Thank you, Otakar.Klier >If you disable the extended packet capture on the polices that are medium and higher, these warning will go away. It works. But i don't understand something. In the document that I quoted, reset-both is recommended, not block. Security Policy with these profiles allows traffic. For example: Warning: The action is block for rule "simple-critical" in anti-spyware profile "Best-practice and sinkhole" with extended packet capture enabled. Only the first packet will be captured. Action is not block, but reset-both. Settings are made according to the manual. 1. Warning should be expected when Commit? 2. Error in the document or mismatch of versions (8.0, not 8.1), restriction for VM-versions? 3. Do I actually need extended packet capture?
... View more