Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Vladimir
Champion
Champion

HTTP parsing error occurred, bypass request.

One of my client's gateways has started logging this since May 28th and users behind Check Point are experiencing dramatic slowdown in web access.

Time: 2019-06-04T14:33:59Z
Interface Direction: outbound
Interface Name: Mgmt
Id: c0a8960e-0af6-593b-5cf6-8157f9480002
Sequencenum: 10
Client Type: Other: Microsoft Office/16.0
Precise Error: unknown error
Source: 192.168.170.41
Source Port: 52843
Destination Country: United States
Destination: zzz.xxx.yyy.112
Destination Port: 80
IP Protocol: 6
Proxied Source IP: 192.168.170.41
Reason: HTTP parsing error occurred, bypass request.
Source User Name: User, One (userone@domain.com)
Source Machine Name: machine01@domain.com
User: User, One (userone@domain.com)
Action: Accept
Type: Log
Policy Name: Policy01
Policy Management: CheckpointMGT
Db Tag: {6AEB0FA4-2F80-A84B-A5FD-61DB3123D6CF}
Policy Date: 2019-05-28T14:10:53Z
Blade: IPS
Origin: CheckpointPh
Service: TCP/80
Product Family: Threat
Resource: http://officecdn.microsoft.com.edgesuite.net/pr/033f92d3-bc6d-439a-858a-a17acf70360a/SDX/WA104381125...
Marker: @A@@B@1559620800@C@213270
Log Server Origin: aaa.bbb.ccc.14
Orig Log Server Ip: aaa.bbb.ccc.14
Index Time: 2019-06-04T14:34:01Z
Lastupdatetime: 1559658839000
Lastupdateseqnum: 10
Severity: Informational
Rounded Sent Bytes: 0
Confidence Level: N/A
Rounded Bytes: 0
Stored: true
Rounded Received Bytes:0
Interface: Mgmt
Description:

 

Can someone let me know what we are looking at here?

0 Kudos
1 Reply
PhoneBoy
Admin
Admin

We probably need packet captures and a TAC case to investigate more closely.
But it generally means there is some issue parsing the HTTP headers of the particular request in question.
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events