Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
JPR
Collaborator
Jump to solution

ChatGPT / HTTP2 parsing error / HTTPS Inspection

Hi all,

I experience frequent loading issues on e.g. chatgpt.com.

When starting a session it usually goes fine for the first couple of prompts, but at some point the session stops and just hangs like seen below:

chatgpt.png

I get the following logs on the gateway (R82 Take 60):

fw1.png

fw2.png

 

Whenever I disable HTTPS Inspection for ChatGPT it works fine.

I've stumbled upon the following SK: https://support.checkpoint.com/results/sk/sk181070

But I can't really say if it's related.

Do any of you have an idea as to why I get the HTTP2 parsing error? And what might be the solution?

Best regards,

Jesper, Denmark

0 Kudos
1 Solution

Accepted Solutions
JPR
Collaborator

Hi,

Very sorry for the late response.

I ended up having a chat with Check Point about it and it was this that solved it:

  1. Set the value 1 for the parameter "IGNORE_ALPN_EXTENSION":
    ckp_regedit -a SOFTWARE\\CheckPoint\\FW1 IGNORE_ALPN_EXTENSION 1
    Note - This change survives reboot.

See: https://support.checkpoint.com/results/sk/sk116022

Best regards, Jesper

 

View solution in original post

14 Replies
zaoar
Contributor

Hi,

i have exactly the same issue. 

Did you find a solution?

Regards,

Aris

JPR
Collaborator

Hi,

Very sorry for the late response.

I ended up having a chat with Check Point about it and it was this that solved it:

  1. Set the value 1 for the parameter "IGNORE_ALPN_EXTENSION":
    ckp_regedit -a SOFTWARE\\CheckPoint\\FW1 IGNORE_ALPN_EXTENSION 1
    Note - This change survives reboot.

See: https://support.checkpoint.com/results/sk/sk116022

Best regards, Jesper

 

jberg712
Collaborator

@JPR Thanks for this.  This is actually what we've been experiencing since R81 and HTTP/2 traffic and had to add this registry key.

@PhoneBoyJust wanted to tag you as not the last webinar you did on HTTPS inspection but one you did previously or a couple of them before hand I asked this question in regards to the struggle with inspecting HTTP/2 traffic and the way to mitigate this is to enforce HTTP 1.1.  You didn't seem to have much information about it at the time and I don't know if the more recent webinar addressed this, but I would like to see if the next one you do on HTTPS inspection addresses this.   Since HTTP/2 has been around for sometime and I know HTTPS inspection has always been a struggle, there isn't much I've been able to find that there will be any improvements in HTTPS inspection for HTTP/2 traffic especially to address this issue.  We would experience this strictly on HTTP/2 traffic even when strict hold wasn't enabled.    I'd be curious if this is being addressed by development and worked on since HTTP/2 is meant to be a faster protocol and improves web browsing.  From my recent TAC case regarding this, I was told that this is quite common to add this ALPN key to enforce HTTP1.1 traffic.   

PhoneBoy
Admin
Admin

A much bigger issue is HTTP/3 where the Chrome/Chromium doesn't allow third party CAs to be imported, which is necessary for HTTPS Inspection to work.
See: https://support.checkpoint.com/results/sk/sk111754
This means blocking QUIC entirely.

Not sure what the issue is with ALPN is here.
Most likely, this will require a TAC case. 

Having said that, it seems the most reliable way to do HTTPS Inspection is to downgrade to HTTP/1.1.
Probably a good idea to update my HTTPS Inspection slides.

0 Kudos
tankp
Employee
Employee

Please check the two limitations in https://support.checkpoint.com/results/sk/sk116022

1. The "Strict Hold" feature is enabled on the Security Gateway in the $FWDIR/conf/malware_config file (sk183840).
2. The ICAP Server is enabled in the Security Gateway object.

JPR
Collaborator

Yes, exactly.

Got it solved by:

  1. Set the value 1 for the parameter "IGNORE_ALPN_EXTENSION":
    ckp_regedit -a SOFTWARE\\CheckPoint\\FW1 IGNORE_ALPN_EXTENSION 1
    Note - This change survives reboot.
Machine_Head
Advisor
Advisor

Having the same issue in R1.20 JHF128. 

Strict hold or icap server not enabled.

0 Kudos
Lau
Contributor
Contributor

I had the same problem at a customer and it was similar for Claude and Harvey. Sometimes working slow, most of the time not working at all. Was working fine on R82 JHF take 41. Experienced the issues on take 60. Went away when patched with take 91.

zaoar
Contributor

still having the same issue on R81.20 take 127 .

The only workaround that works for me is forcing the browsers to use HTTP1.1

It feels like its related to the size of the header. maybe it hits some inspection limit or something.

Regards,

Aris

Jerold_Schlamow
Employee
Employee

I am not sure if this will help, but I have found sk181070 - ChatGPT does not work when HTTPS Inspection is enabled

0 Kudos
JPR
Collaborator

See my answer above. That solved it for me! Sorry for the late response.

0 Kudos
ItsTheFirewall
Participant

Having the same issue. Please let us know if anyone finds a solution.

Jerold_Schlamow
Employee
Employee

I have also found sk180257-HTTP/2 websites do not work when the Strict Hold feature is enabled on a Security Gateway

https://support.checkpoint.com/results/sk/sk180257

It appears to be a limitation and expected behavior with "Strict Hold" and HTTP/2 websites. The only solution is to create a bypass rule or disable "Strict Hold"

0 Kudos
JPR
Collaborator

Sorry for the late response.

This solved it:

  1. Set the value 1 for the parameter "IGNORE_ALPN_EXTENSION":
    ckp_regedit -a SOFTWARE\\CheckPoint\\FW1 IGNORE_ALPN_EXTENSION 1
    Note - This change survives reboot.

See more here: https://support.checkpoint.com/results/sk/sk116022

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events