To clarify, the checkbox in the local GUI affects whether the client provides/contributes additional anonymous information upstream which helps us develop the service (URLs visited etc). It does not affect whether the Real-Time Protection Network Client is in use or not. In fact if you disable the setting, Real-Time Protection client still stays connected & active.
To check the status of the Real-time Protection Network: - On the main page, click Settings - select Other settings, Connection Network status stays "Connected" even if you uncheck the checkbox in the GUI. If you need to disable the client completely which is not recommended(!) but is an option in a completely closed network environment, use Policy Manager Console: F-Secure Real-time Protection Network Client Settings Client is enabled = No This disables the Real-time protection client. With regards to the DNS queries, I do recollect a previous problem where if Automatic Update Agent fails to resolve fsbwserver.f-secure.com it will continuously retry the attempt, even if fallback to F-Secure Update Servers is disabled.
The issue is not fixed but there is a workaround: configure a local DNS server to resolve fsbwserver.f-secure.com to some dummy address.
Hope this helps!
... View more