<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Problem with access to WebService in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Problem-with-access-to-WebService/m-p/189279#M31727</link>
    <description>&lt;P&gt;Im not 100% sure of the meaning of that message, but Im fairly certain it simply implies that 3-eay handshake is not completing. SYN-SYNACK-...nothing&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
    <pubDate>Fri, 11 Aug 2023 15:40:48 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2023-08-11T15:40:48Z</dc:date>
    <item>
      <title>Problem with access to WebService</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Problem-with-access-to-WebService/m-p/189276#M31724</link>
      <description>&lt;P&gt;Hello, everyone.&lt;/P&gt;
&lt;P&gt;We currently have a Cluster R81.10, in which we are having problems consuming a web service, which is on the Internet.&lt;/P&gt;
&lt;P&gt;The destination is the IP 38.43.137.39 (tied to the domain (apostillaconsulta.rree.gob.pe).&lt;/P&gt;
&lt;P&gt;In the logs, I see the following.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ERR2.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/22046i64CCCBBF12204A3B/image-size/large?v=v2&amp;amp;px=999" role="button" title="ERR2.png" alt="ERR2.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ERR1.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/22045i165E2E072A024997/image-size/large?v=v2&amp;amp;px=999" role="button" title="ERR1.png" alt="ERR1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;I do not see "dropped" packets in the logs,&lt;BR /&gt;What I see are "Accepted" packages, but when I check the LOG, it sends me to check the sk113479.&lt;/P&gt;
&lt;P&gt;My question is "why"?&lt;/P&gt;
&lt;P&gt;Has anyone had any similar experience?&lt;/P&gt;
&lt;P&gt;It is worth mentioning that on top of the Firewall Cluster we have, we have an AntiDDos service in the cloud.&lt;/P&gt;
&lt;P&gt;Can the AntiDDos be the cause of my client's network having the experience that the web service "does not load"?&lt;/P&gt;
&lt;P&gt;Greetings.&lt;/P&gt;</description>
      <pubDate>Fri, 11 Aug 2023 14:38:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Problem-with-access-to-WebService/m-p/189276#M31724</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2023-08-11T14:38:53Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with access to WebService</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Problem-with-access-to-WebService/m-p/189277#M31725</link>
      <description>&lt;P&gt;Hey bro,&lt;/P&gt;
&lt;P&gt;I remember working with customer once and TAC T3 guy was on the phone and we encountered exact same issue, related to same sk you provided. Its essentially fancy way of telling you its NOT cp issue lol&lt;/P&gt;
&lt;P&gt;Anyway, that time, turned out to be some service running on the other end that was preventing the connection.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 11 Aug 2023 14:58:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Problem-with-access-to-WebService/m-p/189277#M31725</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-08-11T14:58:44Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with access to WebService</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Problem-with-access-to-WebService/m-p/189278#M31726</link>
      <description>&lt;P&gt;I have read the contents of the SK, and it is clarifying the doubts, but I have a concern, with the famous "CPNotEnoughDataForRuleMatch".&lt;/P&gt;
&lt;P&gt;This, can it be an "informative" message only?&lt;/P&gt;
&lt;P&gt;I have working separate layers, FW layer + APPC&amp;amp;URLF layer.&lt;/P&gt;
&lt;P&gt;And at least the log, when I open it and check, in the APPC&amp;amp;URLF layer, it "matches" with the CPNotEnoughDataForRuleMatch message.&lt;/P&gt;</description>
      <pubDate>Fri, 11 Aug 2023 15:33:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Problem-with-access-to-WebService/m-p/189278#M31726</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2023-08-11T15:33:04Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with access to WebService</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Problem-with-access-to-WebService/m-p/189279#M31727</link>
      <description>&lt;P&gt;Im not 100% sure of the meaning of that message, but Im fairly certain it simply implies that 3-eay handshake is not completing. SYN-SYNACK-...nothing&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 11 Aug 2023 15:40:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Problem-with-access-to-WebService/m-p/189279#M31727</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-08-11T15:40:48Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with access to WebService</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Problem-with-access-to-WebService/m-p/222218#M37015</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;&amp;nbsp;and&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/82839"&gt;@Matlu&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is the same details:&lt;/P&gt;
&lt;P&gt;We have 12 cluster where in the most of the policy packages we follow the below layer wise rule:&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Layer 1: Network Rule&lt;BR /&gt;Layer 2: Application and URL Filtering Rule&lt;BR /&gt;Layer 3: Content Awareness Rule&lt;/P&gt;
&lt;P&gt;This is the below rule we configured in the one ABC Policy Package&lt;/P&gt;
&lt;P&gt;In Layer 1 Rule: Source:Any Network Objest,Destination:Any,Service:Any,Action:Accept&lt;BR /&gt;In Layer 2 Rule: Source:Any ,Destination:Any,Service:All Services Object(PORT:80,443,x),Action:Accept&lt;BR /&gt;In Layer 3 Rule: Create rule as per the compliance&lt;/P&gt;
&lt;P&gt;When we try to access the URL:&lt;A href="https://gem.gov.in/(IP:14.140.34.123" target="_blank"&gt;https://gem.gov.in/(IP:14.140.34.123&lt;/A&gt;) then we able to access the URL from one cluster but unable to access from the another cluster.&lt;/P&gt;
&lt;P&gt;FInd the below details the we get:&lt;/P&gt;
&lt;P&gt;In Layer 1 Rule: Implict Cleanup Action:Accept&lt;BR /&gt;In Layer 2 Rule: CPNotEnoughDataForRuleMatch Action:Accept&lt;BR /&gt;In Layer 3 Rule: CPNotEnoughDataForRuleMatch Action:Accept&lt;/P&gt;
&lt;P&gt;Now my question is that if the Default gateway is not the Checkpoint firewall then I check the internal L3 devicesand analyze the traffic&amp;nbsp; but if my source machine L3 is checkpoint firewall then still issue come or not? (My answer is YES)&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Also as final what is the solution recommendation?&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;My one plan is to create a rule on top and check the status. (Correct me If I am wrong)&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/25509"&gt;@Chinmaya_Naik&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jul 2024 10:26:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Problem-with-access-to-WebService/m-p/222218#M37015</guid>
      <dc:creator>Chinmaya_Naik</dc:creator>
      <dc:date>2024-07-30T10:26:53Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with access to WebService</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Problem-with-access-to-WebService/m-p/222223#M37016</link>
      <description>&lt;P&gt;There has been MANY posts about cpnotenoughdata message. In short, 99% of the time its NOT Check Point issue...essentialy, even if you read the sk about it, long story short, it pretty much tells you that firewall does not have enough data to pass that connection forward.&lt;/P&gt;
&lt;P&gt;See below, hope this helps.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/Security-Gateways/CPNotEnoughDataForRuleMatch/m-p/198942#M37254" target="_blank"&gt;https://community.checkpoint.com/t5/Security-Gateways/CPNotEnoughDataForRuleMatch/m-p/198942#M37254&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jul 2024 11:16:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Problem-with-access-to-WebService/m-p/222223#M37016</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-07-30T11:16:39Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with access to WebService</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Problem-with-access-to-WebService/m-p/222224#M37017</link>
      <description>&lt;P&gt;Thank you&amp;nbsp;&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But rule base optimization can resolved this issue?&lt;/P&gt;
&lt;P&gt;But as per my search also "F&lt;SPAN&gt;irewall does not have enough data to pass that connection forward"so its not a firewall issue right?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;But after some hour its automatically resolved why?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;We also enable the HTTPS inspection but my understand that HTTPS inspection is not the cause because other URL is acessable.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Some situation wher the Outlook Application is work properly but access through browser is not work getting the message "CPNotEnoughData" or some cluster "CPEarly Drop".&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Please help me I need to understand echnically then its Great.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Regards&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/25509"&gt;@Chinmaya_Naik&lt;/a&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jul 2024 11:32:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Problem-with-access-to-WebService/m-p/222224#M37017</guid>
      <dc:creator>Chinmaya_Naik</dc:creator>
      <dc:date>2024-07-30T11:32:58Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with access to WebService</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Problem-with-access-to-WebService/m-p/222226#M37018</link>
      <description>&lt;P&gt;You can try that, but cant guarantee it will work, as usually that message indicates firewall is NOT dropping anything.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jul 2024 11:47:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Problem-with-access-to-WebService/m-p/222226#M37018</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-07-30T11:47:00Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with access to WebService</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Problem-with-access-to-WebService/m-p/222290#M37028</link>
      <description>&lt;P&gt;The only way to avoid this issue entirely is to ensure the relevant traffic is accepted on a service that a simple TCP service early in the rulebase.&lt;BR /&gt;That points to rulebase optimization.&lt;/P&gt;
&lt;P&gt;Consider the following rules and assume BackupServer is located in the ServerZone:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/27045i372F504AAFE84B0A/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;A connection from InternalZone to BackupServer can be matched on the first packet because the service HTTPS is used.&lt;BR /&gt;HTTPS is a simple TCP service.&lt;BR /&gt;Other traffic to the ServerZone (even "Web Browsing") requires multiple packets to correctly identify, thus is Accepted.&lt;BR /&gt;If the connection from InternalZone to ServerZone terminates BEFORE this identification can be done, the traffic is accepted with the message CPNotEnoughDataForRuleMatch.&lt;/P&gt;
&lt;P&gt;For CPEarlyDrop, it means that only drop rules matched when the connection is evaluated against the rulebase based on source/destination/service.&lt;BR /&gt;Note that rules for applications with an action of Drop apply on all ports (even if the application itself doesn't specify the specific port).&lt;BR /&gt;There an example of this in sk:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk111643" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk111643&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;None of these are problems, but expected behavior.&lt;BR /&gt;The behavior can be eliminated through proper rulebase (re)construction.&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jul 2024 16:19:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Problem-with-access-to-WebService/m-p/222290#M37028</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-07-30T16:19:33Z</dc:date>
    </item>
  </channel>
</rss>

