> Source: [sk172647](https://support.checkpoint.com/results/sk/sk172647)

# sk172647 - The action in the Threat Emulation log card for fail-open depends on whether Deep Inspection is "enabled" or "disabled"

| Property | Value |
|----------|-------|
| Solution ID | sk172647 |
| Date Created | 2021-03-22 |
| Last Modified | 2021-07-07 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R81 (EOS) |

## Symptoms

- * The action in the Threat Emulation log card for fail-open depends on whether Deep Inspection is "enabled" or "disabled".  
  If the Settings are:  
  * Fail-open for TE
  * `#tecli adv error set file_max_size error`
  * AV+AB are enabled
  * Deep Inspection - **enabled**

  The User receives an ALLOW log from Threat Emulation without a link to the resource.  

  If the Settings are:  
  * Fail-open for TE
  * `#tecli adv error set file_max_size error`
  * AV+AB are enabled
  * Deep Inspection - **disabled**
  The User receives a DETECT log from Threat Emulation without a URL and only with a file name.
* To replicate the issue, you need to download a 140 MB file, or increase (as per [sk93616](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk93616)) the AV cache to 2048, and download a file that exceeds the maximum allowed value for the AV.
* When Anti-Virus Deep Inspection is enabled along with Threat Emulation, the action under the log is "Accept":  
  Example of the Accept log:  
  Action: Accept  
  Service: http (80)  
  Errors: File was not emulated on some of the operating systems. reason: file: File size exceeded the maximum limit (XXX bytes).  
  Product: Threat Emulation  
  Protection Type: HTTP Emulation  
  Verdict: Error
* When Anti-Virus Deep Inspection is disabled and Threat Emulation is enabled, the action under the log is "Detect":  
  Example of the Detect log:  
  Resource: http://you will see a full URL to the file  
  Reason: File exceeded size limit  
  Action: Detect  
  Product: Threat Emulation  
  Verdict: Error

## Solution

This problem was fixed. The fix is included in:

* [Check Point R81.10](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk170416)

Check Point recommends to always upgrade to the most recent version ([Quantum Security Gateway](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doShowproductpage&productTab=downloads&product=435)).

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
