview
------------

### {#2.1}Licensing and Contracts

**License** --- Entitles the Check Point Firewall to run a Software Blade. Installed on the Check Point Firewall, tied to the appliance or IP address.  
**Contract (Support Renewal / subscription)** --- Entitles the Check Point Firewall to receive updates and support for a Service Blade. Attached to the license container in the User Center and renewed annually.  
The Application Control blade is a service blade and therefore requires both a license and a contract.  

For each Check Point Firewall, make sure you have a Check Point Firewall license that includes the Application Control blade, and a valid Application Control contract. For clusters, make sure each cluster member has a license which includes Application Control and a valid Application Control contract.

New and upgraded installations automatically receive a 30-day trial license and updates.

Contact your Check Point representative to get full licenses and contracts.

If you do not have a valid Application Control contract for a Check Point Firewall, the Application Control blade is disabled. When an Application Control contract is about to expire or has already expired, warnings appear.

Warnings appear in:

* The **Message and Action** section of the **Overview** page of the **Application Control**tab.
* The Check Point User Center, when you log in to your account.

### {#2.2}Application Control Software Blade

The Application Control Software Blade is a Service Blade that requires an active Application Control contract, which is renewed annually. The contract enables the Check Point Firewall to download application updates from the Check Point Application Control Update Service. These updates help identify newly released applications, high-risk applications, bandwidth-intensive applications and more.

The Application Control Software Blade verifies the contract status for each Check Point Firewall. If the Application Control contract expires, the Check Point Firewall continues to display expiration warnings during the grace period. After the grace period ends, Application Control functionality is disabled.

How to verify the status of Application Control contracts on your Check Point Firewalls {#3}
--------------------------------------------------------------------------------------------

Each Check Point Firewall that uses the Application Control Software Blade must have a valid Application Control contract. The contract covers both applications that are provided out-of-the-box, as well as new applications, downloaded from the Check Point Application Control Update Service. The Application Control contract covers all applications supported by the Application Control Software Blade. **Without a valid Application Control contract, the Check Point Firewall is not entitled to use any Application Control applications.**

There are 7 types of Application Control Software Blade contracts:

* **CPSB-APCL-XL:** Covers (ultra high-end appliances and software packages) 21400 appliance, 12600 appliance, Power-1 11000, IP 2400 and SG1201.
* **CPSB-APCL-L:** Covers (high-end appliances and software packages) Power-1 5070, Power-1 9070, IP 1200, SG801.
* **CPSB-APCL-M:** Covers most mid-sized appliances and software packages.
* **CPSB-APCL-S:** Covers 2200 appliance, 4200 appliance, 4400 appliance, 4600 appliance, UTM-1 130, UTM-1 270, UTM-1 570 and SG101.
* **CPSB-APCL-L-HA:** Covers (high-end appliances and software packages) Power-1 5070, Power-1 9070, Power-1 11000, IP 1200, IP 2400, SG801 and SG1201. (HA: For High Availability)
* **CPSB-APCL-M-HA:** Covers most mid-sized appliances and software packages. (HA: For High Availability)
* **CPSB-APCL-S-HA:** Covers 2200 appliance, 4200 appliance, 4400 appliance, 4600 appliance, UTM-1 130, UTM-1 270, UTM-1 570 and SG101. (HA: For High Availability)

Contracts are always associated with licenses, or containers. Each contract, including the Application Control Software Blade, must be attached to a Blade Container or, when using NGX licenses, to a valid Check Point Firewall license.

When contracts are purchased, they appear in the relevant User Center account.

To verify if the Check Point Firewall has a valid Application Control contract:

1. In the User Center, go to the **My Products** page.
2. Look for the Check Point Firewall's Container in the Product column. For example, CPSG-P407. (refer to [sk44224: How to match the User Center Product/License to a specific Check Point Firewall](https://support.checkpoint.com/results/sk/sk44224)).
3. Click the link to open the Product Information Page. When you click on a container, you will be able to see the contracts associated with it.
4. In the **Product Information** tab, check if an Application Control blade is attached to the Container. The attached Application Control blade can be a Built-in Blade or an Additional Blade.   

   **Built-in Blades** are purchased as part of a predefined Software Blades system. They *have* a lock displayed.  

   **Additional Blades** are purchased on their own, not as part of a predefined Software Blade system. They *do not have* a lock displayed.   

5. Look for the Support Renewal, to see if the Check Point Firewall is covered by the Application Control Service.

### {#3.1}Evaluation Contracts

New and upgraded installations automatically receive a 30-day trial license and updates. Contact your Check Point representative to get additional evaluation licenses and contracts.

Notifications about insufficient contract coverage

* **Application Control Overview page:** The Overview page of the SmartDashboard Application Control tab includes the Messages and Action Items section. This section shows an alert when a Check Point Firewall has invalid, or insufficient Application Control contract coverage. A different warning appears when contracts are about to expire.
* **Application Control System Logs**: The System log query of the SmartView Tracker Application Control Blade sub-tree shows Application Control update related logs. When a contract is expired, or about to expire, additional information is shown in the log description, describing the contract status.
* **Contract Expiration window:** During policy installation, the Contract Expiration window shows alerts with contract statuses.

{#5}What happens when there is no Application Control contract
--------------------------------------------------------------

You must have an Application Control Software Blade contract to use the Application Control Software Blade functionality on a Check Point Firewall. If a valid Application Control contract is not associated with a Check Point Firewall, the blade will be disabled.

When this change in functionality occurs, customers will be notified by:

* A pop-up warning message that appears on the screen, during policy installation.
* An audit log that is sent periodically, notifying that the Application Control Blade is disabled.

Once you purchase a valid contract, the blade is enabled again.

**Important: When an Application Control Blade is disabled due to insufficient contract, all Application Control settings in SmartDashboard do not change. The blade will appear to be active in SmartDashboard; however it will not be active on the Check Point Firewall.**

### {#5.1}New Installation or Upgrade of R75

A new or an upgraded R75 Check Point Firewall includes a special trial license. This license allows all Application Control functionality for 30 days, starting from the day when the blade was enabled for the first time. **The only licensing difference between an upgrade and a new installation is that in a new installation, a Plug and Play license is granted for 15 days, and the trial license will be effective, only if a new license that does not contain Application Control blade is deployed on the Check Point Firewall.**   
After the trial license expires, the Application Control Blade is disabled.

### {#5.2}When using Evaluation Contracts

The Application Control Software Blade can be evaluated for 30 days with an evaluation contract. Evaluation contracts are treated the same as "regular" contracts, and they allow prospective customers to use full Application Control functionality on the Check Point Firewall, on which they are installed, for the duration of the 30 day evaluation contract. When the evaluation contract expires, the Application Control Blade is disabled.

### {#5.3}Grace Period

The grace period is the time period after the Application Control Blade license expires, during which the blade will still be active and no restrictions are made. However, warnings are issued regarding the missing contracts. The grace period is granted only after a "regular" contract is expired. The grace period is set for 90 days\*, starting from the latest contract expiration date on that Check Point Firewall. The grace periods are calculated per Check Point Firewall, individually.

**Important:
In versions lower than R80.40, there is no grace period for the Application Control and URL Filtering blades.
\*The grace period has been extended for 90 days in:**

**R80.40 JHF Take 196 and above
R81 JHF Take 82 and above
R81.10 JHF Take 93 and above
R81.20 JHF Take 8 and above**

{#6}FAQ
-------

Show All

* How is the contract information updated?  
  When purchasing a new Application Control Blade contract, the contract is added to your User Center account. In most cases, the contract will already be associated to a container (e.g. a Check Point Firewall). If this is not the case, you need to manually associate it (For more information, refer to sk44245: How to check if the Check Point Firewall is covered by an IPS or SmartDefense contract in User Center). On the Check Point Firewall, a task that runs every 2 hours updates the license and contract information from the User Center account to the Check Point Firewall. Since every contract is associated with a container (or Check Point Firewall) license, the system must verify that all relevant Check Point Firewalls have valid licenses, before updating the contracts information). The automatic contract update task requires Internet connectivity from the Check Point Firewall machine.
* I have just manually installed a new Check Point Firewall, or a new contract. When I install the policy, I still see a warning about a missing, or expired contract for that Check Point Firewall. What is wrong?  
  The contract information is updated periodically: during the periodic scheduled update (every 2 hours). The update process may take a few minutes to complete, so allow up to 10 minutes for the new contract information to be available in the system.
* What are the Application Control contract requirements in cluster environments?  
  Generally, all cluster members must run the exact same policy. Specifically, they must use the same Application Control policy. In case one of the cluster members does not have a valid Application Control contract, the Application Control will be turned off on the specific member. Make sure all cluster members have valid Application Control contracts.
* How are the Application Control contracts managed in a Provider-1 environment?  
  Application Control contracts are managed per CMA. The MDS neither checks nor alerts on missing or expired Application Control contracts. All the Application Control contracts should be available on the CMA (or directly on the Check Point Firewalls), and all the notifications are provided through the CMAs.
* What should I do if my Check Point Firewall is not connected to the Internet?  
  If the Check Point Firewall is not connected to the Internet, it cannot be updated with new contracts. Its contract association status will be determined according to the last successful update. Update with new contracts requires Internet connectivity.
* How can I configure the automatic update to work through a proxy?  
  The automatic update process is performed independently on the Check Point Firewall and the Security Management server. In order to allow connections via proxy from the Check Point Firewall or the Security Management Server, in SmartDashboard, in the object properties of a Check Point Firewall or Security Management Server, go to 'Topology \> Proxy'. In a Multi-Domain Security Management environment, configure a proxy in 'Policy \> Global Properties \> Proxy'. Currently, it is not possible to use authenticated proxies to perform Application Control updates.

**Note: In VSX, where the blade is enabled on a certain VS, the VSX (VS0) MUST have connectivity to the Internet.**

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
