> Source: [sk183425](https://support.checkpoint.com/results/sk/sk183425)

# sk183425 - Threat Emulation fails to process large files (>100MB) and blocks them despite fail-open configuration on Quantum Security Gateways 

| Property | Value |
|----------|-------|
| Solution ID | sk183425 |
| Date Created | 2025-05-05 |
| Last Modified | 2025-05-11 |
| Technical Level | Advanced |
| Products | Security Gateway, Security Management Server |
| Versions | R82, R81.20, R82, R81.20 |

## Symptoms

- * Threat Emulation completes file analysis but does not reply to the sender, resulting in a timeout.

* The sender receives this error message:   

  "`Virus detection was not performed due to communication problem."`

* Some files are delivered to the sandbox for analysis, but are either blocked or not scanned.

* There are inconsistent responses between appliances. For example:   

  * One appliance returns: "`204 Not Modified`" (file allowed)
  * Another appliance returns: "`403 Forbidden`" (file blocked)
  * The issue commonly occurs with large archive files, especially when extracted files exceed 100MB.

  * Threat Emulation is configured to operate in fail-open mode, but files above a certain size are still blocked.

## Cause

Threat Emulation has a hard-coded maximum file size limit of 100MB for local emulation. When an archive contains extracted files which are larger than this size, Threat Emulation cannot process them and does not reply to the sender. This results in a timeout and the file being blocked.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
