<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Bug or something other in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Bug-or-something-other/m-p/228758#M44047</link>
    <description>&lt;P&gt;The action on the log says "Accept."&lt;BR /&gt;When you say "nobody can access the Internet" what is the exact behavior? (i.e. what is seen by end users)&lt;/P&gt;
&lt;P&gt;In any case, the error message itself isn't necessarily indicative of a problem.&lt;BR /&gt;However, if there is an actual issue that can be resolved by uninstalling the relevant JHF, then you'll need to consult with TAC.&lt;/P&gt;</description>
    <pubDate>Wed, 02 Oct 2024 14:40:31 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2024-10-02T14:40:31Z</dc:date>
    <item>
      <title>Bug or something other</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Bug-or-something-other/m-p/228633#M43997</link>
      <description>&lt;P&gt;Hello, I have a version R81.20 Jumbo Hotfix Take 76 on my gateways in ClusterXL, but when I have upgraded it to a Take 84 (recommended version) I get some issues regarding internet access.&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF0000"&gt;Connection terminated before the Security Gateway was able to make a decision: Insufficient data passed.&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;To learn more see sk113479.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;It seems like issue with policy match.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;I have inline layer created for internet access (rule ID: 79). Instead of connections match rule 79.15 they match rule 79.&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;I didn't find a cause of the problem and I have downgrade to Hotfix Take 76&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How to resolve problem?&lt;/P&gt;</description>
      <pubDate>Tue, 01 Oct 2024 14:24:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Bug-or-something-other/m-p/228633#M43997</guid>
      <dc:creator>babicmilan</dc:creator>
      <dc:date>2024-10-01T14:24:10Z</dc:date>
    </item>
    <item>
      <title>Re: Bug or something other</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Bug-or-something-other/m-p/228655#M43998</link>
      <description>&lt;P&gt;This error message is considered "normal" and a function of how modern application-aware firewalls operate.&lt;BR /&gt;In short:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;On first packet, you only know source/destination/service from an IP header perspective.&lt;/LI&gt;
&lt;LI&gt;Additional packets are required to fully classify the traffic (e.g. we need to see HTTP headers or information not available in the first packet).&lt;/LI&gt;
&lt;LI&gt;Assuming there's at least ONE accept rule on the relevant port, traffic will be allowed until the traffic can be properly classified.&lt;/LI&gt;
&lt;LI&gt;If the underlying connection closes before classification occurs, you will see the error you mention.&amp;nbsp;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Again, this is expected behavior and documented in the referenced SK:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk113479" target="_blank" rel="noopener"&gt;https://support.checkpoint.com/results/sk/sk113479&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The fact you rolled back begs the question: were&amp;nbsp;your users experiencing any actual issues as a result of these errors?&lt;/P&gt;</description>
      <pubDate>Tue, 01 Oct 2024 15:50:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Bug-or-something-other/m-p/228655#M43998</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-10-01T15:50:46Z</dc:date>
    </item>
    <item>
      <title>Re: Bug or something other</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Bug-or-something-other/m-p/228696#M44032</link>
      <description>&lt;P&gt;The way I always put it, that sk is literally a long way of saying 3 way handshake is not completing and firewall is not a problem. It simply does not have enough data to classify such a connection, and though you may see the actual drop in the log, thats not technically the case.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 01 Oct 2024 23:09:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Bug-or-something-other/m-p/228696#M44032</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-10-01T23:09:06Z</dc:date>
    </item>
    <item>
      <title>Re: Bug or something other</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Bug-or-something-other/m-p/228716#M44039</link>
      <description>&lt;P&gt;Look at this pictures. When problem occurs, nobody can access the internet. Policy say that rule 79 is matched (rule 79 is inline layer). It must be matched rule 79.11 to allow access the internet.&lt;/P&gt;&lt;P&gt;I don't know, maybe is something wrong with Gaia OS, I think to reinstall Gaia OS.&lt;/P&gt;</description>
      <pubDate>Wed, 02 Oct 2024 08:08:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Bug-or-something-other/m-p/228716#M44039</guid>
      <dc:creator>babicmilan</dc:creator>
      <dc:date>2024-10-02T08:08:58Z</dc:date>
    </item>
    <item>
      <title>Re: Bug or something other</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Bug-or-something-other/m-p/228730#M44043</link>
      <description>&lt;P&gt;Vidio sam slike : - )&lt;/P&gt;
&lt;P&gt;Trust me, its NOT the firewall issue mate. Just carefully read the sk itself.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 02 Oct 2024 11:44:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Bug-or-something-other/m-p/228730#M44043</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-10-02T11:44:02Z</dc:date>
    </item>
    <item>
      <title>Re: Bug or something other</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Bug-or-something-other/m-p/228758#M44047</link>
      <description>&lt;P&gt;The action on the log says "Accept."&lt;BR /&gt;When you say "nobody can access the Internet" what is the exact behavior? (i.e. what is seen by end users)&lt;/P&gt;
&lt;P&gt;In any case, the error message itself isn't necessarily indicative of a problem.&lt;BR /&gt;However, if there is an actual issue that can be resolved by uninstalling the relevant JHF, then you'll need to consult with TAC.&lt;/P&gt;</description>
      <pubDate>Wed, 02 Oct 2024 14:40:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Bug-or-something-other/m-p/228758#M44047</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-10-02T14:40:31Z</dc:date>
    </item>
  </channel>
</rss>

