<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Anti-Bot response with wrong status code in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Anti-Bot-response-with-wrong-status-code/m-p/227802#M43844</link>
    <description>&lt;P&gt;Here is the output&lt;/P&gt;&lt;P&gt;[Expert@Firewall01:0]# cat $FWDIR/conf/rad_conf.C&lt;BR /&gt;(&lt;BR /&gt;:urlfs_service_check_seconds (7200)&lt;BR /&gt;:amws_service_check_seconds (1800)&lt;BR /&gt;:cpu_cores_as_number_of_threads (false)&lt;BR /&gt;:number_of_threads (0)&lt;BR /&gt;:threads_to_cores_ratio (0.334)&lt;BR /&gt;:minimal_resources_usage_ratio (0.2)&lt;BR /&gt;:number_of_threads_fast_response (0)&lt;BR /&gt;:number_of_threads_slow_response (0)&lt;BR /&gt;:queue_max_capacity (2000)&lt;BR /&gt;:debug_traffic (false)&lt;BR /&gt;:use_dns_cache (true)&lt;BR /&gt;:dns_cache_timeout_sec (2)&lt;BR /&gt;:use_ssl_cache (true)&lt;BR /&gt;:cert_file_name ("ca-bundle.crt")&lt;BR /&gt;:cert_type ("CRT")&lt;BR /&gt;:ssl_version ("TLSv1_0")&lt;BR /&gt;:ciphers ("TLSv1")&lt;BR /&gt;:autodebug (true)&lt;BR /&gt;:timeout_events (false)&lt;BR /&gt;:normal_flow_events (false)&lt;BR /&gt;:log_timeouts (false)&lt;BR /&gt;:log_errors (true)&lt;BR /&gt;:number_of_reports (512)&lt;BR /&gt;:max_repository_multiplier (20)&lt;BR /&gt;:flow_timeout (6)&lt;BR /&gt;:excessive_flow_timeout (120)&lt;BR /&gt;:transfer_timeout_sec (15)&lt;BR /&gt;:max_flows (2000)&lt;BR /&gt;:max_pc_in_reply (0)&lt;BR /&gt;:retry_mechanism_on (true)&lt;BR /&gt;:max_retries (25)&lt;BR /&gt;:retry_peroid_mins (15)&lt;/P&gt;&lt;P&gt;)&lt;BR /&gt;[Expert@Firewall01:0]#&lt;/P&gt;</description>
    <pubDate>Tue, 24 Sep 2024 17:34:51 GMT</pubDate>
    <dc:creator>gurowar</dc:creator>
    <dc:date>2024-09-24T17:34:51Z</dc:date>
    <item>
      <title>Anti-Bot response with wrong status code</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Anti-Bot-response-with-wrong-status-code/m-p/227796#M43842</link>
      <description>&lt;P&gt;Good day all,&lt;/P&gt;&lt;P&gt;I was wondering if anyone had a similar issue with there smartconsole, I have a pair of 16200 firewalls, managing them via smartconsole. I noticed in the logs that I am getting a lot of Anti-bot system alerts.&amp;nbsp; It seems to start up around 6am and stops about 4-5pm. I haven't looked at all the messages but the 2 or 3 I opened up today are:&lt;/P&gt;&lt;P&gt;Response with wrong status code., check /opt/CPsuite-R81.10/fw1/log/rad_events/Errors/flow_75937_42293907 For more details&lt;/P&gt;&lt;P&gt;[rad_curl_task.cpp:123] CRadCurlTask::run: [ERROR] Response status = 504&lt;/P&gt;&lt;P&gt;not sure what that means but that is all I see in the logs&lt;/P&gt;&lt;P&gt;Failed to Decrypt CP Site Response., check /opt/CPsuite-R81.10/fw1/log/rad_events/Errors/flow_75937_42306671 For more details&lt;/P&gt;&lt;P&gt;Flow Termination Status:Failed!&lt;/P&gt;&lt;P&gt;FlowError=Failed to Decrypt CP Site Response.&lt;/P&gt;&lt;P&gt;[rad_keyset.cpp:49] CRadRepositoryContaineData::getRadEncKeyByServiceKey: [INFO] no key found for requested service: malware+0returning default&lt;/P&gt;&lt;P&gt;[rad_decrypted_response_task.cpp:134] CRadDecryptedResponseTask::decrypt: [ERROR] response size is 1232944' limit to 1000000&lt;BR /&gt;[rad_decrypted_response_task.cpp:80] CRadDecryptedResponseTask::getResponseString: [ERROR] failed to decrypt response 0xdd054518&lt;BR /&gt;[rad_response_task.cpp:67] CRadResponseTask::run: [ERROR] can not get response string&lt;/P&gt;&lt;P&gt;What key is this looking for?&lt;/P&gt;&lt;P&gt;Going to check the rest of the logs but the 3 I opened, 2 of them has that&amp;nbsp;Response with wrong status code and the other one&amp;nbsp;Failed to Decrypt CP Site Response&lt;/P&gt;&lt;P&gt;Is this a problem&amp;nbsp; or is this normal?&lt;/P&gt;&lt;P&gt;Thank you in advance!!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Sep 2024 16:54:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Anti-Bot-response-with-wrong-status-code/m-p/227796#M43842</guid>
      <dc:creator>gurowar</dc:creator>
      <dc:date>2024-09-24T16:54:37Z</dc:date>
    </item>
    <item>
      <title>Re: Anti-Bot response with wrong status code</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Anti-Bot-response-with-wrong-status-code/m-p/227801#M43843</link>
      <description>&lt;P&gt;Please share&amp;nbsp;&lt;SPAN&gt;$FWDIR/conf/&lt;/SPAN&gt;&lt;STRONG&gt;rad_conf&lt;/STRONG&gt;&lt;SPAN&gt;.C from relevant gateway&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Sep 2024 17:32:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Anti-Bot-response-with-wrong-status-code/m-p/227801#M43843</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2024-09-24T17:32:15Z</dc:date>
    </item>
    <item>
      <title>Re: Anti-Bot response with wrong status code</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Anti-Bot-response-with-wrong-status-code/m-p/227802#M43844</link>
      <description>&lt;P&gt;Here is the output&lt;/P&gt;&lt;P&gt;[Expert@Firewall01:0]# cat $FWDIR/conf/rad_conf.C&lt;BR /&gt;(&lt;BR /&gt;:urlfs_service_check_seconds (7200)&lt;BR /&gt;:amws_service_check_seconds (1800)&lt;BR /&gt;:cpu_cores_as_number_of_threads (false)&lt;BR /&gt;:number_of_threads (0)&lt;BR /&gt;:threads_to_cores_ratio (0.334)&lt;BR /&gt;:minimal_resources_usage_ratio (0.2)&lt;BR /&gt;:number_of_threads_fast_response (0)&lt;BR /&gt;:number_of_threads_slow_response (0)&lt;BR /&gt;:queue_max_capacity (2000)&lt;BR /&gt;:debug_traffic (false)&lt;BR /&gt;:use_dns_cache (true)&lt;BR /&gt;:dns_cache_timeout_sec (2)&lt;BR /&gt;:use_ssl_cache (true)&lt;BR /&gt;:cert_file_name ("ca-bundle.crt")&lt;BR /&gt;:cert_type ("CRT")&lt;BR /&gt;:ssl_version ("TLSv1_0")&lt;BR /&gt;:ciphers ("TLSv1")&lt;BR /&gt;:autodebug (true)&lt;BR /&gt;:timeout_events (false)&lt;BR /&gt;:normal_flow_events (false)&lt;BR /&gt;:log_timeouts (false)&lt;BR /&gt;:log_errors (true)&lt;BR /&gt;:number_of_reports (512)&lt;BR /&gt;:max_repository_multiplier (20)&lt;BR /&gt;:flow_timeout (6)&lt;BR /&gt;:excessive_flow_timeout (120)&lt;BR /&gt;:transfer_timeout_sec (15)&lt;BR /&gt;:max_flows (2000)&lt;BR /&gt;:max_pc_in_reply (0)&lt;BR /&gt;:retry_mechanism_on (true)&lt;BR /&gt;:max_retries (25)&lt;BR /&gt;:retry_peroid_mins (15)&lt;/P&gt;&lt;P&gt;)&lt;BR /&gt;[Expert@Firewall01:0]#&lt;/P&gt;</description>
      <pubDate>Tue, 24 Sep 2024 17:34:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Anti-Bot-response-with-wrong-status-code/m-p/227802#M43844</guid>
      <dc:creator>gurowar</dc:creator>
      <dc:date>2024-09-24T17:34:51Z</dc:date>
    </item>
    <item>
      <title>Re: Anti-Bot response with wrong status code</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Anti-Bot-response-with-wrong-status-code/m-p/227804#M43845</link>
      <description>&lt;P&gt;&lt;SPAN&gt;You can start with below. If you don't trust open TAC case and they can give you custom advise (every setup is different)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Edit file on both cluster members and save it. After change:&amp;nbsp;rad_admin stop ; sleep 5 ; rad_admin start&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Sleep is important!&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;urlfs_service_check_seconds (7200)&lt;/SPAN&gt;&lt;BR /&gt;&lt;STRONG&gt;:amws_service_check_seconds (7200)&lt;/STRONG&gt;&lt;BR /&gt;&lt;SPAN&gt;:cpu_cores_as_number_of_threads (false)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;:number_of_threads (0)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;:threads_to_cores_ratio (0.334)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;:minimal_resources_usage_ratio (0.2)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;:number_of_threads_fast_response (0)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;:number_of_threads_slow_response (0)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;:&lt;STRONG&gt;queue_max_capacity (4000)&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;:debug_traffic (false)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;:use_dns_cache (true)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;:dns_cache_timeout_sec (2)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;:use_ssl_cache (true)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;:cert_file_name ("ca-bundle.crt")&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;:cert_type ("CRT")&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;:ssl_version ("TLSv1_0")&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;:ciphers ("TLSv1")&lt;/SPAN&gt;&lt;BR /&gt;&lt;STRONG&gt;:autodebug (false)&lt;/STRONG&gt;&lt;BR /&gt;&lt;SPAN&gt;:timeout_events (false)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;:normal_flow_events (false)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;:log_timeouts (false)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;:log_errors (true)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;:number_of_reports (512)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;:max_repository_multiplier (20)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;:flow_timeout (6)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;:excessive_flow_timeout (120)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;:transfer_timeout_sec (15)&lt;/SPAN&gt;&lt;BR /&gt;&lt;STRONG&gt;:max_flows (3000)&lt;/STRONG&gt;&lt;BR /&gt;&lt;SPAN&gt;:max_pc_in_reply (0)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;:retry_mechanism_on (true)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;:max_retries (25)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;:retry_peroid_mins (15)&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Sep 2024 18:00:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Anti-Bot-response-with-wrong-status-code/m-p/227804#M43845</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2024-09-24T18:00:49Z</dc:date>
    </item>
    <item>
      <title>Re: Anti-Bot response with wrong status code</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Anti-Bot-response-with-wrong-status-code/m-p/227805#M43846</link>
      <description>&lt;P&gt;Hi Lesley,&lt;/P&gt;&lt;P&gt;Will try and keep you posted I have a call with checkpoint tomorrow as well but let me try your suggestion first, then see what they say.&lt;/P&gt;&lt;P&gt;Keep you posted but for now thank you!!!!&lt;/P&gt;</description>
      <pubDate>Tue, 24 Sep 2024 18:05:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Anti-Bot-response-with-wrong-status-code/m-p/227805#M43846</guid>
      <dc:creator>gurowar</dc:creator>
      <dc:date>2024-09-24T18:05:15Z</dc:date>
    </item>
    <item>
      <title>Re: Anti-Bot response with wrong status code</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Anti-Bot-response-with-wrong-status-code/m-p/227926#M43847</link>
      <description>&lt;P&gt;Just an update on this, talked to Checkpoint and what we did was&amp;nbsp;&lt;/P&gt;&lt;P&gt;sed -i 's/:autodebug (true)/:autodebug (false)/' $FWDIR/conf/rad_conf.C&lt;BR /&gt;rad_admin stop ; sleep 5 ; rad_admin start&lt;/P&gt;&lt;P&gt;didn't have to make any changes to the other fields in the rad_conf.C file as I am told this should cause an auto calculation for rest of the values in the file.&amp;nbsp; Made the changes an hour ago and so far haven't seen an Anti-Bot alert but we will see.&lt;/P&gt;</description>
      <pubDate>Wed, 25 Sep 2024 16:54:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Anti-Bot-response-with-wrong-status-code/m-p/227926#M43847</guid>
      <dc:creator>gurowar</dc:creator>
      <dc:date>2024-09-25T16:54:09Z</dc:date>
    </item>
    <item>
      <title>Re: Anti-Bot response with wrong status code</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Anti-Bot-response-with-wrong-status-code/m-p/228260#M43902</link>
      <description>&lt;P&gt;Good day all,&lt;/P&gt;&lt;P&gt;Happy Friday!!!&amp;nbsp; Just to give an update on this, the only change that was recommended was to change&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;:autodebug (false)&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;and nothng else because by doing this, this change will automatically update the rest of the values in the rad.config.C. So I what was recommended but nothing changed&amp;nbsp; in the past day.&amp;nbsp; Not sure if that was because it didn't work or the way it is configured is the ways it supposed to be, minus the autodebug.&amp;nbsp; So what I did was updated just 2 things that suggested here to and left autodebug to false to see if if will auto configure as they say.&amp;nbsp; &amp;nbsp;But we are making progress there is a lot less Auto-Bot messages scrolling in, hopefully updating the 2 setting will drop it more but we will see.&lt;/P&gt;&lt;P&gt;[Expert@Firewall01:0]# cat $FWDIR/conf/rad_conf.C&lt;BR /&gt;(&lt;BR /&gt;:urlfs_service_check_seconds (7200)&lt;BR /&gt;&lt;STRONG&gt;:amws_service_check_seconds (5400)&lt;/STRONG&gt;&lt;BR /&gt;:cpu_cores_as_number_of_threads (false)&lt;BR /&gt;:number_of_threads (0)&lt;BR /&gt;:threads_to_cores_ratio (0.334)&lt;BR /&gt;:minimal_resources_usage_ratio (0.2)&lt;BR /&gt;:number_of_threads_fast_response (0)&lt;BR /&gt;:number_of_threads_slow_response (0)&lt;BR /&gt;&lt;STRONG&gt;:queue_max_capacity (4000)&lt;/STRONG&gt;&lt;BR /&gt;:debug_traffic (false)&lt;BR /&gt;:use_dns_cache (true)&lt;BR /&gt;:dns_cache_timeout_sec (2)&lt;BR /&gt;:use_ssl_cache (true)&lt;BR /&gt;:cert_file_name ("ca-bundle.crt")&lt;BR /&gt;:cert_type ("CRT")&lt;BR /&gt;:ssl_version ("TLSv1_0")&lt;BR /&gt;:ciphers ("TLSv1")&lt;BR /&gt;:autodebug (false)&lt;BR /&gt;:timeout_events (false)&lt;BR /&gt;:normal_flow_events (false)&lt;BR /&gt;:log_timeouts (false)&lt;BR /&gt;:log_errors (true)&lt;BR /&gt;:number_of_reports (512)&lt;BR /&gt;:max_repository_multiplier (20)&lt;BR /&gt;:flow_timeout (6)&lt;BR /&gt;:excessive_flow_timeout (120)&lt;BR /&gt;:transfer_timeout_sec (15)&lt;BR /&gt;:max_flows (2000)&lt;BR /&gt;:max_pc_in_reply (0)&lt;BR /&gt;:retry_mechanism_on (true)&lt;BR /&gt;:max_retries (25)&lt;BR /&gt;:retry_peroid_mins (15)&lt;/P&gt;</description>
      <pubDate>Fri, 27 Sep 2024 16:47:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Anti-Bot-response-with-wrong-status-code/m-p/228260#M43902</guid>
      <dc:creator>gurowar</dc:creator>
      <dc:date>2024-09-27T16:47:15Z</dc:date>
    </item>
    <item>
      <title>Re: Anti-Bot response with wrong status code</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Anti-Bot-response-with-wrong-status-code/m-p/228774#M44052</link>
      <description>&lt;P&gt;Good day all,&lt;/P&gt;&lt;P&gt;Just wanted to update on this, looks like changing the following in&amp;nbsp;rad_conf.C&amp;nbsp;&lt;/P&gt;&lt;P&gt;:amws_service_check_seconds (5400)&lt;/P&gt;&lt;P&gt;:queue_max_capacity (4000)&lt;/P&gt;&lt;P&gt;:autodebug (false)&lt;/P&gt;&lt;P&gt;has quieted the Anti-bot logs, not completely but quit a bit.&amp;nbsp; So far today we only have 3, also perhaps I misunderstood the engineer but turning off autodebug, in due time it would auto configure teh settings in&amp;nbsp;rad_conf.C file but since I made the changes last week Friday, they are still the same.&amp;nbsp; I would assume it would have auto correct by now. I will monitor the rest of the week and if there is any changes or update will let you know.&amp;nbsp; But for now this seems to have fixed my issue.&lt;/P&gt;&lt;P&gt;Thank you, All!!&lt;/P&gt;&lt;P&gt;Warren&lt;/P&gt;</description>
      <pubDate>Wed, 02 Oct 2024 15:44:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Anti-Bot-response-with-wrong-status-code/m-p/228774#M44052</guid>
      <dc:creator>gurowar</dc:creator>
      <dc:date>2024-10-02T15:44:58Z</dc:date>
    </item>
    <item>
      <title>Re: Anti-Bot response with wrong status code</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Anti-Bot-response-with-wrong-status-code/m-p/232435#M44853</link>
      <description>&lt;P&gt;Please also check&lt;/P&gt;&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk182494" target="_blank"&gt;sk182494 - Anti-Bot Blade generates error logs with the reason "Failed to Decrypt CP Site Response"&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Peter&lt;/P&gt;</description>
      <pubDate>Tue, 12 Nov 2024 11:17:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Anti-Bot-response-with-wrong-status-code/m-p/232435#M44853</guid>
      <dc:creator>JP_Rex</dc:creator>
      <dc:date>2024-11-12T11:17:18Z</dc:date>
    </item>
    <item>
      <title>Re: Anti-Bot response with wrong status code</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Anti-Bot-response-with-wrong-status-code/m-p/235354#M45620</link>
      <description>&lt;P&gt;&lt;STRONG&gt;queue_max_capacity&amp;nbsp; &lt;/STRONG&gt;must be greater than&amp;nbsp; &amp;nbsp;&lt;STRONG&gt;max_flows&lt;/STRONG&gt; in ratio&lt;STRONG&gt; 1:2&amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk182136" target="_blank" rel="noopener"&gt;sk182136 - RAD process unexpectedly exits when a cluster failover or a Security Gateway reboot occurs&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Dec 2024 14:54:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Anti-Bot-response-with-wrong-status-code/m-p/235354#M45620</guid>
      <dc:creator>Itall</dc:creator>
      <dc:date>2024-12-11T14:54:32Z</dc:date>
    </item>
  </channel>
</rss>

