> Source: [sk34182](https://support.checkpoint.com/results/sk/sk34182)

# sk34182 - HTTPS packets are dropped/rejected with "Not allowed SSL version" log

| Property | Value |
|----------|-------|
| Solution ID | sk34182 |
| Date Created | 2008-01-15 |
| Last Modified | 2025-09-16 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R81.20, R81.10 (EOS), R81 (EOS) |

## Symptoms

- HTTPS packets are dropped with "Not allowed SSL version" log even though the Rule Base is configured to allow communication on TCP port 443.  

Possible scenario: Remote access VPN (with Visitor Mode) is established through a gateway, where VPN establishment traffic is dropped with "Not Allowed SSL version".  
Note that this is also applicable for Gateways with SSL Inspection disabled.

## Cause

A rule for SSLv3 is configured to inspect HTTPS traffic (port 443) and it is followed by a set of rules that are configured to inspect the rest of the HTTPS communication.   

The inspection of a service is applied by the Source IP address, Destination IP address and by the port number. The port defines which inspection the connection undertakes.   

When a connection is matched on the rule that contains service "ssl_v3", the connection is allowed only if it is SSLv3. Therefore, packets of lower SSL versions are dropped.   

When an HTTPS connection (port 443) is matched on a rule with HTTPS as 'Service' any type of SSL version communication is allowed to pass on this rule.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
