> Source: [sk117312](https://support.checkpoint.com/results/sk/sk117312)

# sk117312 - Security Gateway configured as MTA does not forward e-mails  that contain attachments in TNEF format, or forwards them very slowly

| Property | Value |
|----------|-------|
| Solution ID | sk117312 |
| Date Created | 2017-05-11 |
| Last Modified | 2017-11-13 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |
| OS | Gaia |

## Symptoms

- * Security Gateway configured as MTA does not forward e-mails that contain attachments in TNEF format, or forwards them very slowly.

* Output of '`top`' / '`ps auxw`' / '`vmstat 1`' commands on Security Gateway show high utilization of RAM and hard disk.

* *$FWDIR/tmp/email_tmp/* directory and */tmp/scrub/* directory on Security Gateway contain large number of temporary files.

* MTA debug (according to [sk109699](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk109699)) shows:

  `
  [emaild.mta PID]@HostName[DATE TIME] email_policy_scrub_replace_part: running AM_attachment_replace (attachment_id = winmail.dat, scrubbed_disk_file = /opt/CPsuite-R77/fw1/tmp/email_tmp/emailtemp-XXX._tnef_dst)`  
  `
  [emaild.mta PID]@HostName[DATE TIME] mime_alter.c:4344:AM_replace_attachment: attachmentname before magic: (null)`  
  ` 
  [emaild.mta PID]@HostName[DATE TIME] mime_alter.c:4357:AM_replace_attachment: magic not given
  `
* After enabling generation of core dump files per [sk92764](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk92764), core dump files for '*in.emaild.mta* ' process were generated in the */var/log/dump/usermode/* directory.

## Cause

The MTA process *in.emaild.mta* crashes when Threat Extraction blade is enabled and e-mail with an attachment in the [TNEF (Transport Neutral Encapsulation Format)](https://en.wikipedia.org/wiki/Transport_Neutral_Encapsulation_Format) format is being cleaned/converted.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
