<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: UserCheck Block Page Times Out in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/UserCheck-Block-Page-Times-Out/m-p/52930#M12784</link>
    <description>&lt;P&gt;Could this be part of my problem?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Time: 2019-05-08T12:20:44Z&lt;BR /&gt;Id: ac1f6e54-0100-00c0-5cd2-c99c00000011&lt;BR /&gt;Sequencenum: 60&lt;BR /&gt;Protection Name: Non Compliant HTTP&lt;BR /&gt;Severity: Critical&lt;BR /&gt;Confidence Level: Medium&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;Protection ID: BlockHttpNonProtocolCompliant&lt;/STRONG&gt;&lt;/FONT&gt;&lt;BR /&gt;Performance Impact: Low&lt;BR /&gt;&lt;STRONG&gt;&lt;FONT color="#FF0000"&gt;Protection Type: Protocol Anomaly HTTP&lt;/FONT&gt;&lt;/STRONG&gt;&lt;BR /&gt;Policy Rule UID: 8b7e6663-2382-4d20-98ae-d7425eece7f3&lt;BR /&gt;Sub Policy Name: Network&lt;BR /&gt;Sub Policy Uid: 688c78ce-c61c-4799-8101-73e9256dd7f8&lt;BR /&gt;Reason: Connection queue exceeded max size&lt;BR /&gt;Client Type: Other: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like Gecko&lt;BR /&gt;Name: Block HTTP Non Compliant&lt;BR /&gt;Source: 172.31.108.39&lt;BR /&gt;Source Port: 57170&lt;BR /&gt;Destination: 172.31.110.81&lt;BR /&gt;Destination Port: 80&lt;BR /&gt;IP Protocol: 6&lt;BR /&gt;Proxied Source IP: 172.31.108.39&lt;BR /&gt;Source Machine Name: hostname@domain.local&lt;BR /&gt;Session ID: 0&lt;BR /&gt;Action: Reject&lt;BR /&gt;Type: Log&lt;BR /&gt;Policy Name: Standard&lt;BR /&gt;Policy Management: cp-smartappliance&lt;BR /&gt;Db Tag: {64DC84C1-EE9B-F649-B404-3092383FFF3B}&lt;BR /&gt;Policy Date: 2019-05-07T22:18:50Z&lt;BR /&gt;Blade: Firewall&lt;BR /&gt;Origin: cp-gateway1&lt;BR /&gt;Service: TCP/80&lt;BR /&gt;Product Family: Access&lt;BR /&gt;Logid: 65537&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;Resource: &lt;A href="http://172.31.110.81/UserCheck/PortalMain?IID=1DE7C584-961B-C9FB-BAFE-F1F5AA48CC3E&amp;amp;" target="_blank"&gt;http://172.31.110.81/UserCheck/PortalMain?IID=1DE7C584-961B-C9FB-BAFE-F1F5AA48CC3E&amp;amp;&lt;/A&gt;&lt;/STRONG&gt;&lt;/FONT&gt;origUrl=aHR0cDovL3d3dy5nb29nbGV0YWdzZXJ2aWNlcy5jb20vdGFnL2pzL2dwdC5qcw&lt;BR /&gt;Marker: @A@@B@1557291602@C@1472301&lt;BR /&gt;Log Server Origin: 172.31.110.240&lt;BR /&gt;Orig Log Server Ip: 172.31.110.240&lt;BR /&gt;Index Time: 2019-05-08T12:20:45Z&lt;BR /&gt;Inspection Settings Log:true&lt;BR /&gt;Layer Uuid Rule Uuid: _8b7e6663-2382-4d20-98ae-d7425eece7f3&lt;BR /&gt;Access Rule Number: 4&lt;BR /&gt;Access Rule Name: Mgmt&lt;BR /&gt;Lastupdatetime: 1557318044000&lt;BR /&gt;Lastupdateseqnum: 60&lt;BR /&gt;Rounded Sent Bytes: 0&lt;BR /&gt;Rounded Bytes: 0&lt;BR /&gt;Stored: true&lt;BR /&gt;Rounded Received Bytes: 0&lt;BR /&gt;Description: http Traffic Rejected from User2, User2 (user2)(172.31.108.39) to 172.31.110.81&lt;BR /&gt;User: User1, User1 (user1), User2, User2 (user2)&lt;BR /&gt;Source User Name: User1, User1 (user1), User2, User2 (user2)&lt;BR /&gt;Src User Dn: XXXXXXXXXXWould be src dn...yada&lt;BR /&gt;Profile: Go to profile&lt;/P&gt;</description>
    <pubDate>Wed, 08 May 2019 17:07:46 GMT</pubDate>
    <dc:creator>Trey_Havener</dc:creator>
    <dc:date>2019-05-08T17:07:46Z</dc:date>
    <item>
      <title>UserCheck Block Page Times Out</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/UserCheck-Block-Page-Times-Out/m-p/52343#M12773</link>
      <description>&lt;P&gt;We just cut over to our 5400 cluster, and during testing the Block Page displayed fine.&amp;nbsp; Today during the cutover however, the block page seems to keep timing out.&amp;nbsp; We aren't doing much on the block page but telling them why they were blocked and to contact us if they feel it's in error.&amp;nbsp; If I do an incognito tab and then sometimes that will work but most of the time it times out as well.&amp;nbsp; I have a ticket open but wanting to see if anyone else has had this problem.&amp;nbsp; We aren't doing any https inspection...not ready for that nightmare.&amp;nbsp; Just URL filtering.&lt;/P&gt;</description>
      <pubDate>Wed, 01 May 2019 20:03:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/UserCheck-Block-Page-Times-Out/m-p/52343#M12773</guid>
      <dc:creator>Trey_Havener</dc:creator>
      <dc:date>2019-05-01T20:03:40Z</dc:date>
    </item>
    <item>
      <title>Re: UserCheck Block Page Times Out</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/UserCheck-Block-Page-Times-Out/m-p/52358#M12774</link>
      <description>&lt;P&gt;Are you sure it times out or are you presented with the empty page on HTTPS resources and with the Block page on HTTP?&lt;/P&gt;</description>
      <pubDate>Wed, 01 May 2019 23:20:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/UserCheck-Block-Page-Times-Out/m-p/52358#M12774</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2019-05-01T23:20:16Z</dc:date>
    </item>
    <item>
      <title>Re: UserCheck Block Page Times Out</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/UserCheck-Block-Page-Times-Out/m-p/52416#M12775</link>
      <description>Like I said if I use the incognito tab option I am presented a block page some times no matter http/s and it appears chrome gets the page more often then firefox and ie... This morning it seems to be more hit then miss. Not sure if the block page issue is performance related, but our firewalls aren't really getting hit all that much. They are sized appropriately.</description>
      <pubDate>Thu, 02 May 2019 13:15:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/UserCheck-Block-Page-Times-Out/m-p/52416#M12775</guid>
      <dc:creator>Trey_Havener</dc:creator>
      <dc:date>2019-05-02T13:15:57Z</dc:date>
    </item>
    <item>
      <title>Re: UserCheck Block Page Times Out</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/UserCheck-Block-Page-Times-Out/m-p/52428#M12776</link>
      <description>I take it you do have the usercheck page to the proper IP / URL that resolves properly and you have a access rule that allows the traffic to the gateway, above the stealth rule.</description>
      <pubDate>Thu, 02 May 2019 14:44:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/UserCheck-Block-Page-Times-Out/m-p/52428#M12776</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2019-05-02T14:44:48Z</dc:date>
    </item>
    <item>
      <title>Re: UserCheck Block Page Times Out</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/UserCheck-Block-Page-Times-Out/m-p/52434#M12777</link>
      <description>It does resolve, and there is a rule above the stealth rule to allow that traffic. Like I said it works some times not all the time. I feel like if either of those things weren't set that it would never work. Also it never works in Firefox.</description>
      <pubDate>Thu, 02 May 2019 15:15:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/UserCheck-Block-Page-Times-Out/m-p/52434#M12777</guid>
      <dc:creator>Trey_Havener</dc:creator>
      <dc:date>2019-05-02T15:15:17Z</dc:date>
    </item>
    <item>
      <title>Re: UserCheck Block Page Times Out</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/UserCheck-Block-Page-Times-Out/m-p/52435#M12778</link>
      <description>&lt;P&gt;Have you tried restarting UserCheck?&lt;/P&gt;&lt;P&gt;[Expert@HostName]# mpclient stop UserCheck&lt;BR /&gt;[Expert@HostName]# mpclient start UserCheck&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You could also look at&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk85040" target="_self"&gt;sk85040.&lt;/A&gt;&amp;nbsp;You may need to increase the number of HTTP sessions.&lt;/P&gt;</description>
      <pubDate>Thu, 02 May 2019 15:26:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/UserCheck-Block-Page-Times-Out/m-p/52435#M12778</guid>
      <dc:creator>Steve_Payne</dc:creator>
      <dc:date>2019-05-02T15:26:15Z</dc:date>
    </item>
    <item>
      <title>Re: UserCheck Block Page Times Out</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/UserCheck-Block-Page-Times-Out/m-p/52450#M12779</link>
      <description>&lt;P&gt;In some cases involving HTTPS connections when HTTPS Inspection is not enabled, certain browsers will refuse to show the UserCheck page because it thinks there is a man-in-the-middle attack occurring against the connection, which technically there is by virtue of the firewall trying to stuff an alternate web page into the connection.&amp;nbsp; So try to establish under what specific circumstances the UserCheck page is not appearing where the variables are the browser being used, website being visited, and the firewall ingress interface for the client.&amp;nbsp; If you can establish that different browsers exhibit different (but consistent) behavior in regards to the UserCheck page appearing for a certain site, that is to some degree expected and there is not much you can do about it short of enabling HTTPS Inspection.&amp;nbsp; If clients coming in on a certain firewall interface are consistently not getting UserChecks, that indicates that the IP address in the UserCheck URL is not reachable coming in on that specific interface.&lt;/P&gt;
&lt;P&gt;However if there is no consistent pattern and it seems truly "random", check the stability of the &lt;STRONG&gt;fwucd&lt;/STRONG&gt; and &lt;STRONG&gt;usrchkd&lt;/STRONG&gt; daemons on the firewall and make sure they are not crashing or having other issues.&amp;nbsp; Might be enlightening to check log files &lt;EM&gt;$FWDIR/log/usrchkd.elg&lt;/EM&gt; and &lt;EM&gt;$FWDIR/log/fwucd.elg&amp;nbsp;&lt;/EM&gt;to see if any interesting error messages are being barfed into them.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 02 May 2019 18:08:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/UserCheck-Block-Page-Times-Out/m-p/52450#M12779</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2019-05-02T18:08:33Z</dc:date>
    </item>
    <item>
      <title>Re: UserCheck Block Page Times Out</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/UserCheck-Block-Page-Times-Out/m-p/52513#M12780</link>
      <description>&lt;P&gt;This is found in &lt;SPAN class="lia-link-navigation crumb-board lia-breadcrumb-board lia-breadcrumb-forum lia-link-disabled"&gt;SMB Appliances and SMP&lt;/SPAN&gt;, but you speak of a 5400 cluster - so what is true ?&lt;/P&gt;</description>
      <pubDate>Fri, 03 May 2019 10:49:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/UserCheck-Block-Page-Times-Out/m-p/52513#M12780</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2019-05-03T10:49:45Z</dc:date>
    </item>
    <item>
      <title>Re: UserCheck Block Page Times Out</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/UserCheck-Block-Page-Times-Out/m-p/52523#M12781</link>
      <description>No up on my CheckPoint product info. It is a 5400 cluster.&lt;BR /&gt;&lt;BR /&gt;Okay, IE and Chrome works but the page some times takes forever to load or it may not fully load the UserCheck block page. Firefox will not load it period I get this: Secure Connection Failed&lt;BR /&gt;The connection to the server was reset while the page was loading. The page you are trying to view cannot be shown because the authenticity of the received data could not be verified.&lt;BR /&gt;Our previous firewall never had this problem. And we didn't use https inspection on it. I thought https inspection would cause more man in the middle bugs then not having it enabled.</description>
      <pubDate>Fri, 03 May 2019 12:26:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/UserCheck-Block-Page-Times-Out/m-p/52523#M12781</guid>
      <dc:creator>Trey_Havener</dc:creator>
      <dc:date>2019-05-03T12:26:34Z</dc:date>
    </item>
    <item>
      <title>Re: UserCheck Block Page Times Out</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/UserCheck-Block-Page-Times-Out/m-p/52527#M12782</link>
      <description>Not anymore &lt;span class="lia-unicode-emoji" title=":grimacing_face:"&gt;😬&lt;/span&gt;</description>
      <pubDate>Fri, 03 May 2019 13:33:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/UserCheck-Block-Page-Times-Out/m-p/52527#M12782</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-05-03T13:33:18Z</dc:date>
    </item>
    <item>
      <title>Re: UserCheck Block Page Times Out</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/UserCheck-Block-Page-Times-Out/m-p/52556#M12783</link>
      <description>Most likely, you just need to configure Firefox to trust the certificate the gateway is using to serve up the UserCheck portal.&lt;BR /&gt;Firefox uses a different certificate store than IE and Chrome on Windows.</description>
      <pubDate>Fri, 03 May 2019 21:58:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/UserCheck-Block-Page-Times-Out/m-p/52556#M12783</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-05-03T21:58:10Z</dc:date>
    </item>
    <item>
      <title>Re: UserCheck Block Page Times Out</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/UserCheck-Block-Page-Times-Out/m-p/52930#M12784</link>
      <description>&lt;P&gt;Could this be part of my problem?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Time: 2019-05-08T12:20:44Z&lt;BR /&gt;Id: ac1f6e54-0100-00c0-5cd2-c99c00000011&lt;BR /&gt;Sequencenum: 60&lt;BR /&gt;Protection Name: Non Compliant HTTP&lt;BR /&gt;Severity: Critical&lt;BR /&gt;Confidence Level: Medium&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;Protection ID: BlockHttpNonProtocolCompliant&lt;/STRONG&gt;&lt;/FONT&gt;&lt;BR /&gt;Performance Impact: Low&lt;BR /&gt;&lt;STRONG&gt;&lt;FONT color="#FF0000"&gt;Protection Type: Protocol Anomaly HTTP&lt;/FONT&gt;&lt;/STRONG&gt;&lt;BR /&gt;Policy Rule UID: 8b7e6663-2382-4d20-98ae-d7425eece7f3&lt;BR /&gt;Sub Policy Name: Network&lt;BR /&gt;Sub Policy Uid: 688c78ce-c61c-4799-8101-73e9256dd7f8&lt;BR /&gt;Reason: Connection queue exceeded max size&lt;BR /&gt;Client Type: Other: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like Gecko&lt;BR /&gt;Name: Block HTTP Non Compliant&lt;BR /&gt;Source: 172.31.108.39&lt;BR /&gt;Source Port: 57170&lt;BR /&gt;Destination: 172.31.110.81&lt;BR /&gt;Destination Port: 80&lt;BR /&gt;IP Protocol: 6&lt;BR /&gt;Proxied Source IP: 172.31.108.39&lt;BR /&gt;Source Machine Name: hostname@domain.local&lt;BR /&gt;Session ID: 0&lt;BR /&gt;Action: Reject&lt;BR /&gt;Type: Log&lt;BR /&gt;Policy Name: Standard&lt;BR /&gt;Policy Management: cp-smartappliance&lt;BR /&gt;Db Tag: {64DC84C1-EE9B-F649-B404-3092383FFF3B}&lt;BR /&gt;Policy Date: 2019-05-07T22:18:50Z&lt;BR /&gt;Blade: Firewall&lt;BR /&gt;Origin: cp-gateway1&lt;BR /&gt;Service: TCP/80&lt;BR /&gt;Product Family: Access&lt;BR /&gt;Logid: 65537&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;Resource: &lt;A href="http://172.31.110.81/UserCheck/PortalMain?IID=1DE7C584-961B-C9FB-BAFE-F1F5AA48CC3E&amp;amp;" target="_blank"&gt;http://172.31.110.81/UserCheck/PortalMain?IID=1DE7C584-961B-C9FB-BAFE-F1F5AA48CC3E&amp;amp;&lt;/A&gt;&lt;/STRONG&gt;&lt;/FONT&gt;origUrl=aHR0cDovL3d3dy5nb29nbGV0YWdzZXJ2aWNlcy5jb20vdGFnL2pzL2dwdC5qcw&lt;BR /&gt;Marker: @A@@B@1557291602@C@1472301&lt;BR /&gt;Log Server Origin: 172.31.110.240&lt;BR /&gt;Orig Log Server Ip: 172.31.110.240&lt;BR /&gt;Index Time: 2019-05-08T12:20:45Z&lt;BR /&gt;Inspection Settings Log:true&lt;BR /&gt;Layer Uuid Rule Uuid: _8b7e6663-2382-4d20-98ae-d7425eece7f3&lt;BR /&gt;Access Rule Number: 4&lt;BR /&gt;Access Rule Name: Mgmt&lt;BR /&gt;Lastupdatetime: 1557318044000&lt;BR /&gt;Lastupdateseqnum: 60&lt;BR /&gt;Rounded Sent Bytes: 0&lt;BR /&gt;Rounded Bytes: 0&lt;BR /&gt;Stored: true&lt;BR /&gt;Rounded Received Bytes: 0&lt;BR /&gt;Description: http Traffic Rejected from User2, User2 (user2)(172.31.108.39) to 172.31.110.81&lt;BR /&gt;User: User1, User1 (user1), User2, User2 (user2)&lt;BR /&gt;Source User Name: User1, User1 (user1), User2, User2 (user2)&lt;BR /&gt;Src User Dn: XXXXXXXXXXWould be src dn...yada&lt;BR /&gt;Profile: Go to profile&lt;/P&gt;</description>
      <pubDate>Wed, 08 May 2019 17:07:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/UserCheck-Block-Page-Times-Out/m-p/52930#M12784</guid>
      <dc:creator>Trey_Havener</dc:creator>
      <dc:date>2019-05-08T17:07:46Z</dc:date>
    </item>
    <item>
      <title>Re: UserCheck Block Page Times Out</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/UserCheck-Block-Page-Times-Out/m-p/53011#M12785</link>
      <description>&lt;P&gt;We have similar problem where under load, the usercheck page doesn't load and times out.&lt;/P&gt;&lt;P&gt;We had this under a R80.20 VSX cluster and we are now running the firewall on a R80.20 cluster. 5000 users, HTTPS inspection enabled. 15600 appliances.&lt;/P&gt;&lt;P&gt;It used to work ok with R80.10, but since R80.20, never worked as well as before.&lt;/P&gt;&lt;P&gt;SK85040 was followed with both versions.&lt;/P&gt;&lt;P&gt;TAC couldn't help us so far because nothing is logged in error messages because the process seems to be working to hard to log… we are kinda stuck.&lt;/P&gt;</description>
      <pubDate>Thu, 09 May 2019 13:20:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/UserCheck-Block-Page-Times-Out/m-p/53011#M12785</guid>
      <dc:creator>Louis_Poulin</dc:creator>
      <dc:date>2019-05-09T13:20:20Z</dc:date>
    </item>
    <item>
      <title>Re: UserCheck Block Page Times Out</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/UserCheck-Block-Page-Times-Out/m-p/53015#M12786</link>
      <description>&lt;P&gt;We tried https inspection for about 30 minutes, and had to shut it back down.&amp;nbsp; Stupid credit card terminals shut down...couldn't see any logging from them once that was turned on.&amp;nbsp; The block page seemed to work fine when that was turned on.&amp;nbsp; Its just turning it on...&lt;/P&gt;</description>
      <pubDate>Thu, 09 May 2019 13:37:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/UserCheck-Block-Page-Times-Out/m-p/53015#M12786</guid>
      <dc:creator>Trey_Havener</dc:creator>
      <dc:date>2019-05-09T13:37:15Z</dc:date>
    </item>
    <item>
      <title>Re: UserCheck Block Page Times Out</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/UserCheck-Block-Page-Times-Out/m-p/53025#M12787</link>
      <description>&lt;P&gt;Inspired by&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?action=portlets.SearchResultMainAction&amp;amp;eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk85040" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?action=portlets.SearchResultMainAction&amp;amp;eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk85040&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A href="https://httpd.apache.org/docs/2.4/mod/mpm_common.html#maxrequestworkers&amp;nbsp;" target="_blank"&gt;https://httpd.apache.org/docs/2.4/mod/mpm_common.html#maxrequestworkers&amp;nbsp;&lt;/A&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;I increased MaxRequestWorkers and ServerLimit from 100 to 256 (which seems to be the default from Apache's point of view instead of 28 from Check Point's point of view. Maybe it's not the same version?). Since there is 15GB of RAM free, I considered it to be safe.&lt;/P&gt;&lt;P&gt;usrchkd was restarted.&lt;/P&gt;&lt;P&gt;User Check page has been working for an hour now. We'll see if it last.&lt;/P&gt;&lt;P&gt;Hopefully it can help someone!&lt;/P&gt;</description>
      <pubDate>Thu, 09 May 2019 14:46:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/UserCheck-Block-Page-Times-Out/m-p/53025#M12787</guid>
      <dc:creator>Louis_Poulin</dc:creator>
      <dc:date>2019-05-09T14:46:15Z</dc:date>
    </item>
    <item>
      <title>Re: UserCheck Block Page Times Out</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/UserCheck-Block-Page-Times-Out/m-p/53130#M12788</link>
      <description>&lt;P&gt;After 1 day, the User Check page is still working!&lt;/P&gt;</description>
      <pubDate>Fri, 10 May 2019 13:29:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/UserCheck-Block-Page-Times-Out/m-p/53130#M12788</guid>
      <dc:creator>Louis_Poulin</dc:creator>
      <dc:date>2019-05-10T13:29:37Z</dc:date>
    </item>
    <item>
      <title>Re: UserCheck Block Page Times Out</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/UserCheck-Block-Page-Times-Out/m-p/53352#M12789</link>
      <description>&lt;P&gt;UserCheck block page keeps loading today…&lt;/P&gt;&lt;P&gt;Restarting the process resolved the issue (mpclient stop UserCheck; mpclient start UserCheck).&lt;/P&gt;&lt;P&gt;We are considering an automated restart of the service by putting those commands in the crontab &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 14 May 2019 13:08:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/UserCheck-Block-Page-Times-Out/m-p/53352#M12789</guid>
      <dc:creator>Louis_Poulin</dc:creator>
      <dc:date>2019-05-14T13:08:07Z</dc:date>
    </item>
    <item>
      <title>Re: UserCheck Block Page Times Out</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/UserCheck-Block-Page-Times-Out/m-p/58985#M12790</link>
      <description>&lt;P&gt;Seeing this same issue after migrating to R80.20.&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jul 2019 18:18:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/UserCheck-Block-Page-Times-Out/m-p/58985#M12790</guid>
      <dc:creator>Gregory_Link</dc:creator>
      <dc:date>2019-07-25T18:18:00Z</dc:date>
    </item>
    <item>
      <title>Re: UserCheck Block Page Times Out</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/UserCheck-Block-Page-Times-Out/m-p/59194#M12791</link>
      <description>&lt;P&gt;Hi there,&lt;/P&gt;&lt;P&gt;We also had to increase serverlimit and maxrequestworkers way more than it is mentioned in SK. Usercheck keeps complaining about "server reached maxrequestworkers", and we are not even close to 5k users... TAC is just making me laugh when suggesting to block traffic without usercheck interaction.&lt;/P&gt;&lt;P&gt;How many connections do you usually have during peak time?&lt;/P&gt;&lt;P&gt;netstat -anp |grep `mpclient getdata UserCheck |awk '{print $6}'` |wc -l&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jul 2019 21:16:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/UserCheck-Block-Page-Times-Out/m-p/59194#M12791</guid>
      <dc:creator>abihsot__</dc:creator>
      <dc:date>2019-07-29T21:16:00Z</dc:date>
    </item>
    <item>
      <title>Re: UserCheck Block Page Times Out</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/UserCheck-Block-Page-Times-Out/m-p/62939#M12792</link>
      <description>&lt;P&gt;This might help you tackle this problem.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'd spent quite a bit of time digging into this exact problem in our environment and found that when having to serve large volumes of block pages to users that it was typically httpd that starts failing by leaking connections.&amp;nbsp; Throwing resources at the problem by upping the number of workers or adjusting the session time and garbage collection didn't help in high load conditions because eventually the available workers get saturated.&amp;nbsp;&lt;/P&gt;&lt;P&gt;This can be seen by listing the number of connections hitting your block page:&lt;/P&gt;&lt;P&gt;`netstat -np | egrep '/httpd|-' | egrep 'x.x.x.x:[0-9]{4,5}' | awk '{print $6}' | sort | uniq -c`&lt;/P&gt;&lt;P&gt;If you see a fair bit more CLOSE_WAIT connections than the configured httpd workers number then httpd is likely failing to keep up with closing connections which results in the connections being orphaned and are taking too long to expire due to age.&amp;nbsp; A good article to read on this topic is:&lt;/P&gt;&lt;P&gt;&lt;A href="https://blog.cloudflare.com/this-is-strictly-a-violation-of-the-tcp-specification/" target="_blank"&gt;https://blog.cloudflare.com/this-is-strictly-a-violation-of-the-tcp-specification/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;By looking for the IPs with the highest number of blocks I was then able to see what the users were trying to access that is generating the majority of the blocks:&amp;nbsp;&lt;/P&gt;&lt;P&gt;`netstat -np | egrep '/httpd|-' | egrep 'x.x.x.x:[0-9]{4,5}' | awk '{print $5}' | awk -F: '{print $1}' | sort | uniq -c | sort -rn | head -10`&lt;/P&gt;&lt;P&gt;In SmartDashboard I then filtered for a TopX IP and action:redirect, then used the "Top Destinations" in the Filters Pane to narrow things down.&lt;/P&gt;&lt;P&gt;In my most recent case there was particular advertising domain, dt[.]adsafeprotected[.]com, that is (still waiting for recat of the site) incorrectly categorised as an "Inactive Site" instead of "Web Advertising" and so resulting in a block which was typically not visible to the users.&amp;nbsp; Since the domain is heavily used in a number of major sites it accounted for around 75% of the block pages being served.&amp;nbsp; Site categorisation overrides can be done using a custom site/app or an override object.&lt;/P&gt;&lt;P&gt;I wrote a quick and dirty script (attached) to aid investigations into how tuning the various known/suggested settings affected the overall performance and to monitor the state of the connections and Top10 users.&amp;nbsp; I ran it through watch:&lt;/P&gt;&lt;P&gt;`watch -n 5 ./httpd_session_info.sh 2&amp;gt; /dev/null`&lt;/P&gt;&lt;P&gt;What became clear was that unless your /opt/CPUserCheckPortal/session directory has exorbitant numbers of files in it you should not have to adjust the php.ini file settings aside from adjusting the lifetime down to 1800 as mentioned in sk98773.&amp;nbsp; I had set mine to 1200 (20 mins) with a garbage collection ratio of 2/100 and had pushed the workers up to 400 and still httpd lost the battle.&lt;/P&gt;&lt;P&gt;If after working through the heavy hitters you get to the point that the hits to your block page are valid and due to 'normal usage' then you can start upping the worker count to accommodate the volume.&amp;nbsp; What you want to aim for is enough workers to allow the system to recover on its own, ideally the max number of workers should not be hit for too long.&lt;/P&gt;&lt;P&gt;I settled on 250 workers for about 1.5-2k users, this allowed for enough head room for the UserCheck portal to recover on its own.&amp;nbsp; Long before I solved this problem for our clusters I'd written a python script that monitors the MPClient portals responsiveness, if a portal takes more than 8 seconds to respond it's considered down, the script then fires off an email notification to alert me which thankfully has not triggered in the last week and a half&amp;nbsp; &lt;span class="lia-unicode-emoji" title=":grinning_face_with_smiling_eyes:"&gt;😄&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Sep 2019 12:28:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/UserCheck-Block-Page-Times-Out/m-p/62939#M12792</guid>
      <dc:creator>AlanTen</dc:creator>
      <dc:date>2019-09-17T12:28:35Z</dc:date>
    </item>
  </channel>
</rss>

