> Source: [sk94508](https://support.checkpoint.com/results/sk/sk94508)

# sk94508 - Recommended Internet Access Settings for Automatic Downloads

| Property | Value |
|----------|-------|
| Solution ID | sk94508 |
| Date Created | 2013-08-22 |
| Last Modified | 2026-02-16 |
| Technical Level | General |
| Products | Security Gateway, Security Management Server, Multi-Domain Security Management Server |
| Versions | R82.10, R82, R81.20, R81.10 (EOS), R82.10, R82, R81.20, R82.10, R81 (EOS), R81.10 (EOS), R81 (EOS), R81 (EOS), R81.10 (EOS), R81.20, R82 |
| OS | Gaia |

## Solution

**Table of Contents:**

1. Introduction
2. Offline Mode Limitations
   * Blade Contracts
   * SmartConsole
   * General
3. Offline Mode Scope
4. Related solutions

Introduction {#Introduction}
----------------------------

**In the First Time Configuration Wizard on Gaia OS, you have the option to enable or disable automatic downloads of Blade Contracts, Check Point Releases / Hotfixes via CPUSE, and data for complete functionality of Software Blades and features.**

It is highly recommended that you keep this option enabled to ensure the smooth operation of Check Point products.

**Notes:**

* The type of downloaded data may change from version to version.

* Before the Check Point Quantum Security Gateway and/or Management Server can automatically download the necessary software packages from the Check Point cloud, your device must share the following technical data with Check Point:

  * The installed license
  * The installed software version
  * The hardware platform, MAC Address, and Serial Number

  If you choose to disable this automatic download feature, the product will not be able to download the packages **automatically**. In such a case, you will need to manually download and install the desired packages per the information detailed in the relevant articles in the Check Point Support Center.

Offline Mode Limitations {#Offline Mode Limitations}
----------------------------------------------------

> ### Blade Contracts {#Offline Mode Limitations - Blade Contracts}
>
> Blade Contracts are annual blade licenses. Their renewal, from the UserCenter, is necessary for complete product functionality. If you disable this setting, Blade Contracts cannot be automatically updated. If your local contract is missing or expired, these limitations apply:
>
> |-------------------------------------|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
> | Blade / Feature                     | Limitation                                                                                                                                                                                        |
> | Threat Emulation local mode         | Files will not be emulated.                                                                                                                                                                       |
> | Data Loss Prevention blade          | Will operate in Bypass mode if there is no valid contract installed on Security Gateway (the contract can be installed manually via SmartUpdate, and DLP will enforce its policy on the traffic). |
> | Compliance blade                    | Will not execute scans.                                                                                                                                                                           |
> | Endpoint Security Policy Management | License report in SmartEndpoint will not be accurate.                                                                                                                                             |
> | CPinfo                              | Self-update is not applicable.                                                                                                                                                                    |
>
> ### SmartConsole {#Offline Mode Limitations - SmartConsole}
>
> |------------------------------|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
> | Blade / Feature              | Limitation                                                                                                                                                                                                         |
> | IPS                          | * IPS updates from UserCenter will fail.                                                                                                                                                                           |
> | Application \& URL Filtering | * AppWiki will not work. * No update of "Messages and Actions" frame in Overview view. * No update of the applications picker in the Policy view. * Search for categorization of sites via overview tab will fail. |
> | Threat Prevention            | * ThreatWiki will not work. * No protections picker in Global Exceptions view. * No Protections view. * No search for malware from Overview. * No RSS feed.                                                        |
> | Threat Emulation             | * No image and file type updates.                                                                                                                                                                                  |
>
> ### General {#Offline Mode Limitations - General}
>
> * Trusted Certificate Authorities (CAs) list will not be updated.
> * No update of Check Point certificate bundle.
> * Relevant upgrade packages will not be shown by [CPUSE Agent](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk92449) (in Gaia Portal / Gaia Clish).

Offline Mode Scope {#Offline Mode Scope}
----------------------------------------

Even in Offline mode, if an activated Software Blade requires external services, it will still connect to Check Point Cloud to get the required data:
>
> |---------------------------------|---------------------------------------------------------------------------------------------------------------------------------------------------------------------|
> | Blade / Feature                 | Limitation                                                                                                                                                          |
> | IPS                             | * Download Geo protection updates * Download malicious IPs lists * Validate Blade contract entitlement                                                              |
> | Application Control             | * Download applications database * Detect social network widgets * Run and return results of cloud-based application analysis * Validate Blade contract entitlement |
> | URL Filtering                   | * Download initial local database * Run and return results of cloud-based categorization * Validate Blade contract entitlement                                      |
> | HTTPS Inspection                | * Update bypass list                                                                                                                                                |
> | Anti-Spam, Anti-Bot, Anti-Virus | * Download updates to the local signature database * Run and return results of cloud-based security analysis * Validate Blade contract entitlement                  |
> | Compliance                      | * Download latest regulations and best practices                                                                                                                    |
> | Endpoint Policy Management      | * Download updates to the malware database                                                                                                                          |
> | Endpoint Anti-Malware           | * Run and return results of cloud-based malware categorization                                                                                                      |
> | Endpoint Application Control    | * Download application database * Run and return results of cloud-based application analysis                                                                        |

This setting on a Management Server applies to all managed Security Gateways (R77 and higher).

**To change this setting after completing the First Time Configuration Wizard, refer to:**

* For R81.20 and higher:  
  [sk175504 - How to configure Check Point software to upload data to Check Point / download data from Check Point in versions R81.20 and higher](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk175504)
* For R81.10 and lower:  
  [sk111080 - How to configure Check Point software to upload data to Check Point / download data from Check Point in versions R81.10 and lower](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk111080)

Related solutions {#Related solutions}
--------------------------------------

* [sk175504 - How to configure Check Point software to upload data to Check Point / download data from Check Point in versions R81.20 and higher](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk175504)
* [sk111080 - How to configure Check Point software to upload data to Check Point / download data from Check Point in versions R81.10 and lower](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk111080)
* [sk106251 - How to configure Security Gateway to accept its own traffic only to Check Point online services](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk106251)
* [sk94509 - Recommended Internet Access Settings for Uploading Data](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk94509)

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
