> Source: [sk97972](https://support.checkpoint.com/results/sk/sk97972)

# sk97972 - Sudden reboots of Security Gateways when Anti-Bot blade is enabled

| Property | Value |
|----------|-------|
| Solution ID | sk97972 |
| Date Created | 2013-12-31 |
| Last Modified | 2015-07-16 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |
| OS | Gaia |

## Symptoms

- * Sudden reboot/freeze of Security Gateways when Anti-Bot is enabled.  

* In ClusterXL, both members are rebooting at the same time every half hour.

## Cause

Problems with Anti-Bot signatures might cause this issue.

## Solution

**Note:** A new signatures update has been released. Therefore, if the Security Gateway stops rebooting it has fetched the new update and no other action is required.

Otherwise follow the procedure below:

1. ***Preferred option:***

   1. SmartDashboard - go to '*Anti-Bot \& Anti-Virus* ' tab (in R77 and above, '*Threat Prevention* ' tab) - click on 'Protections'.   
      Disable the following protections on all profiles:

      **Malicious Activity**

      ![Malicious Activity](https://sc1.checkpoint.com/sc/SolutionsStatics/sk97972/AB1.png "Malicious Activity")

      **Unusual Activity**

      ![Unusual Activity](https://sc1.checkpoint.com/sc/SolutionsStatics/sk97972/Ab2.png "Unusual Activity")

      <br />

   2. Perform Anti-Bot \& Anti-Virus (on R77 - Threat Prevention) policy installation.

      ![policy installation](https://sc1.checkpoint.com/sc/SolutionsStatics/sk97972/AB3.png "policy installation")   

   3. After 24 hours, re-enable the protections by using the "*Restore All to profiles settings* " option.   

   4. Install 'Anti-Bot \& Anti-Virus' policy (on R77 and above, 'Threat Prevention' policy).

   <br />

   <br />

   <br />

   <br />

2. ***Alternative option:* If policy installation is not possible due to frequent reboots, follow the below process:**

   * For Security Gateway:

     * If you can connect to Security Gateway over SSH:

       1. Connect to the Security Gateway over SSH.   

       2. Log in to Expert mode.   

       3. Unload the Anti-Malware policy:

          ***\[Expert@HostName\]# fw amw unload***   

       4. Empty the *$FWDIR/amw/update/cur/malware.eng* file:

          ***\[Expert@HostName\]# echo "" \> $FWDIR/amw/update/cur/malware.eng***   

       5. Reload the Anti-Malware policy:

          ***\[Expert@HostName\]# fw amw fetch local***

       <br />

       <br />

     * If you can connect to Security Gateway only over serial console:

       1. Connect to the Security Gateway over serial console.   

       2. Log in to Expert mode.   

       3. Reboot the Security Gateway - go into Boot Menu - select "Maintenance mode".   

       4. Enter the Expert mode password.   

       5. Empty the *$FWDIR/amw/update/cur/malware.eng* file:

          ***\[Expert@HostName\]# echo "" \> $FWDIR/amw/update/cur/malware.eng***   

       6. Reboot the Security Gateway - go into Boot Menu - select "Normal mode".

     <br />

     <br />

   * **For VSX Gateway:**

     Connect to the VSX Gateway over SSH, or serial console and log in to Expert mode.

     For ***each*** Virtual System:
     1. Switch to the context of the Virtual System:

        ***\[Expert@HostName:0\]# vsenv \<VSID\>***   

     2. Unload the Anti-Malware policy:

        ***\[Expert@HostName:\<VSID\>\]# fw amw unload***   

     3. Empty the *$FWDIR/amw/update/cur/malware.eng* file:

        ***\[Expert@HostName:\<VSID\>\]# echo "" \> $FWDIR/amw/update/cur/malware.eng***   

     4. Reload the Anti-Malware policy:

        ***\[Expert@HostName:\<VSID\>\]# fw amw fetch local***

     <br />

     5. Reboot.

   No additional action is required. After performing the above procedure, the gateway will fetch the latest package automatically.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
