- Products
- Learn
- Local User Groups
- Partners
- More
Firewall Uptime, Reimagined
How AIOps Simplifies Operations and Prevents Outages
Introduction to Lakera:
Securing the AI Frontier!
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
SharePoint CVEs and More!
An event occurred in which an error log in threat emulation was output and files could not be downloaded or uploaded.
Emulation is running on ThreatCloud.
In the log, the reason for the error is explained as follows
Reason:Timeout was exceeded
I think one of the causes is that the emulation connnection handling mode of Threat Emulation is set to Maximum Prevention in the Profile setting of the Threat Prevention Policy.
Do you know the main cause?
Would you mind please send what you have configured under settings in smart console (last tab on the left menu) for that blade? I will send screenshot in a bit.
Andy
@the_rock
Thank you for your response.
Here is the Screenshot. It is default.
The fail-mode is set to fail-open.
I selected wrong tab, I meant to choose general...is it set to allow?
Andy
@the_rock
Yes Allow all connections Fail-open
In profile, Maximum Prevention is set and the file cannot be downloaded until the file Emulation is complete.
If this setting is set to Rapid Delivery, it improves, but I would like to know the cause of the error.
See if below sk helps.
https://support.checkpoint.com/results/sk/sk114806
If not, I would try change to background option and install policy. If still no improvement, would certainly open TAC case.
Best,
Andy
@the_rock
I know about this SK.
If i set Rapid Delivery will improve this.
The question is why the Timeout was exceeded error occurs.
I have no clue, sorry. Thats why I sugegsted TAC case.
Andy
I am asking here because the TAC says they don't know.
I am asking here because the TAC says they don't know.
When I checked the result of tecli show cloud queue at the time of the event, it showed “Cloud Connectivity Problem” and confirmed that there were many files waiting for emulation (inspection) in the queue.
Does this mean that a connection problem with ThreatCloud caused the timeout?
However, some files could be downloaded and uploaded.
Please let me know what you find out.
------------------------
tecli show cloud queue
------------------------
|file's sha1 |file's event_id |file type |insert time |status
|----------------------------------------|----------------------------------------|----------|------------------|----------------------------------------------------------------------
|pdf |203 Minutes |Cloud Connectivity Problem, waiting to resend.
|pdf |197 Minutes |Cloud Connectivity Problem, waiting to resend.
|pdf |96 Minutes |Cloud Connectivity Problem, waiting to resend.
|pdf |94 Minutes |Cloud Connectivity Problem, waiting to resend.
|pdf |88 Minutes |Cloud Connectivity Problem, waiting to resend.
|pdf |85 Minutes |Cloud Connectivity Problem, waiting to resend.
|pdf |82 Minutes |Cloud Connectivity Problem, waiting to resend.
|pdf |81 Minutes |Cloud Connectivity Problem, waiting to resend.
|pdf |77 Minutes |Cloud Connectivity Problem, waiting to resend.
|pdf |75 Minutes |Cloud Connectivity Problem, waiting to resend.
|pdf |16 Minutes |Cloud Connectivity Problem, waiting to resend.
|pdf |7 Minutes |Cloud Connectivity Problem, waiting to resend.
|pdf |205 Minutes |Uploading to Cloud (resend).
Hm, thats what it seems like, possibkly connectivity issue to threat cloud...why would that heppen, that Im really not sure. Lets see if someone else may have an idea.
Any other relevant logs that you can send that might be bit more helpful?
Andy
@the_rock
I can't share the details because it is a customer's log, but the Firewall log also recorded an error with File exceeded size limit. However, we verified that if the following settings are set to 15MB and fail-open, files exceeding the size limit can be downloaded.
SmartConsole > Manage & Settings > Blades > Threat Prevention > Advanced Settings >
Threat Emulation > Emulation Limits > Maximum file size for emulation
The maximum processing time in queue is 720 minutes, so I don't think it will be a Fail-open download, but if the error is Timeout was exceeded due to a connection problem with ThreatCloud, why can't the file be downloaded in Fail-open?
Well, here is the way I look at it. If you are saying TAC could not help, the more we get here, better chances we can try solve it. I get you might not be allowed to send certain things, but if you blur out any sensitive data from the log entry, that would help big time.
Best,
Andy
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
17 | |
12 | |
12 | |
11 | |
11 | |
7 | |
7 | |
6 | |
5 | |
5 |
Wed 22 Oct 2025 @ 11:00 AM (EDT)
Firewall Uptime, Reimagined: How AIOps Simplifies Operations and Prevents OutagesTue 28 Oct 2025 @ 11:00 AM (EDT)
Under the Hood: CloudGuard Network Security for Google Cloud Network Security Integration - OverviewAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY