<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: File size for emulation in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/File-size-for-emulation/m-p/7250#M14079</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can set the maximum file size here (in R80.10):&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/59549_pastedImage_1.png" style="width: 620px; height: 248px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 09 Oct 2017 04:24:40 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2017-10-09T04:24:40Z</dc:date>
    <item>
      <title>File size for emulation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/File-size-for-emulation/m-p/7245#M14074</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Is there a minimum file size for emulation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried downloading a file from eicar.com which was 68 Bytes. But it didnt get emulated, while a file size of 308Bytes got emulated from the same site.&lt;/P&gt;&lt;P&gt;Is this configurable in TE appliance, where we could define the minimum and maximum file size for emulation.&lt;/P&gt;&lt;P&gt;also, Is it possible to exclude some traffic for emulation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Biju&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 08 Oct 2017 17:11:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/File-size-for-emulation/m-p/7245#M14074</guid>
      <dc:creator>Biju_Nair</dc:creator>
      <dc:date>2017-10-08T17:11:39Z</dc:date>
    </item>
    <item>
      <title>Re: File size for emulation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/File-size-for-emulation/m-p/7246#M14075</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you are running anti-virus while downloading the eicar file, it should have caught it and not have to be emulated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Maximum file size can be configured. In R80.10 you can find it in "Manage &amp;amp; Settings -&amp;gt; Blades -&amp;gt; Threat Prevention -&amp;gt; Theat Emulation".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As far as I know, there is no lower limit, and it can't be configured&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the threat prevention policy, you decide the "Protected Scope". Here you&amp;nbsp; decide what traffic you want to be inspected according to which Threat prevention profile. So if you wish that some traffic should not be emulated, you can define a new rule, with a threat prevention profile that does not run Threat emulation.&lt;/P&gt;&lt;P&gt;This is assuming your activation mode is According to policy (Check Open the TE unit-&amp;gt; Threat Emulation)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 08 Oct 2017 18:36:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/File-size-for-emulation/m-p/7246#M14075</guid>
      <dc:creator>Albin_Hakansson</dc:creator>
      <dc:date>2017-10-08T18:36:46Z</dc:date>
    </item>
    <item>
      <title>Re: File size for emulation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/File-size-for-emulation/m-p/7247#M14076</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The reason for my question was I was trying to download a file from eicar.com which was 68Bytes and it didn't emulate. However a 308Bytes file got emulated. From the same website. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What could have happened that the 68Byte file didn't emulate. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Biju Nair&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from my iPhone&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 08 Oct 2017 19:04:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/File-size-for-emulation/m-p/7247#M14076</guid>
      <dc:creator>Biju_Nair</dc:creator>
      <dc:date>2017-10-08T19:04:50Z</dc:date>
    </item>
    <item>
      <title>Re: File size for emulation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/File-size-for-emulation/m-p/7248#M14077</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm not sure. Was it the HTTPS file maybe and you are not running HTTPS inspection?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What does your traffic logs say?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 08 Oct 2017 19:15:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/File-size-for-emulation/m-p/7248#M14077</guid>
      <dc:creator>Albin_Hakansson</dc:creator>
      <dc:date>2017-10-08T19:15:30Z</dc:date>
    </item>
    <item>
      <title>Re: File size for emulation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/File-size-for-emulation/m-p/7249#M14078</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It was a http traffic. I forgot to mention one thing that the http traffic is actually from the proxy via ICAP to TE device. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To answer u.... In the firewall log it shows the ICAP traffic from proxy and then in the emulation log it doesnt show anything. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Biju Nair&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from my iPhone&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Oct 2017 03:43:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/File-size-for-emulation/m-p/7249#M14078</guid>
      <dc:creator>Biju_Nair</dc:creator>
      <dc:date>2017-10-09T03:43:15Z</dc:date>
    </item>
    <item>
      <title>Re: File size for emulation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/File-size-for-emulation/m-p/7250#M14079</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can set the maximum file size here (in R80.10):&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/59549_pastedImage_1.png" style="width: 620px; height: 248px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Oct 2017 04:24:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/File-size-for-emulation/m-p/7250#M14079</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2017-10-09T04:24:40Z</dc:date>
    </item>
    <item>
      <title>Re: File size for emulation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/File-size-for-emulation/m-p/7251#M14080</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi - Please see the AV/AB logs in case enabled, it might have processed with these blades before the file could be emulated.&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Oct 2017 05:23:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/File-size-for-emulation/m-p/7251#M14080</guid>
      <dc:creator>Prashant</dc:creator>
      <dc:date>2017-10-09T05:23:49Z</dc:date>
    </item>
    <item>
      <title>Re: File size for emulation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/File-size-for-emulation/m-p/7252#M14081</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Nope. AV blade currently is not offically available in ICAP - so that can´t be the issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Did you check access.log of the ICAP server to be sure the EICAR.COM is really passed to us ?&lt;/P&gt;&lt;P&gt;access.log is stored in&amp;nbsp;$FWDIR/log/c-icap/&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It is advisable to change the logformat before consulting the log otherwise you won´t "see" much infos in this log.&lt;/P&gt;&lt;P&gt;To extend logging do the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) vi /opt/CPsuite-R77/fw1/c-icap/etc/c-icap.conf&lt;BR /&gt;2) Search for “AccessLog /opt/CPsuite-R77/fw1/log/c-icap/access.log”&lt;BR /&gt;3) Add this line before the abaove finding:&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;LogFormat accessFormat "%tl, %la %a %im %iu %is %huo '%&amp;lt;ho' '%{X-Infection-Found}&amp;lt;ih'"&lt;BR /&gt;4) Change the AccessLog line to:&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;AccessLog /opt/CPsuite-R77/fw1/log/c-icap/access.log accessFormat&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So the section in c-icap.conf should now look like this:&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;LogFormat accessFormat "%tl, %la %a %im %iu %is %huo '%&amp;lt;ho' '%{X-Infection-Found}&amp;lt;ih'"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;AccessLog /opt/CPsuite-R77/fw1/log/c-icap/access.log accessFormat&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So the troubleshooting flow should be:&lt;/P&gt;&lt;P&gt;1) Do you see the file from the proxy to our ICAP server in access.log&lt;/P&gt;&lt;P&gt;2) Do you see the file being handled in $FWDIR/log/ted.elg&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards Thomas&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 27 Oct 2017 13:49:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/File-size-for-emulation/m-p/7252#M14081</guid>
      <dc:creator>Thomas_Werner</dc:creator>
      <dc:date>2017-10-27T13:49:58Z</dc:date>
    </item>
  </channel>
</rss>

