> Source: [sk119192](https://support.checkpoint.com/results/sk/sk119192)

# sk119192 - Traffic is dropped as "Non Compliant HTTP"

| Property | Value |
|----------|-------|
| Solution ID | sk119192 |
| Date Created | 2017-07-24 |
| Last Modified | 2025-11-14 |
| Technical Level | General |
| Products | Security Gateway, Scalable Platforms |
| Versions | R82.10, R82, R81.20, R82, R81.20 |
| Platform | 44000 |

## Symptoms

- Traffic is dropped as "Non Compliant HTTP" when the traffic is not HTTP traffic but is defined in some service object (likely as part of a port range) as HTTP.

## Cause

The traffic is defined as HTTP service, so the Security Gateway assumes that this traffic is HTTP until it parses enough data to decide whether it is indeed HTTP traffic. In this case, the server replies before the Security Gateway has seen enough data from the client. As a result, the traffic is treated as non-compliant HTTP, although it should not be.

## Solution

This problem was fixed. The fix is included in:

* [Jumbo Hotfix Accumulator for R76SP.50](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk117633) - since *Take_16*

For **other [supported](http://www.checkpoint.com/support-services/support-life-cycle-policy/index.html) versions** , [Check Point Support](http://www.checkpoint.com/support-services/contact-support/index.html) can supply a **Hotfix** .  
A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.  
For faster resolution and verification, please collect [CPInfo files](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk92739) from the Security Management Server and Security Gateways involved in the case.

The following **workaround** is also available:

1. Add an exception rule to the "Non Compliant HTTP" IPS protection for the service and destination IP:  
   - Go to the**IPS** tab and click on **Protections**.

   ![](https://sc1.checkpoint.com/sc//SolutionsStatics/sk119192/ips11707250611.png)
2. Click **New...** , fill in the details, and click **OK.**

   **Example** :  
   ![](https://sc1.checkpoint.com/sc//SolutionsStatics/sk119192/ips21707250614.png)
3. Install the policy.

4. Remove the particular service from any service objects defining it as HTTP.

5. Install the policy again.

**Related Solutions:**

* [sk117392 - HTTP traffic dropped by "Non Compliant HTTP" IPS protection when Jumbo HFA installed](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk117392)

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
