> Source: [sk173943](https://support.checkpoint.com/results/sk/sk173943)

# sk173943 - Traffic is blocked, log shows "URL Filtering - Unauthorized Sni: 'URL' found" 

| Property | Value |
|----------|-------|
| Solution ID | sk173943 |
| Date Created | 2021-06-11 |
| Last Modified | 2021-06-13 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R81 (EOS) |

## Symptoms

- * There is a large number of unauthorized SNI logs.


  The logs show:

  ```
  
  URL Filtering - Unauthorized Sni: '<URL>' found (*number*)
  Connection terminated before detection: Insufficient data passed.
  ```

  <br />

* Traffic capture shows that the connection stops after the Security Gateway receives the certificate.

## Cause

The server provided an SNI that is not approved (for example, an SNI that does not align with SAN).  
The Security Gateway blocks servers with SNIs that are not approved.  

Because the connection terminates early, the URL Filtering blade does not have sufficient information to match the rule.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
