> Source: [sk169156](https://support.checkpoint.com/results/sk/sk169156)

# sk169156 - Many "Strict hold is not possible failure - Write to other side occurred" detect logs in SmartLog

| Property | Value |
|----------|-------|
| Solution ID | sk169156 |
| Date Created | 2020-09-14 |
| Last Modified | 2025-08-21 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |

## Symptoms

- * Many `"Strict hold is not possible failure - Write to other side occured"` detect logs are seen in SmartLog.

* In some scenarios: the strict hold message is a prevent log as below:

  ![](https://sc1.checkpoint.com/sc//SolutionsStatics/sk169156/holdfailure202009141256021.png)
* Running Anti-Virus debug show the following:  

  `
  @;229189;[cpu_3];[fw4_1];1560261444:{module} [SID: 02173] ws_module_get_session_attribs: Entered with _attribs = 4503599627370496;`  
  `
  @;229189;[cpu_3];[fw4_1];1560261444:{av} [VSID: 00000] ci_av_handler_is_skip_possible_on_header_stage: write to other side occured - skip is not possible; `  
  `
  @;229189;[cpu_3];[fw4_1];1560261444:{av} [VSID: 00000] ci_av_handler_perform_fail_mode: fail close: 1; `  
  `
  @;229189;[cpu_3];[fw4_1];1560261444:{session} [SID: 02173] ws_http_session_ext_log_header_get_ex: getting header X-Forwarded-For; `  
  `
  @;229189;[cpu_3];[fw4_1];1560261444:{session} [SID: 02173] ws_http_session_ext_log_header_get_ex: getting header user-agent; `  
  `
  @;229189;[cpu_3];[fw4_1];1560261444:{session} [SID: 02173] ws_http_session_get_extended_log: x-forwarded-for: //\\IP//\\; `  
  `
  @;229189;[cpu_3];[fw4_1];1560261444:{session} [SID: 02173] ws_http_session_get_extended_log: user_agent: ; `  
  `
  @;229189;[cpu_3];[fw4_1];1560261444:{session} [SID: 02173] ws_http_session_get_extended_log: server: ;`  
  `
  @;229189;[cpu_3];[fw4_1];1560261444:{session} [SID: 02173] ws_http_session_get_abs_url: _session->abs_url_offset = 30 _session->abs_url_buf_size = 78; `  
  `
  @;229189;[cpu_3];[fw4_1];1560261444:{session} [SID: 02173] ws_http_session_get_abs_url: *_abs_url_buf_size = 50 - 30 + 27 + 1 = 48; `  
  `
  @;229189;[cpu_3];[fw4_1];1560261444:{module} [SID: 02173] ws_module_get_log_attribs: url recived is ://\\ URL //\\; `  
  `
  @;229189;[cpu_3];[fw4_1];1560261444:{module} [SID: 02173] ws_module_add_http_log: adding the error log relevant fields; `  
  `
  @;229189;[cpu_3];[fw4_1];1560261444:{module} [SID: 02173] ws_module_add_http_log: [WARNING]: no precise error message was found; `  
  `
  @;229189;[cpu_3];[fw4_1];1560261444:{session} [VSID: 00000] ci_session_data_av_get_active_skip_flag: strict_hold_session is NULL.; `  
  `
  `

## Cause

The "Strict Hold" mode fails as there were bytes written to the client and therefore connection can not be skipped anymore (skip means nothing is written to the client until the whole file is enforced).

## Solution

This problem was fixed. The fix is included in:

* [Check Point R80.40](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk160736)

Check Point recommends to always upgrade to the most recent version   
([upgrade Security Gateway](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doShowproductpage&productTab=overview&product=435) / [upgrade Security Management Server](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doShowproductpage&productTab=overview&product=184) / [upgrade Multi-Domain Security Management](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doShowproductpage&productTab=overview&product=166)).

Workaround - If **not** using Threat Extraction over HTTP, you can follow [sk183840](https://support.checkpoint.com/results/sk/sk183840) to configure "`strict_hold_enable=0`" in the `$FWDIR/conf/malware_config` file.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
