<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: No access to Internet in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/No-access-to-Internet/m-p/95612#M18829</link>
    <description>&lt;P&gt;In R80.20+, disabling SecureXL isn’t required.&lt;BR /&gt;More specifically, SecureXL will automatically not accelerate PPPoE interfaces without requiring you to disable SecureXL entirely.&lt;/P&gt;</description>
    <pubDate>Sun, 30 Aug 2020 21:31:12 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2020-08-30T21:31:12Z</dc:date>
    <item>
      <title>No access to Internet</title>
      <link>https://community.checkpoint.com/t5/General-Topics/No-access-to-Internet/m-p/95599#M18823</link>
      <description>&lt;P&gt;Hello, Everyone!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have an issue with&amp;nbsp;Check Point Security Gateway&amp;nbsp;R80.10. Clients cannot access Internet resources (for example http/https web-pages), though they can ping External IPs and DNS (8.8.8.8 and google.com). I have default access policy as accept all, threat prevention policy is disabled, Automatic NAT. Looking for help to resolve this issue. For http/https traffic log shows accept, check screenshots below, thanks in advance.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="1.JPG" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/7834iECAF8BB96FCEBC04/image-size/large?v=v2&amp;amp;px=999" role="button" title="1.JPG" alt="1.JPG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2.JPG" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/7835i4029F97220C64EBE/image-size/large?v=v2&amp;amp;px=999" role="button" title="2.JPG" alt="2.JPG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="3.JPG" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/7833i00709E59EDACCB76/image-size/large?v=v2&amp;amp;px=999" role="button" title="3.JPG" alt="3.JPG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="4.JPG" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/7836iDD47519D7E3BC9AE/image-size/large?v=v2&amp;amp;px=999" role="button" title="4.JPG" alt="4.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 30 Aug 2020 12:53:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/No-access-to-Internet/m-p/95599#M18823</guid>
      <dc:creator>buridango</dc:creator>
      <dc:date>2020-08-30T12:53:54Z</dc:date>
    </item>
    <item>
      <title>Re: No access to Internet</title>
      <link>https://community.checkpoint.com/t5/General-Topics/No-access-to-Internet/m-p/95602#M18824</link>
      <description>&lt;P&gt;If ping works but nothing else, it usually means other traffic is being denied by your APCL/URLF layer.&amp;nbsp; Ping is not an application (and need only match a rule in the Network/Firewall policy layer) but practically everything else including DNS is.&amp;nbsp; Click the Matched Rules tab on your log card.&lt;/P&gt;
&lt;P&gt;Beyond that run&amp;nbsp;&lt;STRONG&gt;fw ctl zdebug drop&lt;/STRONG&gt; and try to pass some traffic.&amp;nbsp; If you don't see a drop in that output it is a routing (or possibly NAT) issue of some kind.&lt;/P&gt;</description>
      <pubDate>Mon, 31 Aug 2020 00:43:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/No-access-to-Internet/m-p/95602#M18824</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2020-08-31T00:43:12Z</dc:date>
    </item>
    <item>
      <title>Re: No access to Internet</title>
      <link>https://community.checkpoint.com/t5/General-Topics/No-access-to-Internet/m-p/95606#M18825</link>
      <description>&lt;P&gt;Or a little bit more important they cannot do DNS... try to ping &lt;A href="http://www.google.com" target="_blank"&gt;www.google.com&lt;/A&gt;&amp;nbsp;and see if it resolves.&lt;/P&gt;</description>
      <pubDate>Sun, 30 Aug 2020 17:26:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/No-access-to-Internet/m-p/95606#M18825</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2020-08-30T17:26:05Z</dc:date>
    </item>
    <item>
      <title>Re: No access to Internet</title>
      <link>https://community.checkpoint.com/t5/General-Topics/No-access-to-Internet/m-p/95608#M18826</link>
      <description>&lt;P&gt;Thanks for Reply, Timothy&lt;/P&gt;&lt;P&gt;I issued command&amp;nbsp;&lt;STRONG&gt;fw ctl zdebug drop&lt;/STRONG&gt; and there drops fom one address subnet I don't have:&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;;[cpu_3];[fw4_0];fw_log_drop_ex: Packet proto=6 178.34.109.191:10400 -&amp;gt; 173.194.73.95:443 dropped by cphwd_offload_connkey Reason: VPN and/or NAT traffic between accelerated and non-accelerated interfaces or between non-accelerated interfaces is not allowed;&lt;BR /&gt;;[cpu_3];[fw4_0];fw_log_drop_ex: Packet proto=6 178.34.109.191:10401 -&amp;gt; 108.177.14.101:443 dropped by cphwd_offload_connkey Reason: VPN and/or NAT traffic between accelerated and non-accelerated interfaces or between non-accelerated interfaces is not allowed;&lt;BR /&gt;;[cpu_3];[fw4_0];fw_log_drop_ex: Packet proto=6 178.34.109.191:10399 -&amp;gt; 162.159.129.233:443 dropped by cphwd_offload_connkey Reason: VPN and/or NAT traffic between accelerated and non-accelerated interfaces or between non-accelerated interfaces is not allowed;&lt;BR /&gt;;[cpu_3];[fw4_0];fw_log_drop_ex: Packet proto=6 178.34.109.191:10400 -&amp;gt; 173.194.73.95:443 dropped by cphwd_offload_connkey Reason: VPN and/or NAT traffic between accelerated and non-accelerated interfaces or between non-accelerated interfaces is not allowed;&lt;BR /&gt;;[cpu_3];[fw4_0];fw_log_drop_ex: Packet proto=6 178.34.109.191:10402 -&amp;gt; 35.186.224.47:443 dropped by cphwd_offload_connkey Reason: VPN and/or NAT traffic between accelerated and non-accelerated interfaces or between non-accelerated interfaces is not allowed;&lt;BR /&gt;;[cpu_3];[fw4_0];fw_log_drop_ex: Packet proto=6 178.34.109.191:10396 -&amp;gt; 173.194.73.95:443 dropped by cphwd_offload_connkey Reason: VPN and/or NAT traffic between accelerated and non-accelerated interfaces or between non-accelerated interfaces is not allowed;&lt;BR /&gt;Defaulting all kernel debugging options&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here tab matched rules&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="5.JPG" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/7837i9F0B57E81CDA00CD/image-size/large?v=v2&amp;amp;px=999" role="button" title="5.JPG" alt="5.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 30 Aug 2020 18:58:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/No-access-to-Internet/m-p/95608#M18826</guid>
      <dc:creator>buridango</dc:creator>
      <dc:date>2020-08-30T18:58:03Z</dc:date>
    </item>
    <item>
      <title>Re: No access to Internet</title>
      <link>https://community.checkpoint.com/t5/General-Topics/No-access-to-Internet/m-p/95609#M18827</link>
      <description>&lt;P&gt;Thanks for Reply.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As I mentioned earlier, icmp available by IP and DNS, so this is not a problem.&lt;/P&gt;</description>
      <pubDate>Sun, 30 Aug 2020 18:58:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/No-access-to-Internet/m-p/95609#M18827</guid>
      <dc:creator>buridango</dc:creator>
      <dc:date>2020-08-30T18:58:48Z</dc:date>
    </item>
    <item>
      <title>Re: No access to Internet</title>
      <link>https://community.checkpoint.com/t5/General-Topics/No-access-to-Internet/m-p/95610#M18828</link>
      <description>&lt;P&gt;Okay, I found solution. I have PPPoE and Checkpoint has something called SecureXL wich is in conflict, I disabled and everything is working now.&lt;/P&gt;</description>
      <pubDate>Sun, 30 Aug 2020 19:04:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/No-access-to-Internet/m-p/95610#M18828</guid>
      <dc:creator>buridango</dc:creator>
      <dc:date>2020-08-30T19:04:41Z</dc:date>
    </item>
    <item>
      <title>Re: No access to Internet</title>
      <link>https://community.checkpoint.com/t5/General-Topics/No-access-to-Internet/m-p/95612#M18829</link>
      <description>&lt;P&gt;In R80.20+, disabling SecureXL isn’t required.&lt;BR /&gt;More specifically, SecureXL will automatically not accelerate PPPoE interfaces without requiring you to disable SecureXL entirely.&lt;/P&gt;</description>
      <pubDate>Sun, 30 Aug 2020 21:31:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/No-access-to-Internet/m-p/95612#M18829</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-08-30T21:31:12Z</dc:date>
    </item>
    <item>
      <title>Re: No access to Internet</title>
      <link>https://community.checkpoint.com/t5/General-Topics/No-access-to-Internet/m-p/95635#M18831</link>
      <description>&lt;P&gt;In fact, you cannot completely disable SXL in R80.20+ anymore&lt;/P&gt;</description>
      <pubDate>Mon, 31 Aug 2020 06:37:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/No-access-to-Internet/m-p/95635#M18831</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2020-08-31T06:37:08Z</dc:date>
    </item>
  </channel>
</rss>

