sk180673 - Latency in loading websites when using Security Gateway as proxy with HTTPS Inspection enabled
Latency in loading websites when using Security Gateway as proxy with HTTPS Inspection enabled
Symptoms
- When Security Gateway is configured as a Transparent or Non-Transparent proxy and performing HTTPS Inspection, some websites take a long time to load.
Cause
When the Security Gateway is configured as proxy, it causes HTTP2 Inspection infrastructure to work differently. In this rare scenario, the stream gets closed prematurely.
Solution
This problem was fixed. The fix is included in:
- Jumbo Hotfix Accumulator for R81.20 starting from Take 43
- Jumbo Hotfix Accumulator for R81.10 starting from Take 131
- Jumbo Hotfix Accumulator for R81 starting from Take 87
- Jumbo Hotfix Accumulator for R80.40 starting from Take 211
If you choose not to upgrade, there is a workaround:
Disabling HTTP2 inspection removes the latency. The instructions how to disable HTTP2 inspection can be used from: sk116022 - Check Point inspection of HTTP/2 protocol (RFC 7540)
If the workaround is implemented, once upgrading to version/Jumbo Hotfix which includes the fix, HTTP2 inspection should be re-enabled. In rare situations, some websites will not load if HTTP2 inspection is disabled.
NOTE
This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.
Article Properties
Access Level: General
Status: Approved by TAC
Date Created: 2023-03-07
Last Modified: 2025-03-25