sk183512 - Threat Extraction Software Blade may inadvertently delete some system files

Threat Extraction Software Blade may inadvertently delete some system files

Product

Threat Extraction

Version

R80.30 (EOS), R80.30SP (EOS), R80.40 (EOS), R81 (EOS), R81.10 (EOS), R81.20, R82

OS

Gaia

Last Modified

2025-09-14

Symptoms

Solution

This problem was fixed. The fix is included in:

If you choose not to upgrade, there are two possible options:

Hotfixes:

Version Hotfix Prerequisite
R82 (TAR) R82 Jumbo Hotfix Accumulator, Take 12
R81.20 (TAR) R81.20 Jumbo Hotfix Accumulator, Take 99
R81.10 (TAR) R81.10 Jumbo Hotfix Accumulator, Take 174
R81 (TAR) R81 Jumbo Hotfix Accumulator, Take 107

Notes:

  1. Make sure the IPS Software Blade is enabled:
    1. On the left panel, click Gateways & Servers.
    2. Double-click the Security Gateway / Cluster object.
    3. On the General Properties page, click the Threat Prevention tab.
    4. If in the left section, you selected Custom Threat Prevention:
      1. In the right section select the IPS Software Blade.
      2. In the IPS First Time Activation window, select According to the Threat Prevention policy and click OK.
    5. Click OK to close the Security Gateway / Cluster object.
  2. Make sure the Custom Threat Prevention policy for this Security Gateway / Cluster uses one of the default Threat Prevention profiles: Note - Follow this step if in the Security Gateway / Cluster object > on the General Properties page > on the Threat Prevention tab > in the left section, you selected Custom Threat Prevention. The Autonomous Threat Prevention policy uses the required IPS settings.
    1. On the left panel, click Security Policies.
    2. In the Threat Prevention section, click Custom Policy.
    3. Refer to the Action column in each rule. Make sure this column shows one of these default Threat Prevention profiles:
      • Basic
      • Optimized (recommended)
      • Strict

To select one of the default Threat Prevention profiles in a rule:

  1. Right-click the Action column in the rule.
  2. Select one of the default Threat Prevention profiles.
  3. Install the Threat Prevention policy.

NOTE

This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.

Article Properties

Access Level: General
Status: Approved by TAC
Date Created: 2025-05-29
Last Modified: 2025-09-14