> Source: [sk184791](https://support.checkpoint.com/results/sk/sk184791)

# sk184791 - Some Security Group Members drop web traffic despite explicit Application Control / URL Filtering rules

| Property | Value |
|----------|-------|
| Solution ID | sk184791 |
| Date Created | 2026-03-05 |
| Last Modified | 2026-03-10 |
| Technical Level | Advanced |
| Products | Security Gateway, Scalable Platforms |
| Versions | R82.10, R82, R81.20, R82.10, R82, R81.20 |
| OS | Gaia |

## Symptoms

- * Occasionally, Security Group drops web traffic although there are explicit Application Control / URL Filtering rules to allow such traffic.

* In **SmartConsole** \> **Logs \& Monitor** \> **Logs** , the security logs show that the generic "Drop" action is performed only by specific Security Group Members (identified by "`member_id`" in the log details).

* On the problematic Security Group Members, traffic capture of the affected web traffic shows that the TCP SYN packets pass through, but does not show the TCP SYN-ACK packets.

* On the problematic Security Group Members, connecting to the destination web server with the "`curl`" command is successful.

* On the problematic Security Group Members, the command "`cpstat os -f licensing`" shows "`App Control / URL Filtering blades: Not Entitled`."

  On the working Security Group Members, this command shows "`App Control / URL Filtering blades: Entitled`".

## Cause

The Security Group (SMO) does not contain the correct license entries for all Security Group Members in the "`$CPDIR/conf/cp.license.smo`" file.

As a result, the license file propagated to the Security Group Members does not include the entitlements for Application Control / URL Filtering.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
