> Source: [sk182686](https://support.checkpoint.com/results/sk/sk182686)

# sk182686 - How to block the file download, when there is error "file exceeded size limit" 

| Property | Value |
|----------|-------|
| Solution ID | sk182686 |
| Date Created | 2024-09-16 |
| Last Modified | 2024-09-28 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R81.20, R81.10 (EOS), R81 (EOS) |
| OS | Gaia |
| Platform | TE |

## Symptoms

- No error logs are generated. The issue is only visible in the browser.

## Cause

The default settings can be adjusted to meet your requirements. The file was downloaded due to its size exceeding the configured emulation limit.

## Solution

### Configuring Threat Emulation File Size Limits

To manage threat emulation for file downloads effectively, it is crucial to configure file size limits and fail modes. This ensures optimal security and proper handling of potentially malicious files. This article provides guidance on setting file size limits and managing threat emulation profiles to allow or block file downloads according to your security requirements.  

**Important -** The maximum supported file size for emulation is 100 MB.  

**1. Understanding Threat Emulation File Size Limits**   

Threat emulation analyzes files for potential threats before download. If a file exceeds the configured emulation size limits, the emulation process results in an error. This means:  

* **Verdict -** The emulation verdict is "Error".
* **Action**: The file is not emulated.

Depending on your configuration, the file can either be allowed to download or blocked.  

![](https://sc1.checkpoint.com/sc/SolutionsStatics/NEW_SK_NOID1726478118630/Emulation limits202409161452401.png)  

The handling of this traffic is governed by the **Fail Mode** setting in **Threat Prevention** \> **Advanced Settings** .  

The Fail Mode determines the system's response when a file cannot be emulated due to size limits. You can choose between two modes:  

**Fail Open** : Configure the Fail Mode to "Fail Open" if you want the file to be downloaded even if emulation fails.  
**Fail Close** : Configure the Fail Mode to "Fail Close" if you prefer to block the file when emulation fails.  

**2. Adjusting Profile Settings for Emulation**   

**Maximum Prevention** : Waits for the emulation verdict before deciding whether to download or block the file.  
**Rapid Delivery** : Downloads the file immediately without waiting for the emulation verdict.  

### Steps to Configure Emulation Settings:

1. Access Profile Settings:  
   Navigate to **Profile** \> **Threat Emulation** \> **Advanced**.
2. Set Emulation Connection Handling Mode:  
   Change the **Emulation Connection Handling Mode** to **Maximum Prevention** for a thorough security check, which waits for the verdict before taking action.  
   **Note -** If you use **Rapid Delivery**, the file is downloaded immediately, and the emulation verdict is applied afterward.

![](https://sc1.checkpoint.com/sc/SolutionsStatics/NEW_SK_NOID1726478118630/profile settings202409161503272.jpg)

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
