r80.10 Take 56. 15600 cluster
fw ctl zdebug drop : grep 172.20.10.10 is giving me the following errors
;[cpu_2];[fw4_27];fw_log_drop_ex: Packet proto=(public website IP):443 -> 172.20.10.10:51123 dropped by cphwd_pslglue_handle_packet Reason: PSL Drop: ASPII_MT
closest think on Check Point's support sk121732. this SK does not seem to apply in my situation.
has anybody seen this before?
thanks.
Hello Neil,
I had a similar issue before. It seems in R80.10 some https traffic does not match any Category or Application on that layer (and is logged as connection instead session), so to me, the traffic was dropped on a deny any rule.
My workaround was allow https on Service/Application from any to internet by creating a before last rule.
Regards.