<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Traffic dropped by Reason: PSL Drop: HTTP_DISPATCHER; in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Traffic-dropped-by-Reason-PSL-Drop-HTTP-DISPATCHER/m-p/13322#M2234</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Lots of things use PSL: App Control, IPS, Anti-Bot, and Anti-Malware among them.&lt;/P&gt;&lt;P&gt;The actual error messages might be helpful, but I suspect a TAC case might be in order.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 04 Dec 2018 23:16:08 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2018-12-04T23:16:08Z</dc:date>
    <item>
      <title>Traffic dropped by Reason: PSL Drop: HTTP_DISPATCHER;</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Traffic-dropped-by-Reason-PSL-Drop-HTTP-DISPATCHER/m-p/13321#M2233</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;fw ctl zdebug drop is showing this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;fwpslglue_chain Reason: PSL Drop: HTTP_DISPATCHER;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have no idea what HTTP_DISPATCHER is, just that its being dropped by the Passive Streaming Layer.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any ideas on what is causing these drops?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 Dec 2018 22:00:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Traffic-dropped-by-Reason-PSL-Drop-HTTP-DISPATCHER/m-p/13321#M2233</guid>
      <dc:creator>Paul_Mainhardt1</dc:creator>
      <dc:date>2018-12-04T22:00:20Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic dropped by Reason: PSL Drop: HTTP_DISPATCHER;</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Traffic-dropped-by-Reason-PSL-Drop-HTTP-DISPATCHER/m-p/13322#M2234</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Lots of things use PSL: App Control, IPS, Anti-Bot, and Anti-Malware among them.&lt;/P&gt;&lt;P&gt;The actual error messages might be helpful, but I suspect a TAC case might be in order.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 Dec 2018 23:16:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Traffic-dropped-by-Reason-PSL-Drop-HTTP-DISPATCHER/m-p/13322#M2234</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-12-04T23:16:08Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic dropped by Reason: PSL Drop: HTTP_DISPATCHER;</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Traffic-dropped-by-Reason-PSL-Drop-HTTP-DISPATCHER/m-p/13323#M2235</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi &lt;A href="https://community.checkpoint.com/migrated-users/53970"&gt;Paul&lt;/A&gt;,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think there is an TCP service protocol type problem after updating to R80.10/R80.20. I already had problems with supported protocol types after the update.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;DIV&gt;&lt;STRONG&gt;Symptoms&lt;/STRONG&gt;&lt;P&gt;Database contains services with an unsupported protocol type. For a list of supported protocols, please refer to sk103595" error during upgrade to R80 / R80.10 / R80.20.&lt;/P&gt;&lt;P&gt;The following protocol types are supported in services in R80 / R80.10 / R80.20 versions:&lt;/P&gt;&lt;P&gt;...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;HTTP&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN style="color: #000000;"&gt;HTTP_DISPATCHER&lt;/SPAN&gt; &lt;BR /&gt;&lt;/STRONG&gt;&lt;/LI&gt;&lt;LI&gt;HTTP_WEBSEC&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;P&gt;&lt;/P&gt;&lt;DIV class=""&gt;&lt;STRONG&gt;Solution&lt;/STRONG&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;P&gt;- Disable the HTTP_DISPATCHER protocol type. However, this has an impact on the http security of the TCP service and IPS.&lt;/P&gt;&lt;P&gt;- Then I would open a TAC case as described from &lt;A href="https://community.checkpoint.com/migrated-users/2075"&gt;Dameon&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;P&gt;Look at this SK:&lt;/P&gt;&lt;P&gt;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk103595" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk103595"&gt;"Database contains services with an unsupported protocol type. For a list of supported protocols, please refer to sk1035…&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;DIV&gt;&lt;P&gt;What is PSL?&lt;/P&gt;&lt;P&gt;PSL is an infrastructure layer, which provides stream reassembly for TCP connections.&lt;BR /&gt;&amp;nbsp;&amp;nbsp; -&amp;nbsp; The gateway makes sure that TCP data seen by the destination system is the same as seen by code above PSL.&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; - This layer handles packet reordering, congestion handling and is responsible for various security aspects of the TCP layer such as handling payload overlaps, some DoS attacks and others.&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; - The PSL layer is capable of receiving packets from the firewall chain and from SecureXL module.&lt;BR /&gt;&amp;nbsp;&amp;nbsp; -&amp;nbsp; The PSL layer serves as a middleman between the various security applications and the network packets. It provides the applications with a coherent stream of data to work with, free of various network problems or attacks&lt;BR /&gt;&amp;nbsp;&amp;nbsp; -&amp;nbsp; The PSL infrastructure is wrapped with well defined APIs called the Unified Streaming APIs which are used by the applications to register and access streamed data&lt;/P&gt;&lt;/DIV&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can find more informations to PSL in my articles:&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.checkpoint.com/docs/DOC-3073"&gt;R80.x Security Gateway Architecture (Content Inspection)&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.checkpoint.com/docs/DOC-3041"&gt;R80.x Security Gateway Architecture (Logical Packet Flow)&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Heiko&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Dec 2018 06:15:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Traffic-dropped-by-Reason-PSL-Drop-HTTP-DISPATCHER/m-p/13323#M2235</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2018-12-05T06:15:12Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic dropped by Reason: PSL Drop: HTTP_DISPATCHER;</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Traffic-dropped-by-Reason-PSL-Drop-HTTP-DISPATCHER/m-p/13324#M2236</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I had considered this possibility (FYI) but I think HTTP_DISPATCHER is used in a few other contexts independent of a service definition.&lt;/P&gt;&lt;P&gt;Again, the&amp;nbsp;actual messages from zdebug might&amp;nbsp;provide some additional insight.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Dec 2018 17:35:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Traffic-dropped-by-Reason-PSL-Drop-HTTP-DISPATCHER/m-p/13324#M2236</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-12-05T17:35:55Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic dropped by Reason: PSL Drop: HTTP_DISPATCHER;</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Traffic-dropped-by-Reason-PSL-Drop-HTTP-DISPATCHER/m-p/13325#M2237</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;These are the actual error logs (replaced src and dst ip address with XXXX and YYYY):&lt;/P&gt;&lt;P&gt;;[cpu_3];[fw4_0];fw_log_drop_ex: Packet proto=6 X.X.X.X:50421 -&amp;gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;Y.Y.Y.Y:8081 dropped by fwpslglue_chain Reason: PSL Drop: HTTP_DISPATCHER;&lt;BR /&gt;;[cpu_3];[fw4_0];fw_log_drop_ex: Packet proto=6&amp;nbsp;&lt;SPAN&gt;X.X.X.X:&lt;/SPAN&gt;50421 -&amp;gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;Y.Y.Y.Y:8081 dropped by fwpslglue_chain Reason: PSL Drop: HTTP_DISPATCHER;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Dec 2018 02:50:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Traffic-dropped-by-Reason-PSL-Drop-HTTP-DISPATCHER/m-p/13325#M2237</guid>
      <dc:creator>Paul_Mainhardt1</dc:creator>
      <dc:date>2018-12-07T02:50:41Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic dropped by Reason: PSL Drop: HTTP_DISPATCHER;</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Traffic-dropped-by-Reason-PSL-Drop-HTTP-DISPATCHER/m-p/13326#M2238</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please send a screenshot of your TCP service for port 8081.&lt;/P&gt;&lt;P&gt;Should look something like this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/76259_pastedImage_1.png" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Dec 2018 04:45:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Traffic-dropped-by-Reason-PSL-Drop-HTTP-DISPATCHER/m-p/13326#M2238</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-12-07T04:45:46Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic dropped by Reason: PSL Drop: HTTP_DISPATCHER;</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Traffic-dropped-by-Reason-PSL-Drop-HTTP-DISPATCHER/m-p/13327#M2239</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am also getting the exact same error for HTTPS traffic as well.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;;[cpu_1];[fw4_2];fw_log_drop_ex: Packet proto=6 X.X.X.X:49297 -&amp;gt; Y.Y.Y.Y:443 dropped by fwpslglue_chain Reason: PSL Drop: HTTP_DISPATCHER;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have also tried increasing the PSL buffer as per SK102455&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;# fw ctl get int psl_max_stream_segments&lt;BR /&gt;psl_max_stream_segments = 32772&lt;BR /&gt;# fw ctl get int psl_max_strip_window&lt;BR /&gt;psl_max_strip_window = 16780216&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Screenshots Below:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="TCP 8081" class="image-1 jive-image j-img-original" src="https://community.checkpoint.com/legacyfs/online/checkpoint/76260_Capture1.PNG" /&gt;&lt;IMG alt="" class="image-2 jive-image j-img-original" src="https://community.checkpoint.com/legacyfs/online/checkpoint/76261_Capture2.PNG" /&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="image-3 jive-image j-img-original" src="https://community.checkpoint.com/legacyfs/online/checkpoint/76262_Capture3.PNG" /&gt;&lt;IMG alt="" class="image-4 jive-image j-img-original" src="https://community.checkpoint.com/legacyfs/online/checkpoint/76263_Capture4.PNG" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Dec 2018 05:05:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Traffic-dropped-by-Reason-PSL-Drop-HTTP-DISPATCHER/m-p/13327#M2239</guid>
      <dc:creator>Paul_Mainhardt1</dc:creator>
      <dc:date>2018-12-07T05:05:22Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic dropped by Reason: PSL Drop: HTTP_DISPATCHER;</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Traffic-dropped-by-Reason-PSL-Drop-HTTP-DISPATCHER/m-p/13328#M2240</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Then it's probably an IPS or App Control signature that's triggering.&lt;/P&gt;&lt;P&gt;You can try updating to the latest IPS and App Control signatures and see if the issue goes away.&lt;/P&gt;&lt;P&gt;Otherwise, you should probably open a TAC case.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Dec 2018 05:18:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Traffic-dropped-by-Reason-PSL-Drop-HTTP-DISPATCHER/m-p/13328#M2240</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-12-07T05:18:08Z</dc:date>
    </item>
  </channel>
</rss>

