> Source: [sk183808](https://support.checkpoint.com/results/sk/sk183808)

# sk183808 - Threat Emulation Fails to Reply or Blocks Files Larger Than 100MB

| Property | Value |
|----------|-------|
| Solution ID | sk183808 |
| Date Created | 2025-08-20 |
| Last Modified | 2025-08-21 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R81.20 |

## Symptoms

- * Threat Emulation appliances sometimes complete file analysis but do not reply to the sender, resulting in timeouts.
* Sender receives an error message: ` Virus detection was not performed due to communication problem`.
* Some files sent to Threat Emulation fail and are blocked.
* Appliances respond inconsistently: One returns ` 204 Not Modified (file allowed)`, another returns ` 403 Forbidden (file blocked)`.
* Files larger than 100MB, especially those extracted from archives, trigger the issue.
* Debug logs show `file size exceeds limit` errors for affected files.

## Cause

The Threat Emulation module enforces a maximum file size limit of 100MB for local emulation. Files exceeding this limit, including those extracted from archives, are not processed, and the sender may not receive any response. Increasing the extracted file size limit in the archive tool does not override this limit. Depending on the appliance configuration, the default behavior is to block or to not reply to the sender, which results in inconsistent appliance responses and sender timeouts.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
