CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > SmartDefense
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-10-24
Junior Member
 
Join Date: 2007-02-14
Posts: 4
Rep Power: 0
atomicsushi has an average reputation (10+)
Default WSE0020001 illegal header format detected: Illegal start line in request

Hi,

Does anyone know the fix to this:

Re: [FW-1] https and Squid

I'm seeing the same problem where it's dropping on port 3128.

Number: 2990279
Date: 24Oct2007
Time: 10:24:10
Product: SmartDefense
Interface: eth-s1p1c0
Origin: FWA
Type: Log
Action: Reject
Protocol: tcp
Service: tcp_3128 (3128)
Source: host_10.9.1.23 (10.9.1.23 )
Destination: host_20.0.1.237 (20.0.1.237)
Source Port: 34676
Attack Name: Malformed HTTP
Attack Information: WSE0020001 illegal header format detected: Illegal start line in request
Information: reason: €g^A^C^A

I have HTTP protection Inspection all unchecked.

Does anyone know the fix?
Reply With Quote
  #2 (permalink)  
Old 2007-11-18
Member
 
Join Date: 2007-06-19
Posts: 43
Rep Power: 0
mc_rockz has an average reputation (10+)
Default Re: WSE0020001 illegal header format detected: Illegal start line in request

Hi,
What version of Checkpoint are you using? Because i encountered this type of error msg in my NGX R62 distributed setup, i just de-activate "ASCII only Response Header" save then push the policy.


Best Regards,
mc_rockz
Reply With Quote
  #3 (permalink)  
Old 2008-05-02
Junior Member
 
Join Date: 2008-04-10
Posts: 1
Rep Power: 0
BrianBilbrey has an average reputation (10+)
Default Re: WSE0020001 illegal header format detected: Illegal start line in request

Anything further on this topic - I am running into the same issue, and though I set what seemed to be the appropriate SmartDefence protection to Monitor Only, it still resets https connections to the squid proxy box. HTTP - no problem.

thanks in advance,

.brian
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 11:37.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0