<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Action:Accept Reason:Connection terminated in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Action-Accept-Reason-Connection-terminated/m-p/190308#M35116</link>
    <description>&lt;P&gt;Hello everybody,&lt;/P&gt;&lt;P&gt;The question is very simple and it was asked many times and answered many times, but no answer was really satisfying.&lt;BR /&gt;My question is entirely seen on the picture: I have simple explicit access rule (not application rule) that allows access to certain node by very simple and common protocol. And I see in the LOG records saying &lt;STRONG&gt;Action: "Accept"&lt;/STRONG&gt; and below the &lt;STRONG&gt;Reason:"Connection terminated before detection: insufficient data passed"&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Accept terminated.png" style="width: 969px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/22188i20A76A83E92B7C9A/image-size/large?v=v2&amp;amp;px=999" role="button" title="Accept terminated.png" alt="Accept terminated.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;What can I conclude (if I do not see any other records from this source):&lt;BR /&gt;- the session was accepted or terminated finally?&lt;BR /&gt;- if it was finally accepted and continue, I do not want to see "Connection terminated"&lt;BR /&gt;- if it was finally terminated, I do not want to see "Accept" here.&amp;nbsp; What difference for me that action was not "Deny" or "Drop" but "Terminated" if result is same?&lt;BR /&gt;- If it was terminated finally - it was terminated &lt;STRONG&gt;by who?? by Checkpoint Gw or by the Source or by the Destination? It's critical to understand!&lt;BR /&gt;&lt;BR /&gt;&lt;/STRONG&gt;If the connection was terminated before detection &lt;STRONG&gt;by source or destination node&lt;/STRONG&gt; - please write this in the reason field.&lt;BR /&gt;If the connection was terminated by Gw - please, You should understand that ''Insufficient data passed" just not reasonable to terminate session that explicitly defined as allowed&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 23 Aug 2023 14:11:23 GMT</pubDate>
    <dc:creator>evlad</dc:creator>
    <dc:date>2023-08-23T14:11:23Z</dc:date>
    <item>
      <title>Action:Accept Reason:Connection terminated</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Action-Accept-Reason-Connection-terminated/m-p/190308#M35116</link>
      <description>&lt;P&gt;Hello everybody,&lt;/P&gt;&lt;P&gt;The question is very simple and it was asked many times and answered many times, but no answer was really satisfying.&lt;BR /&gt;My question is entirely seen on the picture: I have simple explicit access rule (not application rule) that allows access to certain node by very simple and common protocol. And I see in the LOG records saying &lt;STRONG&gt;Action: "Accept"&lt;/STRONG&gt; and below the &lt;STRONG&gt;Reason:"Connection terminated before detection: insufficient data passed"&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Accept terminated.png" style="width: 969px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/22188i20A76A83E92B7C9A/image-size/large?v=v2&amp;amp;px=999" role="button" title="Accept terminated.png" alt="Accept terminated.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;What can I conclude (if I do not see any other records from this source):&lt;BR /&gt;- the session was accepted or terminated finally?&lt;BR /&gt;- if it was finally accepted and continue, I do not want to see "Connection terminated"&lt;BR /&gt;- if it was finally terminated, I do not want to see "Accept" here.&amp;nbsp; What difference for me that action was not "Deny" or "Drop" but "Terminated" if result is same?&lt;BR /&gt;- If it was terminated finally - it was terminated &lt;STRONG&gt;by who?? by Checkpoint Gw or by the Source or by the Destination? It's critical to understand!&lt;BR /&gt;&lt;BR /&gt;&lt;/STRONG&gt;If the connection was terminated before detection &lt;STRONG&gt;by source or destination node&lt;/STRONG&gt; - please write this in the reason field.&lt;BR /&gt;If the connection was terminated by Gw - please, You should understand that ''Insufficient data passed" just not reasonable to terminate session that explicitly defined as allowed&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Aug 2023 14:11:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Action-Accept-Reason-Connection-terminated/m-p/190308#M35116</guid>
      <dc:creator>evlad</dc:creator>
      <dc:date>2023-08-23T14:11:23Z</dc:date>
    </item>
    <item>
      <title>Re: Action:Accept Reason:Connection terminated</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Action-Accept-Reason-Connection-terminated/m-p/190312#M35117</link>
      <description>&lt;P&gt;The connection was terminated by either the client or the server participating in it. FW action is Accept. The message is referring that data passing through the connection was not sufficient to determine an actual application.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Aug 2023 14:09:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Action-Accept-Reason-Connection-terminated/m-p/190312#M35117</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2023-08-23T14:09:24Z</dc:date>
    </item>
    <item>
      <title>Re: Action:Accept Reason:Connection terminated</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Action-Accept-Reason-Connection-terminated/m-p/190314#M35118</link>
      <description>&lt;P&gt;Thank You so much! If it so, Your answer make the issue very clear.&lt;BR /&gt;I just want to mention that could be the brilliant improvement from CheckPoint to add at the reason:&lt;BR /&gt;&lt;STRONG&gt;"&lt;/STRONG&gt;Connection terminated&lt;STRONG&gt; by souce/destination&lt;/STRONG&gt;/... before detection&lt;STRONG&gt;"&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Aug 2023 14:25:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Action-Accept-Reason-Connection-terminated/m-p/190314#M35118</guid>
      <dc:creator>evlad</dc:creator>
      <dc:date>2023-08-23T14:25:25Z</dc:date>
    </item>
  </channel>
</rss>

