Kerio Control Web Filter Is Not Activated Categorization Is Disabled Work Site

nslookup mcafee.url.cloud.gfi.com

Navigate to > Applications and Web Categories . Verify Enable Kerio Control Web Filter is checked. Click Apply to save changes.

Ensure your primary and secondary DNS forwarders are reliable public resolvers (e.g., 8.8.8.8 and 1.1.1.1 ).

Set a calendar reminder 30 days before your GFI license expires. When the license expires, the web filter immediately deactivates. nslookup mcafee

If the ping or name resolution fails, fix your WAN DNS settings under . 4. Clear Corrupt Cache and Force Database Update

Check the option in the firewall rules. 4. Fix "Invalid Authorization" (Zvelo Key Expired)

: It is highly recommended to use Cloudflare (1.1.1.1) or OpenDNS (208.67.222.222) as custom DNS servers for *.zvelo.com URLs. Ensure your primary and secondary DNS forwarders are

If your license is active but the Web Filter remains disabled, the problem may be external. Kerio Control continuously sends automatic DNS check queries to reach its licensing and update servers. If the response is not received for ten consecutive attempts within a single minute, the firewall generates a warning: DNS response timeout, Kerio Control Web Filter categorization disabled .

curl -I https://licensing.gfi.com

When the Web Filter is not activated and categorization disabled: If the ping or name resolution fails, fix

Ensure Kerio Control can reach Zvelo's servers:

When the displays a "Not Activated" status and categorization is disabled, your network loses its primary defense against malicious and inappropriate web content. This issue typically stems from licensing lapses, DNS resolution failures, or expired communication tokens with the Zvelo categorization service. Primary Causes for Activation Issues

: Incorrect system time prevents secure SSL handshakes with Kerio servers. Step 1: Verify License and Subscription Status

While categorization is disabled, you can still filter using .

Create or verify a rule at the top of the firewall ruleset: