- CheckMates
- :
- Products
- :
- Quantum
- :
- Threat Prevention
- :
- Re: Global Policy Exceptions
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Global Policy Exceptions
Any idea... How can I add exception for this ? I don't want to bypass the full Antivirus blade for this source.
There is not much information in the log .. Such as MD5 hash, protection name etc.
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
The anti-virus engine is experiencing an internal failure trying to scan that resource, and because the anti-virus blade is set to "fail closed" the resulting action is a Prevent. Creating an exception for that resource will not help since it only changes the final decision rendered (Prevent/Detect/Inactive) but does not stop the scanning of that resource and therefore the internal failure that is occurring. It probably has to do with the scanned resource exceeding the fixed size of the SFT buffer on the firewall, please see the following SK for the fix: sk139292: "Failure-reject: unknown error" in Anti-Virus log, traffic fails
CET (Europe) Timezone Course Scheduled for July 1-2
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi,
You can see the resource name on the upper-right corner. You can add an exception for that.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Use the URL under resource in the top right.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks ...
Do you mean I can add domain (.easel.inventable.com) in the exception ?
If yes, I tried to add global exception but could not find Url based domain in the destination field. Only Ip and subnets is the option.
Thanks,
Amir
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Antivirus blade still catches it. Not sure why .
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
The anti-virus engine is experiencing an internal failure trying to scan that resource, and because the anti-virus blade is set to "fail closed" the resulting action is a Prevent. Creating an exception for that resource will not help since it only changes the final decision rendered (Prevent/Detect/Inactive) but does not stop the scanning of that resource and therefore the internal failure that is occurring. It probably has to do with the scanned resource exceeding the fixed size of the SFT buffer on the firewall, please see the following SK for the fix: sk139292: "Failure-reject: unknown error" in Anti-Virus log, traffic fails
CET (Europe) Timezone Course Scheduled for July 1-2
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thank you for your Help.
Yes sk139292 did work .
# fw ctl set int g_ci_av_sft_classification_buffer_size 15000
Ciao
