<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Can not surf to a website in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-not-surf-to-a-website/m-p/213320#M40612</link>
    <description>&lt;P&gt;I did both and did not get any hit on the rule!&lt;/P&gt;
&lt;P&gt;i have also tested&amp;nbsp;\/matematikxyz\.com and also no hit on the rule!&lt;/P&gt;</description>
    <pubDate>Mon, 06 May 2024 15:34:46 GMT</pubDate>
    <dc:creator>Moudar</dc:creator>
    <dc:date>2024-05-06T15:34:46Z</dc:date>
    <item>
      <title>Can not surf to a website</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-not-surf-to-a-website/m-p/213288#M40597</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;when trying to surf to a specific website i get this error "&lt;STRONG&gt;ERR_EMPTY_RESPONSE&lt;/STRONG&gt;" on all browsers.&lt;/P&gt;
&lt;P&gt;When I open the same website from a private PC (no firewall) then it works with no problem.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;All logs are "Accept" but still getting "&lt;SPAN&gt;ERR_EMPTY_RESPONSE&lt;/SPAN&gt;" on browsers&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What should I troubleshoot when seeing this:&amp;nbsp;&lt;SPAN&gt;ERR_EMPTY_RESPONSE&amp;nbsp; ?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 06 May 2024 14:16:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-not-surf-to-a-website/m-p/213288#M40597</guid>
      <dc:creator>Moudar</dc:creator>
      <dc:date>2024-05-06T14:16:22Z</dc:date>
    </item>
    <item>
      <title>Re: Can not surf to a website</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-not-surf-to-a-website/m-p/213291#M40599</link>
      <description>&lt;P&gt;Can you share what site? Is there ssl inspection involved?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 06 May 2024 14:34:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-not-surf-to-a-website/m-p/213291#M40599</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-05-06T14:34:07Z</dc:date>
    </item>
    <item>
      <title>Re: Can not surf to a website</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-not-surf-to-a-website/m-p/213297#M40601</link>
      <description>&lt;P&gt;matematikxyz.com&lt;/P&gt;
&lt;P&gt;matematikabg.se&lt;/P&gt;
&lt;P&gt;HTTPS is not used&lt;/P&gt;</description>
      <pubDate>Mon, 06 May 2024 14:44:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-not-surf-to-a-website/m-p/213297#M40601</guid>
      <dc:creator>Moudar</dc:creator>
      <dc:date>2024-05-06T14:44:15Z</dc:date>
    </item>
    <item>
      <title>Re: Can not surf to a website</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-not-surf-to-a-website/m-p/213303#M40604</link>
      <description>&lt;P&gt;Just tried both in lab with ssl inspection and without and worked fine. Can you confirm what this is set to now? Not sure if you changed it or not...&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/25548i6A529E032CBAC8CE/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_1.png" alt="Screenshot_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Mon, 06 May 2024 14:54:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-not-surf-to-a-website/m-p/213303#M40604</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-05-06T14:54:13Z</dc:date>
    </item>
    <item>
      <title>Re: Can not surf to a website</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-not-surf-to-a-website/m-p/213307#M40605</link>
      <description>&lt;P&gt;it is "Allow all requests" in my case&lt;/P&gt;</description>
      <pubDate>Mon, 06 May 2024 15:03:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-not-surf-to-a-website/m-p/213307#M40605</guid>
      <dc:creator>Moudar</dc:creator>
      <dc:date>2024-05-06T15:03:33Z</dc:date>
    </item>
    <item>
      <title>Re: Can not surf to a website</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-not-surf-to-a-website/m-p/213309#M40607</link>
      <description>&lt;P&gt;K, fair enough. Did you make custom category to allow the sites?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 06 May 2024 15:07:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-not-surf-to-a-website/m-p/213309#M40607</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-05-06T15:07:57Z</dc:date>
    </item>
    <item>
      <title>Re: Can not surf to a website</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-not-surf-to-a-website/m-p/213311#M40608</link>
      <description>&lt;P&gt;I did not tested to add it there!&lt;/P&gt;
&lt;P&gt;Should I add it as an IP address or as FQDN like *.matematikxyz.com ?&lt;/P&gt;</description>
      <pubDate>Mon, 06 May 2024 15:17:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-not-surf-to-a-website/m-p/213311#M40608</guid>
      <dc:creator>Moudar</dc:creator>
      <dc:date>2024-05-06T15:17:02Z</dc:date>
    </item>
    <item>
      <title>Re: Can not surf to a website</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-not-surf-to-a-website/m-p/213316#M40611</link>
      <description>&lt;P&gt;I would do both.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 06 May 2024 15:28:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-not-surf-to-a-website/m-p/213316#M40611</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-05-06T15:28:01Z</dc:date>
    </item>
    <item>
      <title>Re: Can not surf to a website</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-not-surf-to-a-website/m-p/213320#M40612</link>
      <description>&lt;P&gt;I did both and did not get any hit on the rule!&lt;/P&gt;
&lt;P&gt;i have also tested&amp;nbsp;\/matematikxyz\.com and also no hit on the rule!&lt;/P&gt;</description>
      <pubDate>Mon, 06 May 2024 15:34:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-not-surf-to-a-website/m-p/213320#M40612</guid>
      <dc:creator>Moudar</dc:creator>
      <dc:date>2024-05-06T15:34:46Z</dc:date>
    </item>
    <item>
      <title>Re: Can not surf to a website</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-not-surf-to-a-website/m-p/213322#M40613</link>
      <description>&lt;P&gt;I would add *matematikxyz* and 208.86.159.100&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 06 May 2024 15:39:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-not-surf-to-a-website/m-p/213322#M40613</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-05-06T15:39:37Z</dc:date>
    </item>
    <item>
      <title>Re: Can not surf to a website</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-not-surf-to-a-website/m-p/213324#M40614</link>
      <description>&lt;P&gt;One thing I found super useful with these issues is press F12 when going to the site, so it gives you developer browser tool, it may show you if its trying to reach something else as well.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 06 May 2024 15:54:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-not-surf-to-a-website/m-p/213324#M40614</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-05-06T15:54:17Z</dc:date>
    </item>
    <item>
      <title>Re: Can not surf to a website</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-not-surf-to-a-website/m-p/213327#M40616</link>
      <description>&lt;P&gt;tried both and not get a hit!&lt;/P&gt;</description>
      <pubDate>Mon, 06 May 2024 16:05:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-not-surf-to-a-website/m-p/213327#M40616</guid>
      <dc:creator>Moudar</dc:creator>
      <dc:date>2024-05-06T16:05:10Z</dc:date>
    </item>
    <item>
      <title>Re: Can not surf to a website</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-not-surf-to-a-website/m-p/213329#M40617</link>
      <description>&lt;P&gt;cannot find weird things there!&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 06 May 2024 16:08:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-not-surf-to-a-website/m-p/213329#M40617</guid>
      <dc:creator>Moudar</dc:creator>
      <dc:date>2024-05-06T16:08:02Z</dc:date>
    </item>
    <item>
      <title>Re: Can not surf to a website</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-not-surf-to-a-website/m-p/213330#M40618</link>
      <description>&lt;P&gt;If you filter logs for that destination IP, just do nslookup, make sure it resolved to same IP, what do you see?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 06 May 2024 16:14:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-not-surf-to-a-website/m-p/213330#M40618</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-05-06T16:14:17Z</dc:date>
    </item>
    <item>
      <title>Re: Can not surf to a website</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-not-surf-to-a-website/m-p/213349#M40628</link>
      <description>&lt;P&gt;Let's start with basic information like: Version and JHF level of gateway and maangement.&lt;BR /&gt;The exact rules used to allow the traffic (with custom service definitions shown).&lt;BR /&gt;What shows in the access logs when you attempt to access these sites (full log card, not just the line in the logs list).&lt;/P&gt;
&lt;P&gt;Please provide screenshots where appropriate and redact sensitive details.&lt;/P&gt;</description>
      <pubDate>Mon, 06 May 2024 17:40:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-not-surf-to-a-website/m-p/213349#M40628</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-05-06T17:40:23Z</dc:date>
    </item>
    <item>
      <title>Re: Can not surf to a website</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-not-surf-to-a-website/m-p/213354#M40630</link>
      <description>&lt;P&gt;I found this interesting thing on the log:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="terminated.JPG" style="width: 745px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/25550i66A205E91FB4B034/image-size/large?v=v2&amp;amp;px=999" role="button" title="terminated.JPG" alt="terminated.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Product version Check Point Gaia R81.20&lt;BR /&gt;OS build 631&lt;BR /&gt;OS kernel version 3.10.0-1160.15.2cpx86_64&lt;BR /&gt;OS edition 64-bit&lt;/P&gt;</description>
      <pubDate>Mon, 06 May 2024 17:46:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-not-surf-to-a-website/m-p/213354#M40630</guid>
      <dc:creator>Moudar</dc:creator>
      <dc:date>2024-05-06T17:46:37Z</dc:date>
    </item>
    <item>
      <title>Re: Can not surf to a website</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-not-surf-to-a-website/m-p/213356#M40632</link>
      <description>&lt;P&gt;That sk is essentially long way of telling you 3 way handshake is not completing...so doing fw monitor with -F flag would probably help.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 06 May 2024 17:48:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-not-surf-to-a-website/m-p/213356#M40632</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-05-06T17:48:10Z</dc:date>
    </item>
    <item>
      <title>Re: Can not surf to a website</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-not-surf-to-a-website/m-p/213359#M40633</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="terminated1.JPG" style="width: 603px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/25551iE621FBD361FC5235/image-size/large?v=v2&amp;amp;px=999" role="button" title="terminated1.JPG" alt="terminated1.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;If the Access Rulebase does not reach a final match on accept, a log appears with a new unique rule specific for this case '&lt;/SPAN&gt;&lt;CODE&gt;CPNotEnoughDataForRuleMatch&lt;/CODE&gt;&lt;SPAN&gt;' and accept action. !&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 06 May 2024 17:51:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-not-surf-to-a-website/m-p/213359#M40633</guid>
      <dc:creator>Moudar</dc:creator>
      <dc:date>2024-05-06T17:51:07Z</dc:date>
    </item>
    <item>
      <title>Re: Can not surf to a website</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-not-surf-to-a-website/m-p/213360#M40634</link>
      <description>&lt;P&gt;how would the exact command look like?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 06 May 2024 17:51:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-not-surf-to-a-website/m-p/213360#M40634</guid>
      <dc:creator>Moudar</dc:creator>
      <dc:date>2024-05-06T17:51:59Z</dc:date>
    </item>
    <item>
      <title>Re: Can not surf to a website</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-not-surf-to-a-website/m-p/213361#M40635</link>
      <description>&lt;P&gt;Lets assume your PC ip is 10.10.10.10&lt;/P&gt;
&lt;P&gt;Idea is this fw monitor -F "srcip,srcport,dstip,dstport,protocol" -F "other way around"&lt;/P&gt;
&lt;P&gt;example:&lt;/P&gt;
&lt;P&gt;fw monitor -F "10.10.10.10,0,&lt;SPAN&gt;208.86.159.100,443,0" -F "208.86.159.100,0,10.10.10.10,443,0"&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;As you can see, I left src port and protocol as 0&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Just replace 10.10.10.10 with your actual internal IP&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Andy&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 06 May 2024 17:55:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-not-surf-to-a-website/m-p/213361#M40635</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-05-06T17:55:28Z</dc:date>
    </item>
  </channel>
</rss>

