<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: About &amp;quot;CPNotEnoughDataForRuleMatch&amp;quot; and connection reset in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/About-quot-CPNotEnoughDataForRuleMatch-quot-and-connection-reset/m-p/241721#M46927</link>
    <description>&lt;P&gt;Yes, it's the use of the Custom Application/Site object that is causing the "problem" (which is actually by design).&lt;BR /&gt;More specifically, it appears to be the first "potential match" rule, which means it might impact multiple flows.&lt;BR /&gt;See how Column-Based Rule Matching works:&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/Management/Unified-Policy-Column-based-Rule-Matching/m-p/9888#M1693" target="_blank"&gt;https://community.checkpoint.com/t5/Management/Unified-Policy-Column-based-Rule-Matching/m-p/9888#M1693&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This may not be an issue of "more rules" but one of rule order, depending on what the precise nature of the traffic is and what rules you have.&lt;/P&gt;</description>
    <pubDate>Wed, 19 Feb 2025 19:08:52 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2025-02-19T19:08:52Z</dc:date>
    <item>
      <title>About "CPNotEnoughDataForRuleMatch" and connection reset</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/About-quot-CPNotEnoughDataForRuleMatch-quot-and-connection-reset/m-p/240388#M46630</link>
      <description>&lt;P&gt;Hi there,&lt;/P&gt;&lt;P&gt;I've (partly) asked about this before (&lt;A href="https://community.checkpoint.com/t5/Security-Gateways/quot-CPNotEnoughDataForRuleMatch-quot-and-quot-Connection/m-p/230551/thread-id/44356" target="_blank"&gt;https://community.checkpoint.com/t5/Security-Gateways/quot-CPNotEnoughDataForRuleMatch-quot-and-quot-Connection/m-p/230551/thread-id/44356&lt;/A&gt;), but now I have another related question regarding this behvavior.&lt;/P&gt;&lt;P&gt;I have a service that connects to an external ip address, but every time the connection gets terminated by a reset from the destination. The log in my firewall says "Accept", however, it is getting&amp;nbsp; "terminated before the Security Gateway was able to make a decision: No SSL applicative data."&amp;nbsp; ("CPNotEnoughDataForRuleMatch").&lt;/P&gt;&lt;P&gt;As I got told in my other post (see link above) the behavior is by design and expected, however, I do have a question to why it happens.&lt;/P&gt;&lt;P&gt;The connection in question gets HTTPS Inspected and the log is as follows:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="httpsi.jpg" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/29516i707156E4A6E1511B/image-size/large?v=v2&amp;amp;px=999" role="button" title="httpsi.jpg" alt="httpsi.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;And the "Accept" ("CPNotEnoughDataForRuleMatch") log looks as below:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="accept.jpg" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/29518i9AE4D8059233533E/image-size/large?v=v2&amp;amp;px=999" role="button" title="accept.jpg" alt="accept.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I tried to establish the connection with a Wireshark running on the client (not the firewall) and as far as I can see the handshake completes, but then it gets disconnected by a reset from the destination:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ws.jpg" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/29519i801D882AD6EBAE18/image-size/large?v=v2&amp;amp;px=999" role="button" title="ws.jpg" alt="ws.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I have the same service on another endpoint WITHOUT HTTPS Inspection and there it connects fine.&lt;/P&gt;&lt;P&gt;So my question is: Is it possible that the packet somehow gets "malformed" in the HTTPS Inspection process and therefore the destination sends a reset back to us and kills the connection? Or is something different going on? I really can't figure it out!&lt;/P&gt;&lt;P&gt;Looking forward to your comments &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 04 Feb 2025 15:47:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/About-quot-CPNotEnoughDataForRuleMatch-quot-and-connection-reset/m-p/240388#M46630</guid>
      <dc:creator>JPR</dc:creator>
      <dc:date>2025-02-04T15:47:45Z</dc:date>
    </item>
    <item>
      <title>Re: About "CPNotEnoughDataForRuleMatch" and connection reset</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/About-quot-CPNotEnoughDataForRuleMatch-quot-and-connection-reset/m-p/240457#M46642</link>
      <description>&lt;P&gt;The error states there is no data in the connection, that is true according to the capture so the error is valid.&amp;nbsp;&lt;BR /&gt;You state without https inspection connections it works so we should focus on that. Could start is to see if the chosen encryption ciphers are accepted on both sides. In the capture the source is the fw right? That is starting with syn?&lt;/P&gt;</description>
      <pubDate>Wed, 05 Feb 2025 11:51:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/About-quot-CPNotEnoughDataForRuleMatch-quot-and-connection-reset/m-p/240457#M46642</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2025-02-05T11:51:09Z</dc:date>
    </item>
    <item>
      <title>Re: About "CPNotEnoughDataForRuleMatch" and connection reset</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/About-quot-CPNotEnoughDataForRuleMatch-quot-and-connection-reset/m-p/240508#M46655</link>
      <description>&lt;P&gt;No, that's the client. I haven't done a capture on the firewall.&lt;/P&gt;&lt;P&gt;It seems like the Handshake and thus cipher suites goes through and it is after that, that the destination endpoint sends a reset packet. I just can't figure out why.&lt;/P&gt;&lt;P&gt;And again if I bypass HTTPSi it works, so my theory was that it had something to do with that...&lt;/P&gt;</description>
      <pubDate>Wed, 05 Feb 2025 16:48:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/About-quot-CPNotEnoughDataForRuleMatch-quot-and-connection-reset/m-p/240508#M46655</guid>
      <dc:creator>JPR</dc:creator>
      <dc:date>2025-02-05T16:48:10Z</dc:date>
    </item>
    <item>
      <title>Re: About "CPNotEnoughDataForRuleMatch" and connection reset</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/About-quot-CPNotEnoughDataForRuleMatch-quot-and-connection-reset/m-p/240514#M46656</link>
      <description>&lt;P&gt;Check out below links, hope it helps. In short, this is literally never CP issue, as 3 way handshake is not completing, but its not because of the fw, but rather the fact that server did not send back syn-ack.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/Security-Gateways/quot-CPNotEnoughDataForRuleMatch-quot-and-quot-Connection/m-p/230551#M44356" target="_blank"&gt;https://community.checkpoint.com/t5/Security-Gateways/quot-CPNotEnoughDataForRuleMatch-quot-and-quot-Connection/m-p/230551#M44356&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/General-Topics/When-does-CPEarlyDrop-occur-with-ACCPET-action/m-p/216402#M35976" target="_blank"&gt;https://community.checkpoint.com/t5/General-Topics/When-does-CPEarlyDrop-occur-with-ACCPET-action/m-p/216402#M35976&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 05 Feb 2025 17:29:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/About-quot-CPNotEnoughDataForRuleMatch-quot-and-connection-reset/m-p/240514#M46656</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-02-05T17:29:01Z</dc:date>
    </item>
    <item>
      <title>Re: About "CPNotEnoughDataForRuleMatch" and connection reset</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/About-quot-CPNotEnoughDataForRuleMatch-quot-and-connection-reset/m-p/240582#M46677</link>
      <description>&lt;P&gt;I just don't understand why it then works if I bypass HTTPSi... &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Feb 2025 11:47:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/About-quot-CPNotEnoughDataForRuleMatch-quot-and-connection-reset/m-p/240582#M46677</guid>
      <dc:creator>JPR</dc:creator>
      <dc:date>2025-02-06T11:47:26Z</dc:date>
    </item>
    <item>
      <title>Re: About "CPNotEnoughDataForRuleMatch" and connection reset</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/About-quot-CPNotEnoughDataForRuleMatch-quot-and-connection-reset/m-p/240583#M46678</link>
      <description>&lt;P&gt;Like&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/73547"&gt;@Lesley&lt;/a&gt;&amp;nbsp;said, you should check from the gateway (specifically from the gateway to the remote site) with tcpdump.&lt;/P&gt;</description>
      <pubDate>Thu, 06 Feb 2025 12:02:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/About-quot-CPNotEnoughDataForRuleMatch-quot-and-connection-reset/m-p/240583#M46678</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-02-06T12:02:05Z</dc:date>
    </item>
    <item>
      <title>Re: About "CPNotEnoughDataForRuleMatch" and connection reset</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/About-quot-CPNotEnoughDataForRuleMatch-quot-and-connection-reset/m-p/240587#M46679</link>
      <description>&lt;P&gt;But then it sounds like its httpsi issue...&lt;/P&gt;</description>
      <pubDate>Thu, 06 Feb 2025 12:16:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/About-quot-CPNotEnoughDataForRuleMatch-quot-and-connection-reset/m-p/240587#M46679</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-02-06T12:16:21Z</dc:date>
    </item>
    <item>
      <title>Re: About "CPNotEnoughDataForRuleMatch" and connection reset</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/About-quot-CPNotEnoughDataForRuleMatch-quot-and-connection-reset/m-p/240590#M46680</link>
      <description>&lt;P&gt;Now that I think about it, say if you have httpsi enabled, you can always add bypass rule for affected IPs/destinations.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 06 Feb 2025 20:42:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/About-quot-CPNotEnoughDataForRuleMatch-quot-and-connection-reset/m-p/240590#M46680</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-02-06T20:42:55Z</dc:date>
    </item>
    <item>
      <title>Re: About "CPNotEnoughDataForRuleMatch" and connection reset</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/About-quot-CPNotEnoughDataForRuleMatch-quot-and-connection-reset/m-p/240651#M46686</link>
      <description>&lt;P&gt;Focus on checking HTTPS inspection part, not the&amp;nbsp;&lt;SPAN&gt;CPNotEnoughDataForRuleMatch error.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;HTTPS inspection can go wrong between client &amp;lt;-&amp;gt; FW or FW &amp;lt;-&amp;gt; remote server&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Mismatch in ciphers but also CA that is not up to date on FW.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Feb 2025 18:40:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/About-quot-CPNotEnoughDataForRuleMatch-quot-and-connection-reset/m-p/240651#M46686</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2025-02-06T18:40:13Z</dc:date>
    </item>
    <item>
      <title>Re: About "CPNotEnoughDataForRuleMatch" and connection reset</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/About-quot-CPNotEnoughDataForRuleMatch-quot-and-connection-reset/m-p/240674#M46694</link>
      <description>&lt;P&gt;Yeah, you're right.&lt;/P&gt;&lt;P&gt;Are there any way of troubleshooting that myself or should I involve TAC? And is it okay to bypass destinations that causes problems? Obviously, it wont perform HTTPS Inspection on traffic between whatever source and destination hosts I have defined, but is it a known issue that HTTPSi in some situations will break the connection? It is not a general problem, but I do experience it occasionally.&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Fri, 07 Feb 2025 09:02:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/About-quot-CPNotEnoughDataForRuleMatch-quot-and-connection-reset/m-p/240674#M46694</guid>
      <dc:creator>JPR</dc:creator>
      <dc:date>2025-02-07T09:02:38Z</dc:date>
    </item>
    <item>
      <title>Re: About "CPNotEnoughDataForRuleMatch" and connection reset</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/About-quot-CPNotEnoughDataForRuleMatch-quot-and-connection-reset/m-p/240683#M46695</link>
      <description>&lt;P&gt;Yea, you said it exactly how I would put it. Not a generic problem, but it happens from time to time. Well...if destination causes problems, then I would NOT bypass it, better to involve TAC. However, if it does not cause issues, I would do it.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 07 Feb 2025 12:13:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/About-quot-CPNotEnoughDataForRuleMatch-quot-and-connection-reset/m-p/240683#M46695</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-02-07T12:13:11Z</dc:date>
    </item>
    <item>
      <title>Re: About "CPNotEnoughDataForRuleMatch" and connection reset</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/About-quot-CPNotEnoughDataForRuleMatch-quot-and-connection-reset/m-p/240700#M46697</link>
      <description>&lt;P&gt;Well, it happens all the time for this specific destination and for now I have just created a bypass rule for it. I will consider getting TAC involved.&lt;/P&gt;&lt;P&gt;Thanks &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Feb 2025 14:55:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/About-quot-CPNotEnoughDataForRuleMatch-quot-and-connection-reset/m-p/240700#M46697</guid>
      <dc:creator>JPR</dc:creator>
      <dc:date>2025-02-07T14:55:00Z</dc:date>
    </item>
    <item>
      <title>Re: About "CPNotEnoughDataForRuleMatch" and connection reset</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/About-quot-CPNotEnoughDataForRuleMatch-quot-and-connection-reset/m-p/240701#M46698</link>
      <description>&lt;P&gt;sounds good!&lt;/P&gt;</description>
      <pubDate>Fri, 07 Feb 2025 14:57:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/About-quot-CPNotEnoughDataForRuleMatch-quot-and-connection-reset/m-p/240701#M46698</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-02-07T14:57:05Z</dc:date>
    </item>
    <item>
      <title>Re: About "CPNotEnoughDataForRuleMatch" and connection reset</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/About-quot-CPNotEnoughDataForRuleMatch-quot-and-connection-reset/m-p/240967#M46734</link>
      <description>&lt;P&gt;Hey&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/89831"&gt;@JPR&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any updates from TAC?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 12 Feb 2025 01:11:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/About-quot-CPNotEnoughDataForRuleMatch-quot-and-connection-reset/m-p/240967#M46734</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-02-12T01:11:31Z</dc:date>
    </item>
    <item>
      <title>Re: About "CPNotEnoughDataForRuleMatch" and connection reset</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/About-quot-CPNotEnoughDataForRuleMatch-quot-and-connection-reset/m-p/241000#M46745</link>
      <description>&lt;P&gt;Hey,&lt;/P&gt;&lt;P&gt;Thanks for asking, but haven't gotten so far yet. Already have a couple TAC cases regarding some other stuff, so just waiting on those to get done before I open new ones &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Feb 2025 09:06:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/About-quot-CPNotEnoughDataForRuleMatch-quot-and-connection-reset/m-p/241000#M46745</guid>
      <dc:creator>JPR</dc:creator>
      <dc:date>2025-02-12T09:06:10Z</dc:date>
    </item>
    <item>
      <title>Re: About "CPNotEnoughDataForRuleMatch" and connection reset</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/About-quot-CPNotEnoughDataForRuleMatch-quot-and-connection-reset/m-p/241015#M46753</link>
      <description>&lt;P&gt;No worries, just keep us posted when you do.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 12 Feb 2025 12:04:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/About-quot-CPNotEnoughDataForRuleMatch-quot-and-connection-reset/m-p/241015#M46753</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-02-12T12:04:01Z</dc:date>
    </item>
    <item>
      <title>Re: About "CPNotEnoughDataForRuleMatch" and connection reset</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/About-quot-CPNotEnoughDataForRuleMatch-quot-and-connection-reset/m-p/241378#M46855</link>
      <description>&lt;P&gt;I haven't been in contact with TAC, however, I tried enabling the extra logging as explained here:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk113479" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk113479&lt;/A&gt;&lt;/P&gt;&lt;P&gt;When doing that and then telnetting to an ip on 443 that gives me the "CpNotEnoughDataForRuleMatch" I get this expanded explanation:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="er1.png" style="width: 386px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/29627iFFF563BE3EFB06DA/image-size/large?v=v2&amp;amp;px=999" role="button" title="er1.png" alt="er1.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I'm not sure I fully understand what it means, even after reading the explanation in the aforementioned SK.&lt;/P&gt;&lt;P&gt;Then I tried disabling rule 153 it mentions as a first possible rule match, but then it just says the next rule (154) is the first possible rule match. What those rules have in common, though, is that the source is a Network Group that consist of various hosts, networks and other network groups.&lt;/P&gt;&lt;P&gt;So to try to figure out if that particular group was the culprit, I created a new rule above the first instance where that group was used as source now with a single host as source and that particular ip (the one that otherwise fails with "CpNotEnoughDataForRuleMatch") as destination and action as Accept - and now it works, no error or anything!&lt;/P&gt;&lt;P&gt;It seems as that Network Group is what is causing this issue, but I can't figure out why. Do any of you have an idea as to why that could be the case? It is a group that are being used in many rules and generally it doesn't seem to cause any issues.&lt;/P&gt;&lt;P&gt;Looking forward to your ideas! &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 17 Feb 2025 14:57:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/About-quot-CPNotEnoughDataForRuleMatch-quot-and-connection-reset/m-p/241378#M46855</guid>
      <dc:creator>JPR</dc:creator>
      <dc:date>2025-02-17T14:57:11Z</dc:date>
    </item>
    <item>
      <title>Re: About "CPNotEnoughDataForRuleMatch" and connection reset</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/About-quot-CPNotEnoughDataForRuleMatch-quot-and-connection-reset/m-p/241379#M46856</link>
      <description>&lt;P&gt;Its essentially the same thing &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Its long way of saying 3 way handshake is NOT completing, but its not the fw issue.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 17 Feb 2025 15:02:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/About-quot-CPNotEnoughDataForRuleMatch-quot-and-connection-reset/m-p/241379#M46856</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-02-17T15:02:36Z</dc:date>
    </item>
    <item>
      <title>Re: About "CPNotEnoughDataForRuleMatch" and connection reset</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/About-quot-CPNotEnoughDataForRuleMatch-quot-and-connection-reset/m-p/241381#M46857</link>
      <description>&lt;P&gt;Ok, but how do you conclude it isn't a fw issue?&lt;/P&gt;&lt;P&gt;If that host is a member of that network group the conncetion fails with&amp;nbsp;&lt;SPAN&gt;"CpNotEnoughDataForRuleMatch". If I make a specific rule with that host (not part of a group), it works, and I don't get the&amp;nbsp;"CpNotEnoughDataForRuleMatch". To me it really does seem like a fw issue, but there might be something I don't get &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 17 Feb 2025 15:08:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/About-quot-CPNotEnoughDataForRuleMatch-quot-and-connection-reset/m-p/241381#M46857</guid>
      <dc:creator>JPR</dc:creator>
      <dc:date>2025-02-17T15:08:01Z</dc:date>
    </item>
    <item>
      <title>Re: About "CPNotEnoughDataForRuleMatch" and connection reset</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/About-quot-CPNotEnoughDataForRuleMatch-quot-and-connection-reset/m-p/241382#M46858</link>
      <description>&lt;P&gt;How do I know its not a fw issue? Valid question...my answer? Very easy &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Here is how...when you see that log, do tcpdump and/or fw monitor and follow the packet. 100% it will show you that connection is going through the fw, but its not coming back, meaning the other side is NOT responding with syn-ack.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 17 Feb 2025 15:10:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/About-quot-CPNotEnoughDataForRuleMatch-quot-and-connection-reset/m-p/241382#M46858</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-02-17T15:10:19Z</dc:date>
    </item>
  </channel>
</rss>

