Hi
I'm curious about the routing logic for this traffic. Can you take a look at the attached image? There appear to be three green logs relevant to the issue.
![log12.JPG log12.JPG](https://community.checkpoint.com/t5/image/serverpage/image-id/26730iF830484EB0C24122/image-size/large?v=v2&px=999)
I wonder why the traffic would be sent like that (not inside tunnel) !
the first: accept by network rule and URL rule.
![accept-log.JPG accept-log.JPG](https://community.checkpoint.com/t5/image/serverpage/image-id/26731iF8A890E1526E288A/image-size/large?v=v2&px=999)
the second: accept by network rule but URL, CPNotEnoughDataForRuleMatch!
![accept-log2.JPG accept-log2.JPG](https://community.checkpoint.com/t5/image/serverpage/image-id/26732i0172EECACDC1E320/image-size/large?v=v2&px=999)
the third: same as the second, and then it does as it configured to do through tunnel!
10.80.91 is an internal server in central office 192.168.3.11 is a printer in branch office
Why is that happening?