> Source: [sk183925](https://support.checkpoint.com/results/sk/sk183925)

# sk183925 - Previously accessible websites are blocked and logged as "TLS1.3 Server Hello" in SmartConsole

| Property | Value |
|----------|-------|
| Solution ID | sk183925 |
| Date Created | 2025-09-10 |
| Last Modified | 2026-08-11 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20, R81.10 (EOS) |

## Symptoms

- * The Quantum Security Gateway blocks websites that were previously accessible.

* SmartConsole logs show blocked websites categorized as application "TLS1.3 Server Hello" under "Network Protocols".

* There are no such blocks or logs for the same traffic before the recent update; the issue starts suddenly.

* Example log output:

  `
  Action: Block`  
  `
  Application: TLS1.3 Server Hello`  
  `
  Category: Network Protocols`  
  `
  Source: `  
  Destination:
* In some scenarios, the following drops could be observed when running "fw ctl zdebug + drop": fwmultik_process_f2p_packet_inner Reason: PSL Drop: TLS_PARSER

## Cause

A recent update to the Check Point Application Control package (released in package 070925_1 on September 8, 2025) introduced improved detection for Transport Layer Security (TLS) 1.3 protocol traffic. Previously, TLS 1.3 traffic was classified as "Unknown Traffic" unless a specific inspection was enabled.   

With the update, the system accurately identifies and categorizes TLS 1.3 traffic as "TLS1.3 Server Hello" under "Network Protocols". As a result, Application Control policy rules that block "Network Protocols" or "Encrypted Communication" also block legitimate TLS 1.3 traffic, including access to websites that use this protocol.   

**This change improves security and performance, while also allowing administrators to design stricter and more precise rulebases.**

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
