<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Anti-Virus &amp;amp; Content Awareness Archive Issues in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Anti-Virus-amp-Content-Awareness-Archive-Issues/m-p/131705#M19425</link>
    <description>&lt;P&gt;I suspect this is a bug and a TAC case will be necessary here.&lt;/P&gt;</description>
    <pubDate>Wed, 13 Oct 2021 15:37:23 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2021-10-13T15:37:23Z</dc:date>
    <item>
      <title>Anti-Virus &amp; Content Awareness Archive Issues</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Anti-Virus-amp-Content-Awareness-Archive-Issues/m-p/131496#M19384</link>
      <description>&lt;P&gt;Hi CheckMates,&lt;/P&gt;&lt;P&gt;I want to describe one or actually two issues I encounter when using Anti-Virus and Content Awareness on my Check Point Gateways. Both issues seem to be related only for Archive Scanning. First of all some information about the config:&lt;/P&gt;&lt;P&gt;- R80.40 JHF94 (also tested with new install of R81 and R81.10)&lt;BR /&gt;- HTTPS Inspection enabled&lt;BR /&gt;- Anti-Virus enabled (with archive scanning)&lt;BR /&gt;- Content Awareness enabled (should block executable files and some other types)&lt;/P&gt;&lt;P&gt;I can easily reproduce the issue on some basic PuTTY downloads here:&amp;nbsp;&lt;A href="https://www.chiark.greenend.org.uk/~sgtatham/putty/latest.html" target="_blank" rel="noopener"&gt;https://www.chiark.greenend.org.uk/~sgtatham/putty/latest.html&lt;/A&gt;&lt;BR /&gt;putty.zip:&amp;nbsp;&lt;A href="https://the.earth.li/~sgtatham/putty/latest/w64/putty.zip" target="_blank" rel="noopener"&gt;https://the.earth.li/~sgtatham/putty/latest/w64/putty.zip&lt;/A&gt;&lt;BR /&gt;putty.tar.gz:&amp;nbsp;&lt;A href="https://the.earth.li/~sgtatham/putty/latest/putty-0.76.tar.gz" target="_blank" rel="noopener"&gt;https://the.earth.li/~sgtatham/putty/latest/putty-0.76.tar.gz&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Scenario 1 (Content Awareness: enabled / Anti-Virus: disabled):&lt;BR /&gt;Download of putty.zip fails with log message "error while processing putty.chm: File appears corrupted (13)"&lt;BR /&gt;Download of putty.tar.gz gets blocked correctly because of an ".sh" file.&lt;/P&gt;&lt;P&gt;Scenario 2 (Content Awareness: disabled / Anti-Virus: disabled)&lt;BR /&gt;Download of putty.zip fails with log message "Failed to process the file - unknown error"&lt;BR /&gt;Download of putty.tar.gz&amp;nbsp;fails with log message "Failed to process the file - unknown error"&lt;/P&gt;&lt;P&gt;Scenario 3 (Content Awareness: enabled / Anti-Virus: enabled)&lt;BR /&gt;Download of putty.zip fails without log message&lt;BR /&gt;Download of putty.tar.gz gets blocked correctly because of an ".sh" file&lt;/P&gt;&lt;P&gt;I already did some basic debugs from sk103939 and the issue reported is: "error reason: Max files in archive" but I couldn't find any information about that and the archives don't have many files in them.&lt;/P&gt;&lt;P&gt;Did somebody of you encounter similar problems or can verify the issue on their setup? I already have a ticket opened but my TAC experience isn't the best lately and you guys helped a lot in the past&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Oct 2021 12:01:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Anti-Virus-amp-Content-Awareness-Archive-Issues/m-p/131496#M19384</guid>
      <dc:creator>Marcel_Gramalla</dc:creator>
      <dc:date>2021-10-11T12:01:11Z</dc:date>
    </item>
    <item>
      <title>Re: Anti-Virus &amp; Content Awareness Archive Issues</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Anti-Virus-amp-Content-Awareness-Archive-Issues/m-p/131705#M19425</link>
      <description>&lt;P&gt;I suspect this is a bug and a TAC case will be necessary here.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Oct 2021 15:37:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Anti-Virus-amp-Content-Awareness-Archive-Issues/m-p/131705#M19425</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-10-13T15:37:23Z</dc:date>
    </item>
    <item>
      <title>Re: Anti-Virus &amp; Content Awareness Archive Issues</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Anti-Virus-amp-Content-Awareness-Archive-Issues/m-p/131724#M19429</link>
      <description>&lt;P&gt;Yeah, I think it obviously is a bug but as it occurs on clean installations as well my hope was to find somebody that has already experienced something similar and/or can validate my findings.&amp;nbsp;&lt;/P&gt;&lt;P&gt;TAC case already opened as mentioned but (again) not the best experience yet. Investigation hasn't even started yet after a week because of slow response, a canceled call and no instructions from CP.&lt;/P&gt;&lt;P&gt;I will update this thread if we get any mentionable information.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Oct 2021 21:10:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Anti-Virus-amp-Content-Awareness-Archive-Issues/m-p/131724#M19429</guid>
      <dc:creator>Marcel_Gramalla</dc:creator>
      <dc:date>2021-10-13T21:10:56Z</dc:date>
    </item>
    <item>
      <title>Re: Anti-Virus &amp; Content Awareness Archive Issues</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Anti-Virus-amp-Content-Awareness-Archive-Issues/m-p/141318#M21813</link>
      <description>&lt;P&gt;Over four months later Check Point TAC has finally found the issue and provided a temporary workaround with a final solution coming soon hopefully. The issue was actually found pretty fast because of "max_files" reached as the archive has over 500 files but it seemed that nobody knows the Archive Engine at Check Point...&lt;/P&gt;
&lt;P&gt;But to get back to the issue itself: The problem has nothing to do with Content Awareness but only with Anti-Virus. There is actually one sk for changing different parameters of that Archive Engine:&amp;nbsp;&lt;STRONG&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk167312" target="_blank"&gt;Threat Prevention Archive Tool Configuration (checkpoint.com)&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;I also had to learn that Anti-Virus uses parts of Threat Emulation (at least when using Archive Scanning). The parameter "max_files" has a default of 500 and it can be changed in the config but it will default back to 500 as there is a hard coded limit of 500. There is a way to change that default to any other limit so it gets defaulted to that...I won't share this procedure but it's working correctly.&lt;/P&gt;
&lt;P&gt;Check Point will change that behavior in a future update so that we can change the limit according to the sk. From what I understand this will be provided with the regular Anti-Virus/Anti-Bot updates and will not require a Jumbo.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Little rant about TAC:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;All in all I'm happy that this works now but I don't have to say that over four months for such a basic case is way to long (many useless remote sessions, long response times, no summaries after sessions etc.). In addition it's stupid that we had to open a new case because we updated our Gateways in the meantime - never understood why the case can't be changed instead.&lt;/P&gt;</description>
      <pubDate>Sat, 12 Feb 2022 16:26:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Anti-Virus-amp-Content-Awareness-Archive-Issues/m-p/141318#M21813</guid>
      <dc:creator>Marcel_Gramalla</dc:creator>
      <dc:date>2022-02-12T16:26:15Z</dc:date>
    </item>
    <item>
      <title>Re: Anti-Virus &amp; Content Awareness Archive Issues</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Anti-Virus-amp-Content-Awareness-Archive-Issues/m-p/146514#M23276</link>
      <description>&lt;P&gt;Hi Marcell,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Allow me to apologize for the apparently unsatisfactory handling of this case. your rant is noted!!&lt;/P&gt;
&lt;P&gt;I know some time has passed, but would you mind sharing the TAC case number with me?&lt;/P&gt;
&lt;P&gt;I'd like to try to review and understand how we can improve in future cases.&lt;/P&gt;
&lt;P&gt;You can send it to &lt;A href="mailto:yairsp@checkpoint.com" target="_blank"&gt;yairsp@checkpoint.com&lt;/A&gt;&amp;nbsp;for privacy's sake.&lt;/P&gt;
&lt;P&gt;Thanks,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Yair&lt;/P&gt;</description>
      <pubDate>Tue, 19 Apr 2022 17:15:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Anti-Virus-amp-Content-Awareness-Archive-Issues/m-p/146514#M23276</guid>
      <dc:creator>yairsp</dc:creator>
      <dc:date>2022-04-19T17:15:02Z</dc:date>
    </item>
  </channel>
</rss>

