> Source: [sk162856](https://support.checkpoint.com/results/sk/sk162856)

# sk162856 - HTTPS traffic can not be redirected to Captive Portal if matched on first packet

| Property | Value |
|----------|-------|
| Solution ID | sk162856 |
| Date Created | 2019-10-10 |
| Last Modified | 2025-01-22 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20, R81.10 (EOS), R81 (EOS) |

## Symptoms

- HTTPS traffic cannot be redirected to the Captive Portal if it is matched on the first packet.

## Cause

If HTTPS traffic is matched to the redirection rule on the first packet, it cannot be redirected to the Captive Portal.

The traffic can be matched to the redirection rule on first packet only if all of the rules above the redirection rules could be matched from the packet source and destination IPs and ports and protocols.

If the rule above the redirection rule requires additional parsers to run on the connection (as in, XFF is enabled, APPI, URLF), then the match occurs after the first packet. This allows the redirection to take place.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
