> Source: [sk105513](https://support.checkpoint.com/results/sk/sk105513)

# sk105513 - HTTP traffic through Security Gateway R75.20 and above is dropped by IPS with log "Connection hold failed due to TCP retransmission limit"

| Property | Value |
|----------|-------|
| Solution ID | sk105513 |
| Date Created | 2015-04-06 |
| Last Modified | 2017-04-05 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |

## Symptoms

- * SmartView Tracker logs show that the HTTP traffic was dropped:

  `
  Action = Drop`  
  `
  Service = http (80)`  
  `
  Protocol = tcp`  
  `
  Attack = General Notice`  
  `
  Product = IPS Software Blade`  
  `
  Reason = Connection hold failed due to TCP retransmission limit
  `
* Kernel debug (`fw ctl debug -m fw + drop`) shows that HTTP traffic was dropped:  
  `fw_log_drop: Packet proto=6 `*Source_IP_Address* `:80 > `*Dest_IP_Address* `:`*Dest_Port*` dropped by fwpslglue_chain Reason: PSL Reject: HTTP_PSL;`

## Cause

Possible reasons:

1) Legacy URL Filtering is enabled on Security Gateway R75.20 and above.

Legacy URL Filtering is supported only for versions lower than R75.20 (refer to [R75.20 Application Control and URL Filtering Administration Guide](http://supportcontent.checkpoint.com/documentation_download?id=12263) - chapter 3 'Managing Application Control and URL Filtering' - Legacy URL Filtering).

2) Security Gateway is not able to connect to Check Point servers (URL Filtering Cloud Categorization)

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
