> Source: [sk121894](https://support.checkpoint.com/results/sk/sk121894)

# sk121894 - URL Filtering does not log some HTTP/HTTPS connections accepted by Firewall blade

| Property | Value |
|----------|-------|
| Solution ID | sk121894 |
| Date Created | 2017-12-12 |
| Last Modified | 2017-12-18 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |
| OS | Gaia |

## Symptoms

- * Although URL Filtering blade is enabled and HTTP/HTTPS connections are accepted by the Firewall blade, SmartLog shows only few URLF records which are much less than firewall records for the same traffic.  

* Output of `fwaccel stats -s` command shows more F2Fed pkts than PXL pkts.  

* `fw monitor` shows TCP SYN packets passing through the Security gateway however there is no response (SYN/ACK) from Web servers.

## Cause

There is an external Security gateway blocking Internet connections from some internal hosts even though the internal gateway accepts them.

The SYN packet is allowed by the Firewall blade and a firewall log is shown in SmartLog, however the security gateway does not get to see any L7 HTTP/HTTPS information since the TCP connection was never established, therefore no URL Filtering logs are seen for these connections in SmartLog.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
