Skip to main content
akawade
Staff
Staff
September 22, 2020

Technical Tip: System event as 'Scanunit failed due to internal error: Content decode failed'

  • September 22, 2020
  • 0 replies
  • 5919 views

Description


This article provides information on particular system events which can be seen.

 

Scope

 

FortiGate.

Solution


If the AV profile is applied in policy there can be some random websites which can be blocked and below system event can be observed for the traffic:

'Scanunit failed due to internal error: Content decode failed'

The error can be due to the HTTP inspection enabled in the AV profile.
There can be some web-traffic which use some random port instead of port 80 only, so the traffic is blocked which uses that port when HTTP enabled.

To avoid this the HTTP have to be disabled in AV profile.
Run the below command in AV profile which has been applied in policy:

 

config antivirus profile
    edit <antivirus profile name>
config http
    set av-optimize disable
end

 

  •  Monitor the web-traffic and re-check the system event. The failed error is resolved.
  • Apart from this, check the AV engine with the below command and make sure that the unit has AV engine later to v6.130. Upgrade the AV engine, if required.

 

diag autoupdate versions

 

  • It was the known behavior/bug which is resolved in v6.2.2. If the FortiGate firmware version is below v6.2.2, plan to upgrade the unit to 6.2.2 or later.

Note:

The option 'set av-optimize' has been removed from v6.2.2 CLI and above:
Configure AntiVirus profiles
Configure AntiVirus profiles

Configure AntiVirus profiles

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!