<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Connection terminated before the Security Gateway was able to make a decision in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Connection-terminated-before-the-Security-Gateway-was-able-to/m-p/175106#M31908</link>
    <description>&lt;P&gt;we are trying to connect to&amp;nbsp;idream.pl (137.74.1.35)&amp;nbsp;http (TCP/80)&lt;/P&gt;</description>
    <pubDate>Thu, 16 Mar 2023 13:32:29 GMT</pubDate>
    <dc:creator>Gacki</dc:creator>
    <dc:date>2023-03-16T13:32:29Z</dc:date>
    <item>
      <title>Connection terminated before the Security Gateway was able to make a decision</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Connection-terminated-before-the-Security-Gateway-was-able-to/m-p/175094#M31901</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I have a problem that the idream.pl website works properly inside the company, but if there is a VPN access to the website, unfortunately a too long wait message pops up, the checkpoint logs show what is in the connector.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;A rule is made that should allow access to this page.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Mar 2023 12:26:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Connection-terminated-before-the-Security-Gateway-was-able-to/m-p/175094#M31901</guid>
      <dc:creator>Gacki</dc:creator>
      <dc:date>2023-03-16T12:26:16Z</dc:date>
    </item>
    <item>
      <title>Re: Connection terminated before the Security Gateway was able to make a decision</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Connection-terminated-before-the-Security-Gateway-was-able-to/m-p/175095#M31902</link>
      <description>&lt;P&gt;Have you already reviewed&amp;nbsp;&lt;SPAN&gt;sk113479?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Mar 2023 12:30:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Connection-terminated-before-the-Security-Gateway-was-able-to/m-p/175095#M31902</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-03-16T12:30:03Z</dc:date>
    </item>
    <item>
      <title>Re: Connection terminated before the Security Gateway was able to make a decision</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Connection-terminated-before-the-Security-Gateway-was-able-to/m-p/175096#M31903</link>
      <description>&lt;P&gt;&lt;SPAN&gt;yes, but i didn't find the answer there.&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV class=""&gt;&lt;P&gt;my error is&amp;nbsp;&lt;/P&gt;&lt;TABLE border="1" width="100%" cellspacing="2" cellpadding="4"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="40%" height="69px"&gt;Connection terminated before detection: Insufficient data. &amp;lt;X&amp;gt; bytes passed&lt;/TD&gt;&lt;TD width="59.91189427312775%" height="69px"&gt;&lt;P&gt;Data packets have arrived, but the amount of data was not enough for the engine detection. The string will also state the number of data bytes (TCP/UDP payload) that may pass the Gateway.&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;now the question is how can i solve it?&lt;/SPAN&gt;&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Thu, 16 Mar 2023 12:36:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Connection-terminated-before-the-Security-Gateway-was-able-to/m-p/175096#M31903</guid>
      <dc:creator>Gacki</dc:creator>
      <dc:date>2023-03-16T12:36:19Z</dc:date>
    </item>
    <item>
      <title>Re: Connection terminated before the Security Gateway was able to make a decision</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Connection-terminated-before-the-Security-Gateway-was-able-to/m-p/175099#M31904</link>
      <description>&lt;P&gt;I had this happen with customer before and TAC told us that sk simply states its not CP issue, to make a long story short : - ). I actually agree with that, because logically, connection gets terminated, but there is proof anywhere its the fw causing it.&lt;/P&gt;
&lt;P&gt;You definitely need to run some captures and confirm whats happening with the traffic.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 16 Mar 2023 12:50:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Connection-terminated-before-the-Security-Gateway-was-able-to/m-p/175099#M31904</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-03-16T12:50:20Z</dc:date>
    </item>
    <item>
      <title>Re: Connection terminated before the Security Gateway was able to make a decision</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Connection-terminated-before-the-Security-Gateway-was-able-to/m-p/175101#M31905</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Can you suggest how best to capture this traffic? additionally wireshark? or on the checkpoint side?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Mar 2023 13:04:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Connection-terminated-before-the-Security-Gateway-was-able-to/m-p/175101#M31905</guid>
      <dc:creator>Gacki</dc:creator>
      <dc:date>2023-03-16T13:04:22Z</dc:date>
    </item>
    <item>
      <title>Re: Connection terminated before the Security Gateway was able to make a decision</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Connection-terminated-before-the-Security-Gateway-was-able-to/m-p/175104#M31907</link>
      <description>&lt;P&gt;Lets do remote if you are allowed and I can help you. If not, please provide the source/dst IP addresses with ports/protocol involved and I can send you the captures you need.&lt;/P&gt;
&lt;P&gt;Cheers mate.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 16 Mar 2023 13:25:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Connection-terminated-before-the-Security-Gateway-was-able-to/m-p/175104#M31907</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-03-16T13:25:20Z</dc:date>
    </item>
    <item>
      <title>Re: Connection terminated before the Security Gateway was able to make a decision</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Connection-terminated-before-the-Security-Gateway-was-able-to/m-p/175106#M31908</link>
      <description>&lt;P&gt;we are trying to connect to&amp;nbsp;idream.pl (137.74.1.35)&amp;nbsp;http (TCP/80)&lt;/P&gt;</description>
      <pubDate>Thu, 16 Mar 2023 13:32:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Connection-terminated-before-the-Security-Gateway-was-able-to/m-p/175106#M31908</guid>
      <dc:creator>Gacki</dc:creator>
      <dc:date>2023-03-16T13:32:29Z</dc:date>
    </item>
    <item>
      <title>Re: Connection terminated before the Security Gateway was able to make a decision</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Connection-terminated-before-the-Security-Gateway-was-able-to/m-p/175107#M31909</link>
      <description>&lt;P&gt;K, cool. Can you please give me one source IP you are testing from, so I can give you right capture flags?&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 16 Mar 2023 13:33:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Connection-terminated-before-the-Security-Gateway-was-able-to/m-p/175107#M31909</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-03-16T13:33:40Z</dc:date>
    </item>
    <item>
      <title>Re: Connection terminated before the Security Gateway was able to make a decision</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Connection-terminated-before-the-Security-Gateway-was-able-to/m-p/175108#M31910</link>
      <description>&lt;P&gt;10.10.12.16&lt;/P&gt;</description>
      <pubDate>Thu, 16 Mar 2023 13:35:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Connection-terminated-before-the-Security-Gateway-was-able-to/m-p/175108#M31910</guid>
      <dc:creator>Gacki</dc:creator>
      <dc:date>2023-03-16T13:35:45Z</dc:date>
    </item>
    <item>
      <title>Re: Connection terminated before the Security Gateway was able to make a decision</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Connection-terminated-before-the-Security-Gateway-was-able-to/m-p/175110#M31911</link>
      <description>&lt;P&gt;fw monitor -e "accept host(137.74.1.35);"&lt;BR /&gt;fw monitor -e "accept host(137.74.1.35) and port(80);"&lt;BR /&gt;fw monitor -e "accept host(137.74.1.35) and host(10.10.12.16);"&lt;BR /&gt;tcpdump -nni any host 137.74.1.35&lt;BR /&gt;fw monitor -F "10.10.12.16,0,137.74.1.35,80,0"&lt;BR /&gt;fw monitor -F "10.10.12.16,0,137.74.1.35,80,0" -F "137.74.1.35,0,10.10.12.16,80,0"&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Just as a side note, though you already probably know this, tcpdump will NOT show you any inspection points taking place, simply if traffic is hitting any interface on the firewall, but fw monitor would show you those things.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 16 Mar 2023 13:41:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Connection-terminated-before-the-Security-Gateway-was-able-to/m-p/175110#M31911</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-03-16T13:41:57Z</dc:date>
    </item>
    <item>
      <title>Re: Connection terminated before the Security Gateway was able to make a decision</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Connection-terminated-before-the-Security-Gateway-was-able-to/m-p/175115#M31915</link>
      <description>&lt;P&gt;i.e. it's not a checkpoint problem, but something before the checkpoint is causing not all data packets to arrive&lt;/P&gt;</description>
      <pubDate>Thu, 16 Mar 2023 14:22:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Connection-terminated-before-the-Security-Gateway-was-able-to/m-p/175115#M31915</guid>
      <dc:creator>Gacki</dc:creator>
      <dc:date>2023-03-16T14:22:43Z</dc:date>
    </item>
    <item>
      <title>Re: Connection terminated before the Security Gateway was able to make a decision</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Connection-terminated-before-the-Security-Gateway-was-able-to/m-p/175119#M31916</link>
      <description>&lt;P&gt;Correct and that sk is literally LONG way of simply saying "This is not Check Point issue" &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Mar 2023 14:27:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Connection-terminated-before-the-Security-Gateway-was-able-to/m-p/175119#M31916</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-03-16T14:27:16Z</dc:date>
    </item>
  </channel>
</rss>

