<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: R80.40 explicit proxy does not close the connection to client in certain conditions in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-40-explicit-proxy-does-not-close-the-connection-to-client-in/m-p/162388#M28866</link>
    <description>&lt;P&gt;thanks for suggestions. Just as an update,&amp;nbsp; Take 180 did not fix the issue... I have to open a TAC case&lt;/P&gt;</description>
    <pubDate>Thu, 17 Nov 2022 16:39:16 GMT</pubDate>
    <dc:creator>jkougoulos</dc:creator>
    <dc:date>2022-11-17T16:39:16Z</dc:date>
    <item>
      <title>R80.40 explicit proxy does not close the connection to client in certain conditions</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-40-explicit-proxy-does-not-close-the-connection-to-client-in/m-p/160229#M28221</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;&lt;BR /&gt;I have one VSX gateway configured as non-transparent proxy (r80.40 take 158) and I face a an issue that appears as random but I believe I have narrow it down to something more specific.&lt;BR /&gt;&lt;BR /&gt;So, there are some web servers that do not provide "Content-Length" but they close the TCP connection at the end of the transmission eg when they transmit content in gzip format. In most cases this is not a problem, as the proxy closes the connection to the client when all data are sent.&lt;BR /&gt;However, when the connection of the proxy to the server is better/faster than the one to the client, which causes various re-transmissions, the proxy does not close the connection and the client stays idle. The web browser in this case looks like stalling in transfer.&lt;BR /&gt;I have confirmed with tcpdump/wireshark that the proxy does not send a FIN/RST when the issue happens and the issue does not seem to appear when I use squid instead of checkpoint.&lt;BR /&gt;&lt;BR /&gt;I was able to reproduce this by setting up a server close to our data center and setting the client to 10mbps/half duplex. I transfer a .js file of around 1.7MB which becomes ~400kB after gzip compression.&lt;BR /&gt;The server (an Apache) is configured with something like the following to emulate the behavior of the server that triggered the investigation for this issue (this is for firefox &amp;gt; 100):&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;               BrowserMatch "Firefox/10" \
                                nokeepalive ssl-unclean-shutdown \
                                downgrade-1.0 force-response-1.0&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The issue is reproducible in Edge, Chrome, Firefox, curl, wget in Windows and Linux. The only client that does not show the problem is powershell or .net code using (Invoke-)WebRequest with AutomaticDecompression flag enabled.&lt;BR /&gt;&lt;BR /&gt;The Gateway has HTTPS inspection enabled but the policy does not inspect the specific sites.&lt;BR /&gt;I have tried disabling the IPS, the issue persists.&lt;BR /&gt;&lt;BR /&gt;Does the above behavior ring any bell of any kind of workaround or setting that I may miss?&lt;BR /&gt;Any hints on further troubleshooting, like what kind of debug commands I could enable to see any further information?&lt;BR /&gt;&lt;BR /&gt;Kind regards,&lt;/P&gt;&lt;P&gt;John&lt;/P&gt;</description>
      <pubDate>Mon, 24 Oct 2022 10:29:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-40-explicit-proxy-does-not-close-the-connection-to-client-in/m-p/160229#M28221</guid>
      <dc:creator>jkougoulos</dc:creator>
      <dc:date>2022-10-24T10:29:19Z</dc:date>
    </item>
    <item>
      <title>Re: R80.40 explicit proxy does not close the connection to client in certain conditions</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-40-explicit-proxy-does-not-close-the-connection-to-client-in/m-p/160233#M28222</link>
      <description>&lt;P&gt;I would suggest a TAC case&lt;/P&gt;</description>
      <pubDate>Mon, 24 Oct 2022 11:09:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-40-explicit-proxy-does-not-close-the-connection-to-client-in/m-p/160233#M28222</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-10-24T11:09:01Z</dc:date>
    </item>
    <item>
      <title>Re: R80.40 explicit proxy does not close the connection to client in certain conditions</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-40-explicit-proxy-does-not-close-the-connection-to-client-in/m-p/160234#M28223</link>
      <description>&lt;P&gt;Take 161 GA contains some gzip &amp;amp; proxy fixes.&lt;/P&gt;
&lt;P&gt;Suggest working the case further with TAC since you seem to have a good handle on how it can be replicated.&lt;/P&gt;</description>
      <pubDate>Mon, 24 Oct 2022 11:15:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-40-explicit-proxy-does-not-close-the-connection-to-client-in/m-p/160234#M28223</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-10-24T11:15:28Z</dc:date>
    </item>
    <item>
      <title>Re: R80.40 explicit proxy does not close the connection to client in certain conditions</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-40-explicit-proxy-does-not-close-the-connection-to-client-in/m-p/162388#M28866</link>
      <description>&lt;P&gt;thanks for suggestions. Just as an update,&amp;nbsp; Take 180 did not fix the issue... I have to open a TAC case&lt;/P&gt;</description>
      <pubDate>Thu, 17 Nov 2022 16:39:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-40-explicit-proxy-does-not-close-the-connection-to-client-in/m-p/162388#M28866</guid>
      <dc:creator>jkougoulos</dc:creator>
      <dc:date>2022-11-17T16:39:16Z</dc:date>
    </item>
  </channel>
</rss>

