> Source: [sk171805](https://support.checkpoint.com/results/sk/sk171805)

# sk171805 - Security Gateway rejects an HTTP / HTTPS connection with the log "header length exceeded maximum allowed length"

| Property | Value |
|----------|-------|
| Solution ID | sk171805 |
| Date Created | 2021-02-03 |
| Last Modified | 2024-11-12 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82, R81.20, R81.10 (EOS), R81 (EOS) |
| OS | Gaia |

## Symptoms

- * A user on an internal network cannot load a website

  SmartConsole / SmartView shows this reject log from the Security Gateway (the example below is for HTTPS):

  **Log Info**
  > Blade: Firewall  
  > Product Family: Access  
  > Type: Log

  **Policy**
  > Action: Reject  
  > Reason: 'cookie' header length exceeded maximum allowed length

  **Inspection Settings Details**
  > Name: HTTP Format Sizes  
  > Information: header length exceeded maximum allowed length  
  > Protection Name: HTTP Format Sizes  
  > Protection Type: Signature  
  > Reason: 'cookie' header length exceeded maximum allowed length  
  > Industry Reference: CAN-2001-1304 CAN-2002-1153 CVE-2001-0852

  **Traffic**
  > Service: https (TCP/443)  
  > Destination Port: 443  
  > IP Protocol: TCP (6)

  **More**
  > Protection ID: HttpFormatSizes  
  > Description: https Traffic Rejected from \<USER\> (\<IP Address\>) to \<IP Address\> due to header length exceeded maximum allowed length
* Kernel debug on the Security Gateway ('`fw ctl debug -m WS all`') shows:

  `ws_http2_hpack_header_list_enforce_header_format: Header field number 10 with value length <NUMBER> exceeds maximum allowed length 2100. Policy action is 2, send log is TRUE, track is -1;;`

## Cause

The HTTP format header length has been exceeded the default value of 2100 bytes.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
