> Source: [sk183842](https://support.checkpoint.com/results/sk/sk183842)

# sk183842 - IPS intermittently blocks legitimate traffic from Mobile Access remote users with the error message "Command Injection Detected in Request" 

| Property | Value |
|----------|-------|
| Solution ID | sk183842 |
| Date Created | 2025-08-22 |
| Last Modified | 2025-08-31 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R81.20 |
| OS | Gaia |

## Symptoms

- * IPS intermittently blocks legitimate traffic from Mobile Access remote users to an internal host.

* The IPS blade shows prevent logs with the reason `Command Injection Detected in Request: 'control'.`

* Users cannot access web applications via SSL VPN.

* Attempts to configure an exception directly from the log fail with the error `This protection does not support exceptions`.

## Cause

The IPS engine triggers the "Command Injection" core protection because the application's traffic matches patterns normally associated with malicious activity.

## Solution

The protection is functioning as designed, but the legitimate traffic resembles an attack pattern. To allow the application traffic:  

1. Create a specific IPS exception for Command Injection:
   1. Open SmartConsole.
   2. Go to **Threat Prevention** \> **IPS Protections**.
   3. Go to **Command Injection** in the Core Protection.
   4. Right click **Command Injection** and create a new exception for the applicable source and destination addresses.
   5. Save and install the policy on the Security Gateway.
2. Verify Traffic Flow:
   1. Confirm that legitimate traffic from Mobile Access (SSL VPN) users to the internal host is no longer blocked.
   2. Examine the IPS logs to ensure that legitimate connections are not blocked with the message `Command Injection Detected in Request: 'control'`.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
