- Products
- Learn
- Local User Groups
- Partners
- More
Access Control and Threat Prevention Best Practices
5 November @ 5pm CET / 11am ET
Ask Check Point Threat Intelligence Anything!
October 28th, 9am ET / 3pm CET
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
Spark Management Portal and More!
This is controlled by the fail-open/fail-close settings in situations where the inspection engine has an issue. It is located in two places, not sure which one is relevant since there isn't enough of your log card shown. You must have "fail-close" set in at least one of these locations:
1) Manage & Settings...Blades...APCL/URLF...Advanced Settings...Fail Mode
2) Manage & Settings...Blades...Threat Prevention...Advanced Settings...Fail Mode
Any kind of DNS error like this dictates checking and diligently testing the DNS servers defined in the Gaia OS of the firewall. If one or more of them are slow or not responding consistently it can cause various performance-related mayhem with the rad daemon and APCL/URLF, among others. Make sure *all* DNS servers defined in the Gaia OS respond quickly, not just the first one in the list which is automatically selected by nslookup.
About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY