> Source: [sk182202](https://support.checkpoint.com/results/sk/sk182202)

# sk182202 - Application Control or URL Filtering blocks legitimate traffic as "X-VPN"

| Property | Value |
|----------|-------|
| Solution ID | sk182202 |
| Date Created | 2024-04-11 |
| Last Modified | 2024-04-30 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R81.20, R81.10 (EOS) |
| OS | Gaia |

## Symptoms

- Application Control Software Blade or URL Filtering Software Blade randomly blocks some legitimate traffic because it is categorized as "X-VPN".

## Cause

Issue in the Application Control Update package version **070424_1** that was released on **08 April 2024**.

To see the current package version:

1. Connect to the command line on the Security Gateway.
2. Log in to the Expert mode.
3. Run:  
   `cat $FWDIR/appi/update/Version`

List of the **MD5** values for the problematic update file:  
Show / Hide this section  

|----------------------------------------------------------------|----------------------------------------------|----------------------------------|
| Deployment and Version                                         | CLI Syntax                                   | MD5 for Package "070424_1"       |
| Security Gateway / Cluster Member R80.40 and higher            | `md5sum $FWDIR/appi/update/appi_db.C`        | 3c7770bbd52b039c8d2e1f59dc6f32a6 |
| Security Gateway / Cluster Member R80.30, R80.20, and R80.10   | `md5sum $FWDIR/appi/update/appi_db.C`        | 59820898ff78abdb1ef4e141ea79dbc5 |
| Security Gateway / Cluster Member R77.X, and R76               | `md5sum $FWDIR/appi/update/appi_db.C`        | c7bff0e3dff5f6aea17db79cd2b648b3 |
| Scalable Platform Security Group R81 and higher                | `g_allc md5sum $FWDIR/appi/update/appi_db.C` | 3c7770bbd52b039c8d2e1f59dc6f32a6 |
| Scalable Platform Security Group R80.30SP and R80.20SP         | `g_allc md5sum $FWDIR/appi/update/appi_db.C` | 59820898ff78abdb1ef4e141ea79dbc5 |
| Quantum Spark (SMB) Appliance R81.10.x, R80.20.x, and R77.20.x | `md5sum $FWDIR/appi/update/appi_db.C`        | 25a08f2f9724b4dd4e1c4803d483b287 |

## Solution

This issue was resolved in the Application Control Update package version **110424_1** that was released on **11 April 2024**.

By default, the Security Gateway checks for an available update package every two hours.

Follow these steps, to force an immediate check for an available update package:

1. Connect to the command on the Security Gateway / each Cluster Member / Scalable Platform Security Group.

2. Log in to the Expert mode.

3. Delete the **Version** file:

   * On a Security Gateway / each Cluster Member:

     `rm $FWDIR/appi/update/Version`
   * On a Scalable Platform Security Group:

     `g_all rm $FWDIR/appi/update/Version`
4. Delete the **next_update** file:

   * On a Security Gateway / each Cluster Member:

     `rm $FWDIR/appi/update/next_update`
   * On a Scalable Platform Security Group:

     `g_all rm $FWDIR/appi/update/next_update`
5. Wait for 5 minutes.

6. Examine the **Version** file (related article - [sk181186](https://support.checkpoint.com/results/sk/sk181186)):

   * On a Security Gateway / each Cluster Member:

     `cat $FWDIR/appi/update/Version`
   * On a Scalable Platform Security Group:

     `g_allc cat $FWDIR/appi/update/Version`
7. Verify the **MD5** value of the **update file**:

   **Important Note** - If you get a different MD5 value, then repeat the entire procedure.  
   If you still get a different MD5 value, then [contact Check Point Support](https://www.checkpoint.com/support-services/contact-support/).

   |--------------------------------------------------------------|----------------------------------------------|-------------------------------------|
   | Deployment and Version                                       | CLI Syntax                                   | Expected MD5 for Package "110424_1" |
   | Security Gateway / Cluster Member R80.40 and higher          | `md5sum $FWDIR/appi/update/appi_db.C`        | a9c76ce42d59642e558fa96d3a0add9b    |
   | Security Gateway / Cluster Member R80.30, R80.20, and R80.10 | `md5sum $FWDIR/appi/update/appi_db.C`        | ecb7401996aaf70c23ad80e5b264f47d    |
   | Security Gateway / Cluster Member R77.x and R76              | `md5sum $FWDIR/appi/update/appi_db.C`        | b55f36f0b66ac3eefd0a536f5b0ba455    |
   | Scalable Platform Security Group R81 and higher              | `g_allc md5sum $FWDIR/appi/update/appi_db.C` | a9c76ce42d59642e558fa96d3a0add9b    |
   | Scalable Platform Security Group R80.30SP and R80.20SP       | `g_allc md5sum $FWDIR/appi/update/appi_db.C` | ecb7401996aaf70c23ad80e5b264f47d    |
   | Quantum Spark Appliance R81.10.x, R80.20.x, and R77.20.x     | `md5sum $FWDIR/appi/update/appi_db.C`        | fc9bdd697638202e4ff7cb76669461ce    |

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
