> Source: [sk164815](https://support.checkpoint.com/results/sk/sk164815)

# sk164815 - HTTPS traffic does not work when using custom Application/Site

| Property | Value |
|----------|-------|
| Solution ID | sk164815 |
| Date Created | 2020-01-23 |
| Last Modified | 2021-04-11 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |
| OS | Gaia |

## Symptoms

- * HTTPS traffic is dropped on the Clean Up rule when using custom Application/Site.
* Running kernel debug ('fw ctl zdebug + drop) it can be seen that the first packet of the HTTPS connection is silently dropped with error message:` "PSL Drop: TLS_PARSER"`
* A log in SmartLog is seen with drop message:` "URL Filtering - Connection hold failed due to TCP retransmission limit"` on the Firewall Blade.
* Connections after the first drop are successful.

## Cause

This issue applies when the following configuration combinations are used:

* URL Filtering Whitelist policy - Websites are explicitly allowed and all non-allowed websites are blocked via the Clean Up rule.
* Categorize HTTPS websites - SSL/HTTPS Inspection is not being used for outbound connections.
* Added SNI information to connection logs when connection is matched on rule with "Extended Log"
* Website categorization mode is set to Hold - Requests are blocked until categorization of the website is completed. Improved enforcement of first connection when URL Filtering setting is 'Hold' mode. ( Hold mode granularity )

When a request to a website is made, the Security Gateway holds the "Unknown" traffic. The traffic is sent to the RAD (Resource Advisor) daemon to verify the CN (Common Name) of the website. Before the response from RAD is returned, the policy is enforced on the "Unknown" traffic and is dropped on a Clean Up rule. The IP address of the website is entered into the cache table, but the connection has already been dropped by the policy. The second connection attempt to the same IP address is successful because the IP address has been entered into the cache table and CN has been verified.

## Solution

This problem was fixed. The fix is included in:

* [Check Point R80.40](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk160736)
* Check Point R80.30 Jumbo Hotfix Take_228

Check Point recommends to always upgrade to the most recent version   
([upgrade Security Gateway](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doShowproductpage&productTab=overview&product=435)).

For **other [supported](http://www.checkpoint.com/support-services/support-life-cycle-policy/index.html) versions** , Check Point can supply a **Hotfix** . [Contact Check Point Support](https://www.checkpoint.com/support-services/contact-support/) to get a Hotfix for this issue.  
A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.  
For faster resolution and verification, please collect [CPinfo files](http://supportcontent.checkpoint.com/solutions?id=sk92739) from the Security Management Server and Security Gateways involved in the case.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
