<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PSL reject in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/PSL-reject/m-p/193218#M32336</link>
    <description>&lt;P&gt;&lt;STRONG&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk60160" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;sk60160: After a failover, cluster drops traffic with "dropped by fwpslglue_chain Reason: PSL Reject: failover occured and connection is marked for reject"&lt;/SPAN&gt;&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk109777" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;sk109777: "&lt;STRONG&gt;PSL&lt;/STRONG&gt; &lt;STRONG&gt;Reject&lt;/STRONG&gt;: internal - &lt;STRONG&gt;reject&lt;/STRONG&gt; enabled" log after migration to a new version, traffic is dropped&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk111579" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;sk111579: IPS blade drops non-compliant HTTP packets with multiple gzip compression&lt;/SPAN&gt;&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;DIV style="display: flex;"&gt;
&lt;DIV class="" style="margin-top: 4px; margin-right: 5px; display: inline;" aria-label="You Need To Sign Up Or Sign In To View More Information"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;A href="https://support.checkpoint.com/results/sk/sk112724" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;sk112724: Updates For Anti-Virus/Anti-Bot/Application Control/URL Filtering blades are not working on standby ClusterXL member&lt;/SPAN&gt;&lt;/A&gt;&lt;/DIV&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk119432" target="_blank" rel="noopener"&gt;sk119432: Application Control/URL Filtering drops traffic from internal web server&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk105513" target="_blank" rel="noopener"&gt;sk105513: HTTP traffic through Security Gateway R75.20 and above is dropped by IPS with log "Connection hold failed due to TCP retransmission limit"&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk111937" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;sk111937: "Turn on TLS 1.0, TLS 1.1, and TLS 1.2 in Advanced settings" error in Internet Explorer browser for HTTPS web site&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 21 Sep 2023 07:37:30 GMT</pubDate>
    <dc:creator>G_W_Albrecht</dc:creator>
    <dc:date>2023-09-21T07:37:30Z</dc:date>
    <item>
      <title>PSL reject</title>
      <link>https://community.checkpoint.com/t5/General-Topics/PSL-reject/m-p/193207#M32334</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Does anyone know what PSL is and what causes these drops?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;After I change the equipment name, the log occurs. (SIC reser without cp service)&lt;/P&gt;&lt;P&gt;If you use fwckl zdebug + drop, the PSL reject log also comes out.&lt;BR /&gt;It is used only for APT, and all policies are set to leave no logs with any, any, accept.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;@;184761404; [cpu_0];[fw4_1];FW-1:global lock of instance 1 is released without the proper flags (4)
lock holder is fwmultik_queue_async_dequeue_cd;
@;184761582;[cpu_0];[fw4_1];fw_log_drop_ex: Packet proto=6 10.234.53.211:51095 -&amp;gt; 23.45.150.162:80 dropped by fwpslglue_chain Reason: PSL Reject: internal - reject enable;&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Any ideas where to start looking?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;And does this make Internet connectivity impossible?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thank you in advance.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 21 Sep 2023 01:55:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/PSL-reject/m-p/193207#M32334</guid>
      <dc:creator>bund</dc:creator>
      <dc:date>2023-09-21T01:55:33Z</dc:date>
    </item>
    <item>
      <title>Re: PSL reject</title>
      <link>https://community.checkpoint.com/t5/General-Topics/PSL-reject/m-p/193218#M32336</link>
      <description>&lt;P&gt;&lt;STRONG&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk60160" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;sk60160: After a failover, cluster drops traffic with "dropped by fwpslglue_chain Reason: PSL Reject: failover occured and connection is marked for reject"&lt;/SPAN&gt;&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk109777" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;sk109777: "&lt;STRONG&gt;PSL&lt;/STRONG&gt; &lt;STRONG&gt;Reject&lt;/STRONG&gt;: internal - &lt;STRONG&gt;reject&lt;/STRONG&gt; enabled" log after migration to a new version, traffic is dropped&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk111579" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;sk111579: IPS blade drops non-compliant HTTP packets with multiple gzip compression&lt;/SPAN&gt;&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;DIV style="display: flex;"&gt;
&lt;DIV class="" style="margin-top: 4px; margin-right: 5px; display: inline;" aria-label="You Need To Sign Up Or Sign In To View More Information"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;A href="https://support.checkpoint.com/results/sk/sk112724" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;sk112724: Updates For Anti-Virus/Anti-Bot/Application Control/URL Filtering blades are not working on standby ClusterXL member&lt;/SPAN&gt;&lt;/A&gt;&lt;/DIV&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk119432" target="_blank" rel="noopener"&gt;sk119432: Application Control/URL Filtering drops traffic from internal web server&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk105513" target="_blank" rel="noopener"&gt;sk105513: HTTP traffic through Security Gateway R75.20 and above is dropped by IPS with log "Connection hold failed due to TCP retransmission limit"&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk111937" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;sk111937: "Turn on TLS 1.0, TLS 1.1, and TLS 1.2 in Advanced settings" error in Internet Explorer browser for HTTPS web site&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 21 Sep 2023 07:37:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/PSL-reject/m-p/193218#M32336</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2023-09-21T07:37:30Z</dc:date>
    </item>
  </channel>
</rss>

