> Source: [sk181285](https://support.checkpoint.com/results/sk/sk181285)

# sk181285 - Error: "Connection terminated before the Security Gateway was able to make a decision: No SSL applicative data"

| Property | Value |
|----------|-------|
| Solution ID | sk181285 |
| Date Created | 2023-07-21 |
| Last Modified | 2023-07-23 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R81.20, R81.10 (EOS), R81 (EOS) |
| OS | Gaia |

## Symptoms

- * Firewall logs shows an accept log with error: "Connection terminated before the Security Gateway was able to make a decision: No SSL applicative data"
* Access role are used in the relevant policy
* The policy is configured to detect users who are using an HTTP proxy configured with X-Forwarded-For (XFF). To verify this please navigate to the Smart Console -\> relevant security policy -\> Edit the policy -\> Click on "edit layer".
* There is no proxy between the gateway and the users.

## Cause

Typically, when X-Forwarded-For (XFF) is used at the layer, we do not disclose the client's original IP address in the SYN packet. Instead, we await the XFF header to provide this information.  

Due to the absence of an HTTP proxy to send the gateway a packet with the X-Forwarded-For (XFF) header, we cannot establish a conclusive match. Consequently, the connection is terminated before detection can occur.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
