Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
NorthernNetGuy
Advisor

Large File download emulation responses

With the 100mb file limit on file emulation, we're left with fail open or fail close for anything that exceeds that.

So if a file is larger than the limit, and it's fail open, we're essentially assuming the file is safe in fail-open?

Fail close would lead to tickets where users may need to download larger files. Manual emulation would need to be performed to investigate the file further, which isn't very scalable. 

 

I want to know how others handle this policy, and what systems you may have in place for dealing with large file downloads.

0 Kudos
1 Reply
Lesley
MVP Gold
MVP Gold

I think it is best to block large files. That is the best for security. If you going to scan large files the performance is also impacted on the firewall. Note there is also cache on the gateway so same files should not go again via scanning. 

I think 100mb is still the limit for this blade: https://support.checkpoint.com/results/sk/sk183425

 

-------
Please press "Accept as Solution" if my post solved it 🙂
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    Tue 02 Jun 2026 @ 09:00 AM (CEST)

    CheckMates Live Denmark - Aarhus

    Wed 03 Jun 2026 @ 09:00 AM (CEST)

    CheckMates Live Denmark - Copenhagen

    Fri 12 Jun 2026 @ 09:00 AM (CEST)

    Netzwerk- & Cloud-Workshop: Wien
    CheckMates Events