Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Forsaken_61
Explorer

Threat Prevention API - not reaching 100MB

Hi,

 

I'm having some issues emulating files on "on-prem" Threat Emulation boxes. The files are being sent with the API to security gateways that then forward the files to "Remote Emulation Appliances" were the emulation Is taking part.

 

When I send files that exceeds 90MB that API method doesn't work. When I run "tecli show remote queue" on the Security gateway the file get's stuck there, It's like the file cannot be handled over the Threat Emulation Boxes. I can  see the:
- file's SHA1
- file's event_id
- insert_time
- status

The status shows Cloud Connectivity Problem, waiting to resend. Which Is weird. According to all my policies the emulation Is done ON-PREM. And If files cannot be emulated we've rejected the option to send these to the cloud.


The logs In my Smart Console says "Private Threat Cloud Appliance has failed to emulate X amount of times". 


The workflow with the API works fine with files under 90MB. But with files over 90MB I'm getting issues.

 

The Threat Prevention API should support files up to 100MB, therefore I'm wondering why I'm not reaching these levels. 

0 Kudos
7 Replies
Chris_Atkinson
Employee Employee
Employee

How do your settings compare with those outlined in sk137032 for increasing this limit?

 

CCSM R77/R80/ELITE
0 Kudos
Forsaken_61
Explorer

Thanks for your reply. Yes It's been a while since I changed config on those files.

Should I change all that on the my Threat Emulation boxes aswell? Or should It just be done on my Security Gateway?

 

Thanks

0 Kudos
the_rock
Legend
Legend

Good question, maybe better to verify with TAC, though sk states security gateway in the instructions.

Kind regards,

Andy

0 Kudos
PhoneBoy
Admin
Admin

Have you confirmed this is set to the correct limit?
Manage & Settings > Blades Threat Prevention > Threat Emulation > Emulation Limits 

0 Kudos
Forsaken_61
Explorer

@PhoneBoy 
Yes that one is set to 100,000 KB.

0 Kudos
PhoneBoy
Admin
Admin

100000k is not 100mb, it's actually 97.65mb.
Even so, you probably will need the TAC to assist here: https://help.checkpoint.com 

0 Kudos
Forsaken_61
Explorer

You're right. 
Manage & Settings > Blades Threat Prevention > Threat Emulation > Emulation Limits 

Maximum file size for emulation (KB) is 100,000 KB. That's the maximum value. 

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events