Your subscription

Forcepoint subscriptions are issued on a per-client (IP address) basis.

To activate your software, enter a valid subscription key (see Configuring your account information). This lets you:

  • Download the Forcepoint URL Database (see The Forcepoint URL Database), enabling policy enforcement.
  • (Forcepoint Web Security only) Download the analytic databases to support real- time analysis of web content.

After the first successful database download, the Web > Settings > General > Account page in the Forcepoint Security Manager displays the number of clients your subscription includes and your subscription type (Forcepoint Web Security or Forcepoint URL Filtering).

A component called Filtering Service maintains a subscription table of clients generating Internet requests.

When the number of subscribed clients exceeds the licensed count, Forcepoint Web Security tracks usage per unique client IP address over a rolling interval. The default interval is 24 hours. Once the licensed seat count is reached for that interval, the product treats any additional client IP address as over-subscription.

The Block users when subscription is exceeded setting on the Settings > General > Account page controls whether the product blocks or allows that traffic:

  • If you disable the option (the default), the product allows over-subscription traffic through but does not apply category-based policy. Filtering Service logs each request as an unfiltered "exceeded" event. Client IP addresses already counted before the limit was reached continue to be filtered normally.
  • If you enable the option, the product blocks over-subscription traffic and displays the standard policy block page.

This same setting handles subscription expiration. An expired (non-perpetual) subscription causes the effective licensed count to drop to zero, so the product treats all client traffic as over-subscription from that point forward.

Note: This behavior is the same for Forcepoint Web Security and Forcepoint URL Filtering deployments.

If the subscription is consistently exceeded, you may be asked to increase your subscription limit.

In all deployments, when a subscription expires, all requests are permitted or blocked, depending on the same configurable setting. When the expiration date approaches, administrators are notified through a combination of email alerts and health alerts displayed in the Security Manager.

  • To configure how Internet requests are handled when a subscription expires, see Configuring your account information.
  • To have an alert message sent when the subscription approaches or exceeds its limit, see Configuring system alerts.