This document describes how to troubleshoot the error "Unscannable Category = Message Error, Unscannable Reason = Archive Error: Exceeded the total size limit of the unarchived files" in a Cisco ESA.
Cisco recommends that you have knowledge of these topics:
This document is not restricted to specific software and hardware versions.
The information in this document was created from devices in a specific lab environment. All devices used in this document started with a cleared (default) configuration. Review the potential impact of any change before applying it in a production network.
When a message with an attachment reaches Advanced Malware Protection (AMP) in the mail processing pipeline, that is, the ESA stage where attachment scanning occurs, ESA attempts to parse the attachment. ESA also checks the message headers for compliance with Request for Comments (RFC) 2045 (RFC 2045). If the message is not fully compliant, ESA still makes a best-effort attempt to parse the attachment.
Next, ESA checks whether the attachment is an archive file. If it is, ESA attempts to unpack it. ESA evaluates multiple factors in order to estimate the uncompressed size and ensure that the archive is valid. ESA also detects suspicious archives, such as highly compressed files.
If no file reputation verdict is available from the cloud reputation lookup, and the file meets the criteria for analysis, ESA quarantines the file and uploads it to the AMP sandbox, that is, the cloud-based file analysis environment.
ESA then opens a connection to the AMP servers, uploads the file, and waits for verdict updates, as shown in the image:

ESA provides a verdict based on these scenarios:
Highly compressed files such as CSV, XML, and TXT can exceed the maximum file size that is hardcoded into ESA. Compression algorithms such as Lempel-Ziv, generate a digital map that counts the number and position of characters within the full document. This process can produce very small archive file sizes.
By contrast, files that contain graphics or formats such as PDF, JPG, and PNG are not compressed in the same way. As a result, they usually remain close to their original file size.
ESA logs an AMP unscannable verdict for a compressed attachment with the reason "Archive Error: Exceeded the total size limit of the unarchived files."
The attachment is a compressed archive that expands beyond the ESA hardcoded limit for the total size of unarchived files. Highly compressible file types (for example, CSV, XML, and TXT) can produce small archives that expand significantly when unpacked, which can trigger an 'Unscannable' verdict.
Use one of these options based on the desired handling: user notification, or containment and review. The verification steps shown help determine which option to use.
In order to confirm the condition, locate the mentioned type of mail log entry.
Example mail log entry:
Info: The attachment could not be scanned. File Name = 'ACTS Chopped ISO 88591 encod_NoSchema.XML.zip', MID = 226, SHA256 = 7efa6154b7519872055cff10a69067dcad88562f708b284a390a9abcf5e99b8f, Unscannable Category = Message Error, Unscannable Reason = Archive Error: Exceeded the total size limit of the unarchived files
Note: Use this option when message delivery must continue but recipients need a clear warning that AMP did not analyze the attachment.

Note: Use this option when the message must be contained for further analysis instead of being delivered to the recipient.
| Revision | Publish Date | Comments |
|---|---|---|
1.0 |
29-Oct-2019
|
Initial Release |