<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Content Awareness Blade misbehaving (silently blocking/stalling) in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Content-Awareness-Blade-misbehaving-silently-blocking-stalling/m-p/8168#M1003</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We have had some problems recently with aborted FTP transfers and also (unrelated, or so we thought) delayed/stalled HTTP downloads.&lt;/P&gt;&lt;P&gt;On the FTP transfers we found that sometimes we got an alert on the logs, stating "Content Awareness &amp;nbsp;- &amp;nbsp;Error: Internal system error (1000)"&lt;BR /&gt;The Fail Mode for Content Awareness is set to Allow all requests (fail-open) but apparently it interferes with traffic anyway.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The second issue, with stalled HTTP downloads, we at first suspected was due to Threat Emulation.&lt;/P&gt;&lt;P&gt;Files would download almost completely and then stall for 1 to 4 minutes.&lt;/P&gt;&lt;P&gt;However, there were no logs from TE blade indicating these files were uploaded and emulated, nor were there any files stuck in TE queue.&lt;/P&gt;&lt;P&gt;We made exceptions in the policy to disable all Threat Prevention blades for this traffic, but that did not help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But I remembered something from about a year ago with CA doing strange stuff, so we tried disabling it completely, unchecking it on the gateways, not just removing protocols from CA settings.&lt;/P&gt;&lt;P&gt;And lo and behold, downloads started to complete without delay!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Has anyone experienced similar issues?&lt;/P&gt;&lt;P&gt;In the case of HTTP downloads, they would eventually complete and files were correct, but no signs of anything wrong in the logs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We really want to be able to have CA active, to block clients downloading .EXEs etc, but currently we need to have it off.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 28 Feb 2019 14:16:41 GMT</pubDate>
    <dc:creator>Johan_Hillstrom</dc:creator>
    <dc:date>2019-02-28T14:16:41Z</dc:date>
    <item>
      <title>Content Awareness Blade misbehaving (silently blocking/stalling)</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Content-Awareness-Blade-misbehaving-silently-blocking-stalling/m-p/8168#M1003</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We have had some problems recently with aborted FTP transfers and also (unrelated, or so we thought) delayed/stalled HTTP downloads.&lt;/P&gt;&lt;P&gt;On the FTP transfers we found that sometimes we got an alert on the logs, stating "Content Awareness &amp;nbsp;- &amp;nbsp;Error: Internal system error (1000)"&lt;BR /&gt;The Fail Mode for Content Awareness is set to Allow all requests (fail-open) but apparently it interferes with traffic anyway.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The second issue, with stalled HTTP downloads, we at first suspected was due to Threat Emulation.&lt;/P&gt;&lt;P&gt;Files would download almost completely and then stall for 1 to 4 minutes.&lt;/P&gt;&lt;P&gt;However, there were no logs from TE blade indicating these files were uploaded and emulated, nor were there any files stuck in TE queue.&lt;/P&gt;&lt;P&gt;We made exceptions in the policy to disable all Threat Prevention blades for this traffic, but that did not help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But I remembered something from about a year ago with CA doing strange stuff, so we tried disabling it completely, unchecking it on the gateways, not just removing protocols from CA settings.&lt;/P&gt;&lt;P&gt;And lo and behold, downloads started to complete without delay!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Has anyone experienced similar issues?&lt;/P&gt;&lt;P&gt;In the case of HTTP downloads, they would eventually complete and files were correct, but no signs of anything wrong in the logs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We really want to be able to have CA active, to block clients downloading .EXEs etc, but currently we need to have it off.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Feb 2019 14:16:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Content-Awareness-Blade-misbehaving-silently-blocking-stalling/m-p/8168#M1003</guid>
      <dc:creator>Johan_Hillstrom</dc:creator>
      <dc:date>2019-02-28T14:16:41Z</dc:date>
    </item>
    <item>
      <title>Re: Content Awareness Blade misbehaving (silently blocking/stalling)</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Content-Awareness-Blade-misbehaving-silently-blocking-stalling/m-p/8169#M1004</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Did you check your disk space?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Feb 2019 15:50:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Content-Awareness-Blade-misbehaving-silently-blocking-stalling/m-p/8169#M1004</guid>
      <dc:creator>Alessandro_Marr</dc:creator>
      <dc:date>2019-02-28T15:50:29Z</dc:date>
    </item>
    <item>
      <title>Re: Content Awareness Blade misbehaving (silently blocking/stalling)</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Content-Awareness-Blade-misbehaving-silently-blocking-stalling/m-p/8170#M1005</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Johan,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What environment are you working with at the minute? Hardware/software version, hotfix version etc?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Mark&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Feb 2019 15:51:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Content-Awareness-Blade-misbehaving-silently-blocking-stalling/m-p/8170#M1005</guid>
      <dc:creator>Mark_Mitchell</dc:creator>
      <dc:date>2019-02-28T15:51:29Z</dc:date>
    </item>
    <item>
      <title>Re: Content Awareness Blade misbehaving (silently blocking/stalling)</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Content-Awareness-Blade-misbehaving-silently-blocking-stalling/m-p/8171#M1006</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry, I tagged it with R80.20 only.&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are running two clustered 15600 with separate mgmt.&amp;nbsp;&lt;/P&gt;&lt;P&gt;All are latest and greatest R80.20 maintrain, no custom HFs&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Feb 2019 16:48:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Content-Awareness-Blade-misbehaving-silently-blocking-stalling/m-p/8171#M1006</guid>
      <dc:creator>Johan_Hillstrom</dc:creator>
      <dc:date>2019-02-28T16:48:30Z</dc:date>
    </item>
    <item>
      <title>Re: Content Awareness Blade misbehaving (silently blocking/stalling)</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Content-Awareness-Blade-misbehaving-silently-blocking-stalling/m-p/8172#M1007</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, no problems there.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Both GWs and mgmt and SmartLog have plenty of free soace.&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Feb 2019 16:50:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Content-Awareness-Blade-misbehaving-silently-blocking-stalling/m-p/8172#M1007</guid>
      <dc:creator>Johan_Hillstrom</dc:creator>
      <dc:date>2019-02-28T16:50:19Z</dc:date>
    </item>
    <item>
      <title>Re: Content Awareness Blade misbehaving (silently blocking/stalling)</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Content-Awareness-Blade-misbehaving-silently-blocking-stalling/m-p/8173#M1008</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Could you try reenable CA and use a only one rule passing packets just your computer?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Feb 2019 17:20:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Content-Awareness-Blade-misbehaving-silently-blocking-stalling/m-p/8173#M1008</guid>
      <dc:creator>Alessandro_Marr</dc:creator>
      <dc:date>2019-02-28T17:20:13Z</dc:date>
    </item>
    <item>
      <title>Re: Content Awareness Blade misbehaving (silently blocking/stalling)</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Content-Awareness-Blade-misbehaving-silently-blocking-stalling/m-p/8174#M1009</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Johan,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the additional information.&amp;nbsp;I think as you are not seeing anything in the logs that pertains to a reason as to why connections are being terminated (FTP) a debug session is likely needed.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk119715" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk119715"&gt;ATRG: Content Awareness (CTNT)&lt;/A&gt;&amp;nbsp; &amp;lt;- will detail the debug process. However I would would proceed with extreme caution due to the additional load that the debug will put on the box. As per the following statement from the ARTG.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"&lt;STRONG style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;Note:&lt;/STRONG&gt;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;Kernel debug increases load on the Security Gateway's CPU. Schedule a maintenance window during a low traffic time. In cluster environment, this procedure must be performed on&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;EM style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;all&lt;/EM&gt;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;members of the cluster."&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;I have had to run debugs in the past at a time that has low traffic and still managed to max all CPU's at 100%, needless to say things weren't great at this point. &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;Personally I think it would be best getting a TAC case raised as I would not like to advise on running the debug's without knowing the affected environment in detail.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;Regards&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;Mark&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Feb 2019 21:13:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Content-Awareness-Blade-misbehaving-silently-blocking-stalling/m-p/8174#M1009</guid>
      <dc:creator>Mark_Mitchell</dc:creator>
      <dc:date>2019-02-28T21:13:42Z</dc:date>
    </item>
  </channel>
</rss>

