CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have 72 attendees signed up from 20 countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Miscellaneous
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-01-26
JCole11 JCole11 is offline
Junior Member
 
Join Date: 2006-01-26
Posts: 3
Rep Power: 0
JCole11 has an average reputation (10+)
Default Line in HTTP request too long error

Hi,

We implement NG R55 with Websense 6.1. When you browse to a JSP page from the internal network, the page will not display and the FW log displays a "Line in HTTP request too long" message. When I add a previous rule to allow HTTP through without Websense enabled, the page loads successfully. This suggests to me there may be an issue with the HTTP Security Server. We are running HFA 16 and SmartDefence. I have looked at the HTTP Security Server settings and the max URL length is 2048 bytes, which the URL is nowhere near. I have searched the net and can only find suggestions on increasing the URL length to 1024 bytes (earlier versions, therefore not implemented), and disabling the Wormcatcher settings (implemented but did not resolve the issue). All other pages seem fine (even with longer URLs). Has anyone else had this issue? Does anybody have any suggestions?

Thanks in advance.
Reply With Quote
  #2 (permalink)  
Old 2006-01-26
chillyjim chillyjim is offline
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,637
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: Line in HTTP request too long error

See sk31267 for the fix.
Reply With Quote
  #3 (permalink)  
Old 2006-01-26
JCole11 JCole11 is offline
Junior Member
 
Join Date: 2006-01-26
Posts: 3
Rep Power: 0
JCole11 has an average reputation (10+)
Default Re: Line in HTTP request too long error

Thanks ChillyJim, but I have already disabled the WormCatcher setting which has not resolved the issue. After reading the knowledge base article, it looks like that is all the hotfix does, but I will try installing this tomorrow anyway and tell you how I go.

Thanks again.
Reply With Quote
  #4 (permalink)  
Old 2006-01-27
JCole11 JCole11 is offline
Junior Member
 
Join Date: 2006-01-26
Posts: 3
Rep Power: 0
JCole11 has an average reputation (10+)
Default Re: Line in HTTP request too long error

HFA 17 seems to have resolved the issue. Thanks for your help chillyjim.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 21:16.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0