CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Web Security > Web Intelligence
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-06-07
Junior Member
 
Join Date: 2006-06-07
Posts: 4
Rep Power: 0
bobgandalf has an average reputation (10+)
Default WSE0020001 illegal header format detected

Hello,

I have problem enabling Web-Intelligence.
When enabled this feature will block legal HTTPS (port 443) traffic to my webmail server. Here the log:

Attack Name: Malformed HTTP
Information: reason: ^V^C
Attack Information: WSE0020001 illegal header format detected: Illegal start line in request

Any idea on how to use the Web Intelligence without blocking this traffic?

(Checkpoint NGX R60 on Windows)
Thanks, Bob.
Reply With Quote
  #2 (permalink)  
Old 2006-06-07
Senior Member
 
Join Date: 2006-01-26
Location: Moscow, Russia
Posts: 706
Rep Power: 3
kva.kva has an average reputation (10+)
Default Re: WSE0020001 illegal header format detected

https://secureknowledge.checkpoint.c....do?id=sk26440

Clear the box "Enforce strict HTTP request parsing".
Reply With Quote
  #3 (permalink)  
Old 2006-06-08
Junior Member
 
Join Date: 2006-06-07
Posts: 4
Rep Power: 0
bobgandalf has an average reputation (10+)
Default Re: WSE0020001 illegal header format detected

Sorry, the box has always been unchecked.
I tried to check/uncheck and install ... but no way.
Still have the same problem.
Reply With Quote
  #4 (permalink)  
Old 2006-06-08
Senior Member
 
Join Date: 2006-01-26
Location: Moscow, Russia
Posts: 706
Rep Power: 3
kva.kva has an average reputation (10+)
Default Re: WSE0020001 illegal header format detected

Try to uncheck all HTTP Protocol Inspection options for experiment or set monitor only.
Reply With Quote
  #5 (permalink)  
Old 2006-06-09
Junior Member
 
Join Date: 2006-06-07
Posts: 4
Rep Power: 0
bobgandalf has an average reputation (10+)
Default Re: WSE0020001 illegal header format detected

Unchecked all the HTTP protocol inspection options. The traffic is still blocked/monitor-only.
The log change as:

Action: Monitor Only
Service: https (443)
Rule: 14
Attack Name: Malformed HTTP
Information: service_id: https
Attack Information: Error parsing HTTP sub-header
Rule UID: {E2054E15-E0FF-4561-906D-9063624CF854}

Rule 14 is: any --> webmailserver https Accept

Why FW complains "Malformed HTTP" when using HTTPS ?

There should be a way to configure some "exception" in the WebIntelligence engine, so I can insert the "legal" content and not have it blocked.

Last edited by bobgandalf; 2006-06-09 at 02:12.
Reply With Quote
  #6 (permalink)  
Old 2006-06-22
Junior Member
 
Join Date: 2006-06-22
Posts: 21
Rep Power: 0
masterloo has an average reputation (10+)
Default Re: WSE0020001 illegal header format detected

The only way I've found you can work around this problem is by changing the service specific protocol type used (squidntlm,etc) to NONE. Web Intelligence checks have no impact.

Regards,
Ryan Huggins
Reply With Quote
  #7 (permalink)  
Old 2006-07-20
Member
 
Join Date: 2006-03-24
Posts: 51
Rep Power: 3
crucial has an average reputation (10+)
Default Re: WSE0020001 illegal header format detected

Does anyone have any other information on this? I am running into this with my http traffic. I dont want to change my http object to match 'None' in the traffic type, due to the potential impact.
Reply With Quote
  #8 (permalink)  
Old 2006-11-07
Junior Member
 
Join Date: 2006-11-07
Location: Germany, Münster
Posts: 4
Rep Power: 0
manfred.huels has an average reputation (10+)
Send a message via Yahoo to manfred.huels
Default Re: WSE0020001 illegal header format detected

Uncheck in "Web Intelligence"-Tab -> HTTP Protocol Inspection -> "Ascii Only Request" and "Ascii only response header".
Caution: You really need to "uncheck". Monitoring only does not help.
Reply With Quote
  #9 (permalink)  
Old 2006-11-27
Junior Member
 
Join Date: 2006-10-03
Location: Cambridge UK
Posts: 17
Rep Power: 0
speculatrix has an average reputation (10+)
Default Re: WSE0020001 illegal header format detected

I found this thread whilst trying to fix a problem where desktops couldn't see the remote proxy over tcp-8080. Despite verifying that my "http-proxy-tcp8080" service didn't have the "http" protocol ticked, the firewall was still inspecting the protocol and killing access to https websites with a bad header log.

I have to change the global Web Intelligence properties so as to disable "ASCII Only Request" and "ASCII Only Response Headers", and then it worked!

sigh.
__________________
Linux fanboy: SuSE10.x on x86, Cacko1.23 on Zaurus SL-C3100, OZ on SL-6000L.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 00:35.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0