> Source: [sk183569](https://support.checkpoint.com/results/sk/sk183569)

# sk183569 - Security Gateway drops HTTP connections without the "Host" header after installing a Jumbo Hotfix Accumulator

| Property | Value |
|----------|-------|
| Solution ID | sk183569 |
| Date Created | 2025-06-25 |
| Last Modified | 2025-11-05 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20, R81.10 (EOS) |
| OS | Gaia |

## Symptoms

- * Security Gateway drops some HTTP requests after installing one of these Jumbo Hotfixes:

  * R82 Jumbo Hotfix Take 25
  * R81.20 Jumbo Hotfix Take 99
  * R81.10 Jumbo Hotfix Take 177
* The output of the "`fw ctl zdebug + drop`" command on the Security Gateway contains these drops:

  * `fw_log_drop_ex: Packet proto=6 ... dropped by ... Reason: PSL Drop: WS`

  * `fw_log_drop_ex: Packet proto=6 ... dropped by ... Reason: PSL Reject: WS`

## Cause

Starting from these Jumbo Hotfix Accumulator Takes (PRHF-37149), the Security Gateway enforces [RFC 2616](https://www.rfc-editor.org/search/rfc_search_detail.php?rfc=2616) and drops HTTP requests that do not include the mandatory "Host" header.

Previously, this enforcement was more lenient, but it is now strictly validated by the Packet Streaming Library (PSL) component.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
