- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi all
I'm having issues with the TE blade. Despite I have the activation mode for some traffic in "prevent" by all cases, I see some logs with the "detect" action.
I already tried the suggested in sk106119 and sk106251, without success.
Before I talk to my local partner or open a SR I was wondering if could be some wierd incompatibility between the R80 mgmt and R77.30 gw?
Thanks lads
This is the answer I got:
From logs it looks like it is a known malware so it is likely that it was also dropped by AV.
The way that it works is that while TE is emulating other blades might decide to drop the connection. By the time TE is setting the connection to drop it is no longer in the table and the blade does not know if the connection was dropped or not so it produces a detect log.
In the second time the file is in the cache so it is prevented at roughly the same time it is prevented in AV so there is no discrepancy in the logs.
Can you check if this makes sense in your environment?
Hi Santiago,
I am not aware of such an issue.
Can you send a screen shot of this log.
Thanks,
Amir
Hi Amir,
I attached two logs, close both in time, with the same malicious file detected, one with detect action and other with prevent one


Thanks!
This is the answer I got:
From logs it looks like it is a known malware so it is likely that it was also dropped by AV.
The way that it works is that while TE is emulating other blades might decide to drop the connection. By the time TE is setting the connection to drop it is no longer in the table and the blade does not know if the connection was dropped or not so it produces a detect log.
In the second time the file is in the cache so it is prevented at roughly the same time it is prevented in AV so there is no discrepancy in the logs.
Can you check if this makes sense in your environment?
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 16 | |
| 15 | |
| 7 | |
| 5 | |
| 5 | |
| 5 | |
| 4 | |
| 4 | |
| 4 | |
| 4 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY