> Source: [sk139292](https://support.checkpoint.com/results/sk/sk139292)

# sk139292 - "Failure-reject: unknown error" in Anti-Virus log, traffic fails

| Property | Value |
|----------|-------|
| Solution ID | sk139292 |
| Date Created | 2018-10-31 |
| Last Modified | 2020-07-14 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |
| OS | Gaia |

## Symptoms

- * Anti-Virus Log shows:  

  ![](https://sc1.checkpoint.com/sc//SolutionsStatics/sk139292/Untitled picture1810300640.png)
* Anti-Virus blade engine mode is set to "Fail-Close"; changing it to "Fail-Open" resolves the issue.  

* When the user tries to access some site resources, a blank page or a UserCheck Block Page is displayed.  

* Kernel debug *(fw ctl debug -m CI + all)* shows the following errors:  
  ***ci_filter_av_ft_classify_by_magic: \[ERROR\]: sft_mgr_classify() failed;
  ci_filter_av_ft_pass_ex: \[ERROR\]: sft_mgr_init_classifation() failed;
  ci_av_mgr_inspect: \[ERROR\]: ci_filter_vtable_pass() failed;
  ci_avsi_inspect: \[ERROR\]: ci_av_mgr_inspect() failed;*** Kernel debug *(fw ctl debug -m SFT + all)* shows the following errors:  
  ***{SFT_MGR} sft_opaque_pop_accumulated_data: \[SFT_INFO\] _accumulated_data_length*** *XXXXX**, returning TRUE;
  {SFT_MGR} sft_db_classify: \[SFT_ERROR\] kiss_vbuf_add_buffer() failed;*** Where *XXXXX* represents a value higher than 10,000.  

* Kernel debug (fw ctl debug -m kiss + vbuf) shows the following errors:  
  "kiss_vbuf_add_buffer: given a buffer with size (14000) \> max_chunk_size (10000), not adding it to vbuf;"

## Cause

The kernel parameter that represents the SFT (Stream File Type module) classification buffer for***g_ci_av_sft_classification_buffer_size*** is higher than the allocated buffer for the Security Gateway. The default is 10000.

**Note**: In R80.30, the default value is 16000. It is unlikely, however, that the buffer of the resource (in Anti-Virus) will exceed 16000.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
