Hi there,
I've (partly) asked about this before (https://community.checkpoint.com/t5/Security-Gateways/quot-CPNotEnoughDataForRuleMatch-quot-and-quot...), but now I have another related question regarding this behvavior.
I have a service that connects to an external ip address, but every time the connection gets terminated by a reset from the destination. The log in my firewall says "Accept", however, it is getting "terminated before the Security Gateway was able to make a decision: No SSL applicative data." ("CPNotEnoughDataForRuleMatch").
As I got told in my other post (see link above) the behavior is by design and expected, however, I do have a question to why it happens.
The connection in question gets HTTPS Inspected and the log is as follows:
data:image/s3,"s3://crabby-images/f707e/f707e93888e203e7c3a7bfa15369eae5dacd4504" alt="httpsi.jpg httpsi.jpg"
And the "Accept" ("CPNotEnoughDataForRuleMatch") log looks as below:
data:image/s3,"s3://crabby-images/68096/68096d521a518400051897ab13e6c0d3c1fc3d19" alt="accept.jpg accept.jpg"
I tried to establish the connection with a Wireshark running on the client (not the firewall) and as far as I can see the handshake completes, but then it gets disconnected by a reset from the destination:
data:image/s3,"s3://crabby-images/652c0/652c0a4ece591926c565428195c3c11f66bc77c4" alt="ws.jpg ws.jpg"
I have the same service on another endpoint WITHOUT HTTPS Inspection and there it connects fine.
So my question is: Is it possible that the packet somehow gets "malformed" in the HTTPS Inspection process and therefore the destination sends a reset back to us and kills the connection? Or is something different going on? I really can't figure it out!
Looking forward to your comments 🙂
Thanks!