Kerio Control Web Filter Is Not Activated Categorization Is Disabled Hot Instant
Kerio Control: Web Filter Not Activated & Categorization Disabled
Explanation: "Kerio Control web filter is not activated; categorization is disabled; hot"
This phrase likely describes a problem state in Kerio Control where the web filtering feature is not functioning because URL categorization is disabled or unavailable. Below is a full-length, structured explanation covering possible causes, effects, diagnostics, and step-by-step remediation options.
2. Root Causes
There are three primary reasons why this status occurs:
Step 1: Verify Web Filter License Status
Navigate to: Status → License Information (or Configuration → Licenses). Kerio Control: Web Filter Not Activated & Categorization
Look for:
- Web Filter – must say Activated.
- Expiration date – ensure it's not past due.
Solution:
- If expired: Purchase/renew via GFI or a reseller, then enter the new license key under License → Install License.
- If missing: You may have purchased only the basic firewall. Upgrade to Kerio Control Total or add the Web Filter add-on.
Pro tip: After installing a new license, restart the Kerio Control Filtering Service via Status → Services.
3. Fix DNS Resolution
- Use reliable DNS servers (e.g., 8.8.8.8, 1.1.1.1).
- Go to Configuration → DNS and set valid DNS.
- Flush DNS cache: in CLI (if accessible) –
kempctl dns flush.
5. Corrupted Local Cache
Kerio caches category data locally. If the cache database becomes corrupted (e.g., after an unclean shutdown or power outage), the service refuses to start. Web Filter – must say Activated
The Most Common Causes (Ranked by Frequency)
Through years of troubleshooting Kerio installations, these five culprits account for 99% of these errors:
Troubleshooting Guide: Kerio Control Web Filter "Not Activated" & Categorization Disabled
What Does "Categorization is Disabled" Mean?
When categorization is disabled, Kerio Control cannot assign a category to any requested URL. Consequently: Solution:
- Rules using "Web Filter" as a condition are ignored.
- The firewall falls back to basic allow/deny rules based on IP addresses, ports, or raw domains if defined.
In most configurations, this leads to either:
- Overly permissive access (if your default rule is Allow) – users can visit blocked categories.
- Overly restrictive access (if your default rule is Deny) – legitimate business sites get blocked.