> Source: [sk174045](https://support.checkpoint.com/results/sk/sk174045)

# sk174045 - Wrong rule match on the first access to a URL or website

| Property | Value |
|----------|-------|
| Solution ID | sk174045 |
| Date Created | 2021-06-16 |
| Last Modified | 2025-11-09 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82, R81.20, R81.10 (EOS), R81 (EOS) |
| OS | Gaia |

## Symptoms

- * Security Gateway logs for the first access to a URL or website show that an unexpected Access Control rule is matched for this traffic.

* Security Gateway logs for later accesses to the same URL or website show that the expected Access Control rule is matched for this traffic.

* After a while, the same behavior happens again.

* The unexpected rule matched on the first access is a catch up rule to "Any Services \& Applications" or "Uncategorized" Websites.

## Cause

Application Control Signatures and URL Filtering Categories are used in the same rule.

### Example of an Access Control rule that contains a Group object:

![](https://sc1.checkpoint.com/sc//SolutionsStatics/sk174045/image01202106151006101.jpg)

### Example of a Group object:

![](https://sc1.checkpoint.com/sc//SolutionsStatics/sk174045/image02202106151011022.jpg)

The Security Gateway must inspect at least several packets to identify the application and determine which Access Control rule to match. Even if the URL Filtering category matches before the Application Control, it may be possible that this Access Control rule is not the appropriate one for the Application Control.

This happens if Application Signatures and URL Filtering categories are used in a Group object, and are also used as single objects in the "Services \& Applications" column of the Access Control rule.

For more information, see:

* About Rule Matching in the Access Control Policy, see the [Security Management Administration Guide](https://sc1.checkpoint.com/documents/R82/WebAdminGuides/EN/CP_R82_SecurityManagement_AdminGuide/Content/Topics-SECMG/Rule-Matching-in-the-Access-Control-Policy.htm?tocpath=Creating%20an%20Access%20Control%20Policy%7C_____3) for your version \> Creating an Access Control Policy \> Rule Matching in the Access Control Policy
* About Best Practices for Access Control Rules, see the [Security Management Administration Guide](https://sc1.checkpoint.com/documents/R82/WebAdminGuides/EN/CP_R82_SecurityManagement_AdminGuide/Content/Topics-SECMG/Best-Practices-for-Access-Control-Rules.htm?tocpath=Creating%20an%20Access%20Control%20Policy%7C_____8) for your version \> Creating an Access Control Policy \> Best Practices for Access Control Rules

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
