> Source: [sk185284](https://support.checkpoint.com/results/sk/sk185284)

# sk185284 - Threat Emulation mail delays caused by FakeServer TLS parsing errors 

| Property | Value |
|----------|-------|
| Solution ID | sk185284 |
| Date Created | 2026-08-17 |
| Last Modified | 2026-09-07 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |
| OS | Gaia |
| Platform | 15000, 3000, 5000, 7000, 28000, VMWare ESX, Mobile Devices, 16000, 26000, 6000 |

## Symptoms

- * SMTP messages accumulate in the Postfix queue, waiting for Threat Emulation verdicts which are not given. No emulation Virtual Machines (VMs) are reported as running. This message appears:

  "*Adding emulation request ... (\<number\> requests in queue, 0 running emulation VMs)*".
* Restarting TED or requeuing Postfix messages may temporarily restore mail processing.

* *$FWDIR/log/ted.elg\** shows this output:  

  ```
  Exception: Error parser TLS packet
  Internal Communication Error just happened: Unexpected error in fake server
  Terminating VM due to error: Unexpected error in fake server
  Internal virtual sandbox communication error
  ```

* Some environments may also report *resources shortage exist* and *Not_enough_resources*.

## Cause

<br />

Under specific conditions, the Threat Emulation Fake Internet component can incorrectly process TLS traffic generated by a Windows 10 emulation VM.  

<br />

This condition causes the emulation VM to terminate unexpectedly. Repeated VM termination can reduce the number of available emulation VMs to zero. When no emulation VMs are available, Threat Emulation cannot process new requests and keeps them in the queue.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
