> Source: [sk181361](https://support.checkpoint.com/results/sk/sk181361)

# sk181361 - Inspection Settings exception does not work on Centrally Managed Spark Firewall

| Property | Value |
|----------|-------|
| Solution ID | sk181361 |
| Date Created | 2023-08-15 |
| Last Modified | 2023-08-16 |
| Technical Level | General |
| Products | Spark Firewall (Locally Managed) |
| Versions | R81.10.X |

## Symptoms

- * Cannot create an exception for "Non Compliant HTTP" in the Inspection Settings.

* One specific HTTP traffic is always blocked by Application Control with the following error.

  ```
  Reason: Application Control - HTTP parsing error occurred (2)
  Action Reason: Blocking request as configured in engine settings of Application Control
  Precise Error: both content-len and transfer-encoding headers in request
  ```

* The following two exception tables are empty on the Quantum Spark Appliance.

  `[Expert@HOSTNAME]# `**fw tab -t sd_src_intvl_list**
  `
  `localhost:
  `
  `

  Table sd_src_intvl_list not loaded: Invalid argument
  `
  `

  [Expert@HOSTNAME]# **fw tab -t sd_dst_intvl_list**
  `
  `

  localhost:
  `
  `

  Table sd_dst_intvl_list not loaded: Invalid argument
  `
  `

  `[Expert@HOSTNAME]#`

## Cause

The exception tables are not generated correctly by the Security Management server during the policy installation.

## Solution

[Contact Check Point Support](https://www.checkpoint.com/support-services/contact-support/) to get a Hotfix for this issue.

A Support Engineer will make sure the Hotfix is compatible with your environment before providing it.  
For faster resolution and verification, collect these files:

1. [CPinfo](https://support.checkpoint.com/results/sk/sk92739) file from the Management Server involved in the case.
2. [CPinfo](https://support.checkpoint.com/results/sk/sk92739) file from the Security Gateway / each Cluster Member involved in the case.

**Hotfix installation instructions:**   
Refer to [sk168597 - How to install a Hotfix](https://support.checkpoint.com/results/sk/sk168597).

<br />

Workaround for the above specific drop of the Application Control:

1. In SmartConsole, go to **MANAGE \& SETTINGS** \>**Blades** \>**Application Control \& URL Filtering** \>**General**.

2. Change

   "**Fail mode**"

   To

   "**Allow all requests (fail-open)**".
3. Install the Access Control policy.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
