> Source: [sk165434](https://support.checkpoint.com/results/sk/sk165434)

# sk165434 - Security Gateway or Security Management accepts outbound traffic to Sucuri CloudProxy servers 

| Property | Value |
|----------|-------|
| Solution ID | sk165434 |
| Date Created | 2020-02-25 |
| Last Modified | 2020-03-01 |
| Technical Level | Advanced |
| Products | Security Gateway, Security Management Server |
| Versions | R82.10, R82, R81.20, R82.10, R82, R81.20 |

## Symptoms

- Outbound traffic (HTTP (TCP/80)) accepted by implied rule "Accept outgoing packets originating from Gateway" to destination resolving to cloudproxy (some number) .sucuri.net  
**Note:** Destination IP addresses may be 192.124.249.0/24

## Cause

Many Check Point update servers (e.g. https://updates.checkpoint.com ), or utility servers (e.g. https://productservices.checkpoint.com ) have HTTPs certificates signed by GoDaddy, which has CRL lists stored on sucuri.net cloudproxy servers.  

As part of the TLS connection to these servers, the CRL may be retrieved by the initiator of the connection (Check Point Security Gateway or Security Management).

<br />

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
