Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
evlad
Participant
Jump to solution

Action:Accept Reason:Connection terminated

Hello everybody,

The question is very simple and it was asked many times and answered many times, but no answer was really satisfying.
My question is entirely seen on the picture: I have simple explicit access rule (not application rule) that allows access to certain node by very simple and common protocol. And I see in the LOG records saying Action: "Accept" and below the Reason:"Connection terminated before detection: insufficient data passed"

Accept terminated.png

What can I conclude (if I do not see any other records from this source):
- the session was accepted or terminated finally?
- if it was finally accepted and continue, I do not want to see "Connection terminated"
- if it was finally terminated, I do not want to see "Accept" here.  What difference for me that action was not "Deny" or "Drop" but "Terminated" if result is same?
- If it was terminated finally - it was terminated by who?? by Checkpoint Gw or by the Source or by the Destination? It's critical to understand!

If the connection was terminated before detection by source or destination node - please write this in the reason field.
If the connection was terminated by Gw - please, You should understand that ''Insufficient data passed" just not reasonable to terminate session that explicitly defined as allowed

 

0 Kudos
1 Solution

Accepted Solutions
_Val_
Admin
Admin

The connection was terminated by either the client or the server participating in it. FW action is Accept. The message is referring that data passing through the connection was not sufficient to determine an actual application. 

View solution in original post

2 Replies
_Val_
Admin
Admin

The connection was terminated by either the client or the server participating in it. FW action is Accept. The message is referring that data passing through the connection was not sufficient to determine an actual application. 

evlad
Participant

Thank You so much! If it so, Your answer make the issue very clear.
I just want to mention that could be the brilliant improvement from CheckPoint to add at the reason:
"Connection terminated by souce/destination/... before detection"

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events