> Source: [sk133672](https://support.checkpoint.com/results/sk/sk133672)

# sk133672 - Block UserCheck page doesn't display on first attempt 

| Property | Value |
|----------|-------|
| Solution ID | sk133672 |
| Date Created | 2018-08-07 |
| Last Modified | 2020-03-14 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |
| OS | Gaia |

## Symptoms

- * When the user tries to open a website that should be blocked, the UserCheck page does not display on the first attempt. The problem does not occur on the second attempt, and the page displays properly.(The Security Gateway is acting as a proxy in non-transparent mode, and HTTPS Inspection is enabled.)
* Kernel debug shows (Appi + UserCheck):

  <br />


  `
  ;[cpu_4];[fw4_1];1526296200:{connection} `***up_transaction_handle_usercheck_action: usercheck action: UC_HTTP_CANT_REDIRECT_DROP;*** `;`  
  `
  ;[cpu_4];[fw4_1];1526296200:{connection} up_conn_module_get_connection: [dir 1, X.X.X.X:54820 -� > X.X.X.X:8080, IPP 6];`  
  `
  ;[cpu_4];[fw4_1];1526296200:{connection} up_conn_module_get_connection: found up conn ffffc200519eb048;`  
  `
  ;[cpu_4];[fw4_1];1526296200:{connection} up_conn_get_conn_app_opq: found entry id 4;`  
  `
  ;[cpu_4];[fw4_1];1526296200:{connection} [WARNING]: up_transaction_is_ignore_redirect: ignore redirect attrib not found;`  
  `
  ;[cpu_4];[fw4_1];1526296200:{connection} up_transaction_is_ignore_redirect: ignore_redirect is FALSE;`  
  `
  ;[cpu_4];[fw4_1];1526296200:{connection} up_transaction_is_ignore_redirect: Clear E_UP_CONNECTION_FLAG_REDIRECT_WAS_IGNORED;`  
  `
  ;[cpu_4];[fw4_1];1526296200:{webapi} user_check_web_get_cant_redirect_reason: Cant redirect reason:' Avoiding redirection - the redirect isn't possible in the current phase of the protocol';`  
  `
  ;[cpu_4];[fw4_1];1526296200:{connection} [WARNING]: `***up_transaction_handle_usercheck_action: Reason: Avoiding redirection - the redirect isn't possible in the current phase of the protocol;*** `;`  
  `
  ;[cpu_4];[fw4_1];1526296200:{connection} up_transaction_free_uc_match_data: calling observer [2:'Application'] to free uc_match_data;`  
  `
  ;[cpu_4];[fw4_1];1526296200:{log} up_clob_observer_free_usercheck_data: free usercheck data for observer Application;`  
  `
  ;[cpu_4];[fw4_1];1526296200:{rulebase} up_rulebase_execute_match: UC action final action is 0 (Drop);`  
  `
  ;[cpu_4];[fw4_1];1526296200:{rulebase} up_rulebase_execute_match: terminating position of chain was update to 0;`  
  `
  ;[cpu_4];[fw4_1];[PROB]: Network, 17, dir 0, 10.0.79.166, 54820, 10.29.0.163, 8080, IPP 6, -1, Drop;`  
  `
  ;[cpu_4];[fw4_1];1526296200:{rulebase} up_sub_policy_get_rule_uui`

* `Kernel debug shows (fw + advp):
  `  

  `
  ``
  ; 4Jun2018 14:57:15.847859;[cpu_5];[fw4_0];advp_get_advp_policy_attribs: APLC and URLF are not active on the matched HTTPS Inspection rule`

  `
  `

## Cause

R80.10 contains a new feature that enables UC page injection into the HTTPS connection. The injection is possible **only if the connection is inspected by HTTPS Inspection**

Due to an issue in this feature, UC page is not injected into HTTPS connection because the connection is mistakenly considered as not being inspected by HTTPS Inspection, when it is in fact inspected.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
