<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Content Awareness R80.10 - Blocked request in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-Awareness-R80-10-Blocked-request/m-p/10329#M58960</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Kyle,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Surely that is not a secure option to turn it to fail-open?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is that the only way of getting around this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 29 Mar 2018 16:44:25 GMT</pubDate>
    <dc:creator>Matt_Parfitt</dc:creator>
    <dc:date>2018-03-29T16:44:25Z</dc:date>
    <item>
      <title>Content Awareness R80.10 - Blocked request</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-Awareness-R80-10-Blocked-request/m-p/10327#M58958</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Content Awareness in R80.10 - A user is trying to download some packages from a program called Unity and some are failing to download. After looking through the logs I repeatedly see a log that is blocking and the reason is 'Blocking request as configured in engine settings of Content Awareness.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Reason 1 - Content Awareness - Error while processing 'Big long string of characters: Failed to extract text.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Reason 2 -&amp;nbsp;&lt;SPAN&gt;Content Awareness - Error while processing 'Big long string of characters: Archive decompression ratio is suspiciously high.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;My question is, where do I edit the Threat Prevention/Access Policy in order to allow this program to download all of it's packages?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks&lt;IMG alt="" class="image-1 jive-image j-img-original" src="/legacyfs/online/checkpoint/64212_Content Awareness 2.PNG" style="height: auto;" /&gt;&lt;IMG alt="" class="image-2 jive-image j-img-original" src="/legacyfs/online/checkpoint/64213_Content Awareness 1.PNG" style="height: auto;" /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Mar 2018 08:36:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-Awareness-R80-10-Blocked-request/m-p/10327#M58958</guid>
      <dc:creator>Matt_Parfitt</dc:creator>
      <dc:date>2018-03-29T08:36:36Z</dc:date>
    </item>
    <item>
      <title>Re: Content Awareness R80.10 - Blocked request</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-Awareness-R80-10-Blocked-request/m-p/10328#M58959</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This traffic is being dropped because the Content Awareness engine is running into an error and you currently have the Fail Mode set to 'Fail Close'.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you need this traffic to go through, you can switch the Fail Mode to 'Fail-Open.'&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/64230_pastedImage_1.png" style="width: 620px; height: 359px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Mar 2018 16:41:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-Awareness-R80-10-Blocked-request/m-p/10328#M58959</guid>
      <dc:creator>Kyle_Danielson</dc:creator>
      <dc:date>2018-03-29T16:41:26Z</dc:date>
    </item>
    <item>
      <title>Re: Content Awareness R80.10 - Blocked request</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-Awareness-R80-10-Blocked-request/m-p/10329#M58960</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Kyle,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Surely that is not a secure option to turn it to fail-open?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is that the only way of getting around this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Mar 2018 16:44:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-Awareness-R80-10-Blocked-request/m-p/10329#M58960</guid>
      <dc:creator>Matt_Parfitt</dc:creator>
      <dc:date>2018-03-29T16:44:25Z</dc:date>
    </item>
    <item>
      <title>Re: Content Awareness R80.10 - Blocked request</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-Awareness-R80-10-Blocked-request/m-p/10330#M58961</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I can definitely understand the caution about the security impact. &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you want to stay in Fail-Close, there is an option to change the Content Awareness settings to avoid these errors. You can see this documented in SK11851.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Take note that changing these is not recommended unless you need to.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Mar 2018 17:03:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-Awareness-R80-10-Blocked-request/m-p/10330#M58961</guid>
      <dc:creator>Kyle_Danielson</dc:creator>
      <dc:date>2018-03-29T17:03:08Z</dc:date>
    </item>
    <item>
      <title>Re: Content Awareness R80.10 - Blocked request</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-Awareness-R80-10-Blocked-request/m-p/10331#M58962</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Kyle, I've put&amp;nbsp;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;SK11851 into Google and CheckPoint site and nothing comes up? Please could you link me &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 03 Apr 2018 08:35:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-Awareness-R80-10-Blocked-request/m-p/10331#M58962</guid>
      <dc:creator>Matt_Parfitt</dc:creator>
      <dc:date>2018-04-03T08:35:07Z</dc:date>
    </item>
    <item>
      <title>Re: Content Awareness R80.10 - Blocked request</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-Awareness-R80-10-Blocked-request/m-p/10332#M58963</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Looks like I missed a digit -- &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk118516"&gt;sk118516&lt;/A&gt;.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 03 Apr 2018 13:27:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-Awareness-R80-10-Blocked-request/m-p/10332#M58963</guid>
      <dc:creator>Kyle_Danielson</dc:creator>
      <dc:date>2018-04-03T13:27:03Z</dc:date>
    </item>
    <item>
      <title>Re: Content Awareness R80.10 - Blocked request</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-Awareness-R80-10-Blocked-request/m-p/10333#M58964</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thank you!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 03 Apr 2018 13:46:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-Awareness-R80-10-Blocked-request/m-p/10333#M58964</guid>
      <dc:creator>Matt_Parfitt</dc:creator>
      <dc:date>2018-04-03T13:46:01Z</dc:date>
    </item>
    <item>
      <title>Re: Content Awareness R80.10 - Blocked request</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-Awareness-R80-10-Blocked-request/m-p/10334#M58965</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So my current value for&amp;nbsp;&lt;EM style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;# fw ctl set int fileapp_max_upload_file_size &lt;/EM&gt;is 0, surely that can't be right if the default value is 10mb?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I want to set this as 200mb for example, would I just enter&amp;nbsp;&lt;EM style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;# fw ctl set int fileapp_max_upload_file_size &amp;lt;200&amp;gt; ?&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;&amp;nbsp;&lt;/EM&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Apr 2018 16:31:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-Awareness-R80-10-Blocked-request/m-p/10334#M58965</guid>
      <dc:creator>Matt_Parfitt</dc:creator>
      <dc:date>2018-04-10T16:31:51Z</dc:date>
    </item>
    <item>
      <title>Re: Content Awareness R80.10 - Blocked request</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-Awareness-R80-10-Blocked-request/m-p/10335#M58966</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm going back and forth to our vendor, then to CheckPoint support and then back. I'm debating whether to turn on fail-open as this is just using up too much of my time and stopping a lot of users from uploading &amp;amp; downloading files. It seems there's some sort of limit at 200mb, although when running&amp;nbsp;fw ctl get int fileapp_max_upload_file_size it&amp;nbsp; = 0.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When in fail-open, if the gateway is unable to extract text does it still get analysed by all the other blades for malicious content?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Apr 2018 15:30:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-Awareness-R80-10-Blocked-request/m-p/10335#M58966</guid>
      <dc:creator>Matt_Parfitt</dc:creator>
      <dc:date>2018-04-18T15:30:51Z</dc:date>
    </item>
    <item>
      <title>Re: Content Awareness R80.10 - Blocked request</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-Awareness-R80-10-Blocked-request/m-p/111903#M58967</link>
      <description>&lt;P&gt;Hello &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/208"&gt;@Kyle_Danielson&lt;/a&gt;, thanks for your help and brief explanation, I just made this change and looks like it's working, but can you explain what are the differences between fail-open and fail-close options? Does it mean if there is an error with the content awareness system, it will "bypass" traffic and won't inspect it through content awareness?&lt;/P&gt;</description>
      <pubDate>Fri, 26 Feb 2021 14:00:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-Awareness-R80-10-Blocked-request/m-p/111903#M58967</guid>
      <dc:creator>s-quintanilla</dc:creator>
      <dc:date>2021-02-26T14:00:56Z</dc:date>
    </item>
    <item>
      <title>Re: Content Awareness R80.10 - Blocked request</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-Awareness-R80-10-Blocked-request/m-p/198250#M58968</link>
      <description>&lt;P&gt;I am having a similar issue, but in this case, our mode is set to fail-open.&lt;/P&gt;&lt;DIV class=""&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="contAwareness1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23284iBB660687119591C2/image-size/medium?v=v2&amp;amp;px=400" role="button" title="contAwareness1.png" alt="contAwareness1.png" /&gt;&lt;/span&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;Any advice?&lt;/DIV&gt;</description>
      <pubDate>Fri, 17 Nov 2023 09:43:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-Awareness-R80-10-Blocked-request/m-p/198250#M58968</guid>
      <dc:creator>bmartins-EUDA</dc:creator>
      <dc:date>2023-11-17T09:43:47Z</dc:date>
    </item>
    <item>
      <title>Re: Content Awareness R80.10 - Blocked request</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-Awareness-R80-10-Blocked-request/m-p/198435#M58969</link>
      <description>&lt;P&gt;That's a different problem that has a solution:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk167173" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk167173&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Nov 2023 22:23:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-Awareness-R80-10-Blocked-request/m-p/198435#M58969</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-11-20T22:23:55Z</dc:date>
    </item>
  </channel>
</rss>

