> Source: [sk80340](https://support.checkpoint.com/results/sk/sk80340)

# sk80340 - Application Control / URL Filtering rules do not match for Destination 'Internet' when Security Gateway is configured with only one interface

| Property | Value |
|----------|-------|
| Solution ID | sk80340 |
| Date Created | 2012-09-11 |
| Last Modified | 2022-12-25 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R81.20, R81.10 (EOS), R81 (EOS) |

## Symptoms

- * Application Control / URL Filtering rules do not match for Destination 'Internet'.

* The Security Gateway is configured as an HTTP Proxy with a single interface.

* Kernel debug ('`fw ctl debug -m NRB + session`') on the Security Gateway shows:

  `received INzone = External OUTzone = None`
  `
  ``received INzone = Internal OUTzone = None`

## Cause

The Destination "Internet" is inspected only for traffic that passes through External or DMZ interfaces.

## Solution

In the Access Control policy (R80 and higher) / Application \& URL Filtering policy (R77.30 and lower), change the "Destination" column in the rule from "Internet" to "Any":

1. Connect with SmartConsole (R80 and higher) / SmartDashboard (R77.30 and lower) to the Management Server.

   * In SmartConsole (R80 and higher):

     From the left navigation panel, click **Security Policies** \> click **Access Control** \> **Policy**.
   * In SmartDashboard (R77.30 and lower):

     From the top, click the **Application \& URL Filtering** tab \> from the left, click **Policy**.
2. In the applicable rule, configure:

   **`Source`** - '`Any`'

   **`Destination`** - '`Any`'

   To configure '*Any* ' instead of '*Internet*' use either of the methods:
   * Right-click the '*`Internet`* ' object and click '`Remove`' in the context menu
   * Left-click the '*`Internet`* ' object and press the '`Delete`' key on keyboard
3. Save the changes.

4. Install the Access Control policy.

**Related Solutions:**

* [sk88682 - SmartView Tracker shows that Application Control blocked the traffic per the rulebase, however data was still transferred](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk88682)
* [sk65283 - Application Control Blade does not block traffic on IPSO-based Security Gateway when SecureXL is enabled](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk65283)

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
