<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic rad errors : &amp;quot;Failed to parse CP Site Response.&amp;quot;, response expired several days ago. in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/rad-errors-quot-Failed-to-parse-CP-Site-Response-quot-response/m-p/177395#M32500</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I have two clusters of CP 16200 running R80.40 T192 with thousands of internet users.&lt;/P&gt;&lt;P&gt;I started url filtering blade to block some application using https categorization (no https inspection).&lt;/P&gt;&lt;P&gt;It's working as expected, but i have now hundreds of "Failed to parse CP Site Response" logs in smartconsole.&lt;/P&gt;&lt;P&gt;$FWDIR/log/rad_events/Errors is full of error files (hundreds per minute).&lt;/P&gt;&lt;P&gt;In attach an example of flow error (proxy IP changed)&lt;/P&gt;&lt;P&gt;We are not using anti-virus or anti-bot.&lt;/P&gt;&lt;P&gt;I opened a case (SR #6-0003583350)&amp;nbsp; but for now, it doesn't help.&lt;/P&gt;&lt;P&gt;I have a strange "response expired" message in the error files :&amp;nbsp;&lt;/P&gt;&lt;P&gt;---------------------&lt;/P&gt;&lt;P&gt;[rad_xml_urlf.cpp:350] CRadXmlUrlf::listen: [INFO] Found response UTC: 1680631251&lt;BR /&gt;[rad_xml_urlf.cpp:359] CRadXmlUrlf::listen: [ERROR] response expired: seconds difference: 68797 now: Wed Apr 5 15:07:28 2023&lt;BR /&gt;response time: Tue Apr 4 20:00:51 2023&lt;/P&gt;&lt;P&gt;---------------------&lt;/P&gt;&lt;P&gt;In this example, response time is 68797s (=19 hours) before current time. This value varies from 40000 up to 400000s = more than 4 days.&lt;/P&gt;&lt;P&gt;I'm looking for the possible cause of such errors.&lt;/P&gt;&lt;P&gt;thanks,&lt;/P&gt;&lt;P&gt;fred&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 05 Apr 2023 13:26:48 GMT</pubDate>
    <dc:creator>fcamus</dc:creator>
    <dc:date>2023-04-05T13:26:48Z</dc:date>
    <item>
      <title>rad errors : "Failed to parse CP Site Response.", response expired several days ago.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/rad-errors-quot-Failed-to-parse-CP-Site-Response-quot-response/m-p/177395#M32500</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I have two clusters of CP 16200 running R80.40 T192 with thousands of internet users.&lt;/P&gt;&lt;P&gt;I started url filtering blade to block some application using https categorization (no https inspection).&lt;/P&gt;&lt;P&gt;It's working as expected, but i have now hundreds of "Failed to parse CP Site Response" logs in smartconsole.&lt;/P&gt;&lt;P&gt;$FWDIR/log/rad_events/Errors is full of error files (hundreds per minute).&lt;/P&gt;&lt;P&gt;In attach an example of flow error (proxy IP changed)&lt;/P&gt;&lt;P&gt;We are not using anti-virus or anti-bot.&lt;/P&gt;&lt;P&gt;I opened a case (SR #6-0003583350)&amp;nbsp; but for now, it doesn't help.&lt;/P&gt;&lt;P&gt;I have a strange "response expired" message in the error files :&amp;nbsp;&lt;/P&gt;&lt;P&gt;---------------------&lt;/P&gt;&lt;P&gt;[rad_xml_urlf.cpp:350] CRadXmlUrlf::listen: [INFO] Found response UTC: 1680631251&lt;BR /&gt;[rad_xml_urlf.cpp:359] CRadXmlUrlf::listen: [ERROR] response expired: seconds difference: 68797 now: Wed Apr 5 15:07:28 2023&lt;BR /&gt;response time: Tue Apr 4 20:00:51 2023&lt;/P&gt;&lt;P&gt;---------------------&lt;/P&gt;&lt;P&gt;In this example, response time is 68797s (=19 hours) before current time. This value varies from 40000 up to 400000s = more than 4 days.&lt;/P&gt;&lt;P&gt;I'm looking for the possible cause of such errors.&lt;/P&gt;&lt;P&gt;thanks,&lt;/P&gt;&lt;P&gt;fred&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 05 Apr 2023 13:26:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/rad-errors-quot-Failed-to-parse-CP-Site-Response-quot-response/m-p/177395#M32500</guid>
      <dc:creator>fcamus</dc:creator>
      <dc:date>2023-04-05T13:26:48Z</dc:date>
    </item>
    <item>
      <title>Re: rad errors : "Failed to parse CP Site Response.", response expired several days ago.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/rad-errors-quot-Failed-to-parse-CP-Site-Response-quot-response/m-p/183648#M33709</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;I reply to my post.&lt;/P&gt;&lt;P&gt;After a (painfull) case where TAC asked me to do some tuning, modify my custom application objects, the case reached R&amp;amp;D where it was rapidly identified that rad process refused the cached proxy reply.&lt;/P&gt;&lt;P&gt;The problem was resolved as soon as the proxy administrator disabled cache for cws.checkpoint.com&lt;/P&gt;&lt;P&gt;If rad doesn't accept cached response, it would be better to use the cache-control functionalities of http protocol !&lt;/P&gt;&lt;P&gt;So if you use proxy, verify that caching is disabled. Hope this will help some members.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;fred&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Jun 2023 15:31:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/rad-errors-quot-Failed-to-parse-CP-Site-Response-quot-response/m-p/183648#M33709</guid>
      <dc:creator>fcamus</dc:creator>
      <dc:date>2023-06-08T15:31:30Z</dc:date>
    </item>
  </channel>
</rss>

