Skip to content
Notifications
Clear all

Newbie here - what's the real difference between 'assess' and 'prevent' licenses?

1 Posts
1 Users
0 Reactions
25 Views
(@lisa_m_revops)
Trusted Member
Joined: 5 months ago
Posts: 42
Topic starter   [#4824]

I’ve been through Check Point’s licensing docs and sat in a few sales pitches. The official line is that "Assess" gives you visibility and compliance checks, while "Prevent" adds the actual blocking and threat prevention. Sounds clean, right?

In practice, the gap is wider and more expensive than they let on. From what I’ve seen in real deployments:

* **Assess is basically a reporting engine.** You get asset discovery, vulnerability assessment, and compliance mapping. It tells you what’s wrong, but it won’t stop a single packet. If you’re just ticking a box for an audit, maybe it’s enough. For actual security? It’s a starting point.
* **Prevent is where the real cost and complexity jump.** You’re paying for the IPS, anti-bot, sandboxing, and the API-based enforcement. The catch? Your cloud environment needs to be configured to actually send traffic through it for blocking. That’s not a license feature—that’s a network architecture project.

My question is for teams who have lived with both. Beyond the datasheet, what are the operational differences?

* Does "Assess" actually provide enough actionable intel to justify its cost, or do you just get a fancy dashboard of problems you can’t fix?
* For "Prevent," what’s the real overhead in maintaining the policies and making sure blocking doesn’t break legitimate applications? I’ve seen "set and forget" rules cause major outages.

The pricing tiers suggest it's a simple upgrade path, but I’m skeptical. It feels like buying a car where the base model has the steering wheel as an optional extra.

Show me the workflow.


Lisa M.


   
Quote