- Products
- Learn
- Local User Groups
- Partners
- More
Quantum Spark Management Unleashed!
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
SharePoint CVEs and More!
Since the update of the Anti-Malware Engine, we have had massive problems with various programs. In some cases, .exe files that previously worked without any problems are moved to quarantine. However, this does not affect all clients. The exceptions that we define do not have the desired effect.
Do any of you have the same effects or possible recommended settings?
After Update to client version 88.50, the issue seems to be resolved now !
Have you opened an SR# with CP TAC already ? If exceptions do not work this should be the first step.
Yes, I have opened a case, but the first recommandation was to deactivate the security settings at the policy.
Did TAC come up with something usefull ? Our TAC case seems to run silently nowhere - also, they did not confirm that it is a known issue...
No, currently not.
After Update to client version 88.50, the issue seems to be resolved now !
Hello,
I have a question: we have problems with memory consumption on two servers (a SQL database and a file server). Both servers have 88.32 and the antimalware blade only has one.
Is it possible to disable the antimalware blade and enable forensics to improve memory consumption?
I saw someone mention they had issue with forensic service confuming high CPU, but yes, I would definitely contact TAC about the issue.
Sorry, but this is off topic - the issue is with non-Kaspersky AV/AM engine, not forensics....
Not really off topic, as issue happened AFTER update to DHS compliant version...
You did not write that...
Haha...never mind mate, I was more referring to an issue with DHS compliant version.
Cheers,
Andy
Forensics is the reason for 80% of our customers EPS tickets with CP...
My colleague was telling me it happened with only 3 users so far out of 300+, so its not that bad at all, thats 1%.
If you look at under "Logs" tab for the forensic log entries for these detections, what is in the "Protection Type" field?
Want to confirm specifically what is making the detections
For one application I see URL Reputation - Forensics. However, the log message goes on to say which applications have been moved to quarantine.
No log entries are created for other applications although the program freezes and crashes.
One of our partners customer also is experiencing this issue - RDS server after upgrade to DoC compliant version E88.32 has EPS client crashing 32 times in 2 days !SR# is open with TAC now.
Ouch...mind sharing exact reason for the crash? MY colleague told me one of our customers also has same problem on few machines, but I did not inquire further.
Andy
The update did it - worked OK before. First solution attempt from TAC is to completely uninstall and re-install the client...
Thats usually first step, sometimes it does work...
@G_W_Albrecht does uninstall and reinstall solved the problems ? We are facing more and more problems with other customers after changing to DoC compliant version.
I will ask one of my colleagues about it as well.
Andy
I would appreciate if someone tries that ! The RDS with the issue is in production and has over 60 users, so any change is only hard to do and has to be allowed by the customer. I would appreciate if this could be replicated by CP in Lab ! Last solution attempt was to update BIOS and all driver on the server, which is hard to do in a Hyper-V VM 8) So i have now escalated the case.
We are still seeing issues with our RDS servers, even on E88.60. We are using FSLogix in our environment so maybe it has something to do with that.
I'm actually getting really fed up with the Harmony endpoint protection software as a whole...
After Update to client version 88.50, the issue seems to be resolved !
Im upgrading a fleet of roughly 600 endpoints tomorrow, now i'm panicking reading this thread.
Would the recommendation be to go directly to 88.50?
Yes, CP gave the recommendation to use this version as the process crashing issue is resolved here.
Is this for older installations which were then upgraded to E2 or new ones also?
We have a few implementations with EPMaaS which were set from the beginning to EU/DHS compliant in the initial setup, running the recommended version and no big issues reported so far. The difference we see is the "DHS Compliant" label next the version, in the drop-down when choosing the version in the deployment options.
Hello,
You should absolutly manage this upgrade very carefully. We had many problems after upgrade to E88.32 and many SR's with TAC without progress. I would recommend you test E88.50 or E88.60 in a few machines for some days, and after you are sure it works ok do the massive change. We did that but only with IT machines and was not enough, normal users had different problems, so if you can, include machines from different areas on the test stage.
Regards
Thanks All,
I had a few POC machines in 88.32 which didnt have complaints.
I did the massive upgrade to 88.50 and no complaints either! (for now :D)
So all looks good so far.
Thanks all
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
4 | |
4 | |
3 | |
1 | |
1 | |
1 | |
1 | |
1 |
Tue 16 Sep 2025 @ 02:00 PM (EDT)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - AmericasWed 17 Sep 2025 @ 04:00 PM (AEST)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - APACWed 17 Sep 2025 @ 03:00 PM (CEST)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - EMEAThu 18 Sep 2025 @ 03:00 PM (CEST)
Bridge the Unmanaged Device Gap with Enterprise Browser - EMEAThu 18 Sep 2025 @ 02:00 PM (EDT)
Bridge the Unmanaged Device Gap with Enterprise Browser - AmericasTue 16 Sep 2025 @ 02:00 PM (EDT)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - AmericasWed 17 Sep 2025 @ 04:00 PM (AEST)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - APACWed 17 Sep 2025 @ 03:00 PM (CEST)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - EMEAThu 18 Sep 2025 @ 03:00 PM (CEST)
Bridge the Unmanaged Device Gap with Enterprise Browser - EMEAThu 18 Sep 2025 @ 02:00 PM (EDT)
Bridge the Unmanaged Device Gap with Enterprise Browser - AmericasAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY