- CheckMates
- :
- Products
- :
- Quantum
- :
- Threat Prevention
- :
- Help on IPS Blade Log
Options
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×
Sign in with your Check Point UserCenter/PartnerMap account to access more great content and get a chance to win some Apple AirPods! If you don't have an account, create one now for free!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Help on IPS Blade Log
Hi,
Since I activated IPS Blade I frequently log messages like with action Accept, source from internet and destination is the outside IP of the Gateway.
On the Forensics Details I get:
Reason: HTTP parsing error ocurred, bypass request
And the Precise Error is Illegal URL
Since this is reported by IPS I suspect this is a possible form of attack. Why is it allowed? I did not configure an exception ...
Thanks
Carlos
1 Reply
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Maybe the kernel variable mentioned here is set?
See: https://community.checkpoint.com/t5/Remote-Access-Solutions/HTTP-parsing-error-occurred-blocking-req...
See: https://community.checkpoint.com/t5/Remote-Access-Solutions/HTTP-parsing-error-occurred-blocking-req...
