> Source: [sk121835](https://support.checkpoint.com/results/sk/sk121835)

# sk121835 - Application Control does not fail-close when internal error detected

| Property | Value |
|----------|-------|
| Solution ID | sk121835 |
| Date Created | 2017-12-06 |
| Last Modified | 2017-12-13 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |
| OS | Gaia |

## Symptoms

- * Even though "fail-close" is selected under "Application Control \& URL Filtering Settings", the engine performs "fail-open" instead.
* Unable to find APPI property "block_when_no_rad" in GuiDBedit.
* Kernel debug (of APPI and RAD_KERNEL modules) shows:  

  ```
  
  {global} rad_kernel_api_check_service_status: service is down;
  {global} rad_kernel_api_async_get_resource_ex: RAD service is down;
  {policy} [ERROR]: appi_rad_uf_cmi_handler_match_cb_handle_url: rad_kernel_api_async_get_resource() failed, error: service is down;
  {global} rad_kernel_urlf_request_dtor: going to free original url buffer;
  {policy} [ERROR]: appi_rad_uf_cmi_handler_match_cb: appi_rad_uf_cmi_handler_match_cb_handle_url() failed;
  {global} appi_global_policy_get_rad_fail_action: RAD fail action is ACCEPT;
  {connection} appi_rad_uf_cmi_handler_match_cb: perform fail action [Accept];
  ```

## Cause

**The APPI property *block_when_no_rad* does not exist in GuiDBedit for R80.**

The Check Point Online Web Service is used by the URL Filtering engine for updated website categorization and by the Application Control engine for updated Widget definitions.

The responses the Security Gateway gets are cached locally to optimize performance. When the '*block requests when the web service is unavailable* ' checkbox is **not**selected, requests are allowed, when there is no connectivity to the Check Point Online Web Service (this is the default setting).

## Solution

Navigate to: 'Manage \& Settings \> Blades \> Application and URL Filtering \> Advanced Settings \> Check Point online web service':

* Select the checkbox "*Block requests when the web service is unavailable*"

[![](https://sc1.checkpoint.com/sc//SolutionsStatics/sk121835/sk1218351712130051.png)](https://skcenter.checkpoint.com/skcenter//SolutionsStatics/sk121835/sk1218351712130051.png)

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
