CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Web Security > Web Intelligence
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-03-07
mac123 mac123 is offline
Junior Member
 
Join Date: 2005-08-16
Posts: 17
Rep Power: 0
mac123 has an average reputation (10+)
Default HTTP Connect Command found in HTTP request

Hi

We are browsing through a http blue coat proxy, http sites are fine but browsing to any https site fails with

CONNECT Command found in HTTP request.

Looking at resolutions for this it states to switch off CONNECT checking as part of the web intelligence HTTP methods tab but after doing this, saving the changes and pushing the policy i still get the same error.

We are using Checkpoint VSX NGX R60A.

Thanks in advance

Mac
Reply With Quote
  #2 (permalink)  
Old 2008-03-07
melipla melipla is offline
Senior Member
 
Join Date: 2006-01-25
Posts: 850
Rep Power: 3
melipla has an average reputation (10+)
Default Re: HTTP Connect Command found in HTTP request

You could disable SMDF for the gateway (under the gateway object) and see if this is SmartDefense related. If the error still occurs, it may be due to the protocol type & its settings for the services in the rule of the drop.

If turning off SMDF allows the traffic to pass, then there are additional SMDF checks you need to disable. In the past, with an HTTP illegal header drop I was seeing, I've found that merely disabling the check did not disable it for other SMDF checks. I had to disable all SMDF which related to the inspection of HTTP traffic. You can find that list in this CPUG thread.

HTH
__________________
Its all in the documentation.
Reply With Quote
  #3 (permalink)  
Old 2008-03-07
mac123 mac123 is offline
Junior Member
 
Join Date: 2005-08-16
Posts: 17
Rep Power: 0
mac123 has an average reputation (10+)
Default Re: HTTP Connect Command found in HTTP request

Hi

Thanks for the reply. Never heard of SMDF and cant find it on the gateway object for either VSX NGX or NGX

Can you help further

Appreciate your help

Mac
Reply With Quote
  #4 (permalink)  
Old 2008-03-07
melipla melipla is offline
Senior Member
 
Join Date: 2006-01-25
Posts: 850
Rep Power: 3
melipla has an average reputation (10+)
Default Re: HTTP Connect Command found in HTTP request

Quote:
Originally Posted by mac123 View Post
Thanks for the reply. Never heard of SMDF and cant find it on the gateway object for either VSX NGX or NGX
Ah, my apologies. I'm abbreviating SmartDefense into SMDF, and I realize now that it may only be an R65 setting. Under the object properties for the gateway between NAT and VPN you may have a "SmartDefense", if you highlight that you should have an option to "Do not apply SmartDefense on this gateway". If you cannot do this step then you will need to proceed to turn off specific SMDF checks until you no longer see the traffic drop, then you will know which SMDF checks were the problem.
__________________
Its all in the documentation.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 22:07.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0