sk183373 - Cannot browse HTTPS sites after upgrade to R81.20 or higher when HyperFlow is enabled

Cannot browse HTTPS sites after upgrade to R81.20 or higher when HyperFlow is enabled

Product: Security Gateways
Version: R81.20, R82
Last Modified: 2025-09-02

Symptoms

[fw4_26];[vs_0];cml_av_lite_conn_state_process_message: ERROR: Task not allowed. state=0x7f6d71e7bd78 new_task=0x1e, old_task=0x1, policy_task=0x2.

`[fw4_26];[vs_0];cmi_lite_conn_process_single_message: ERROR: app process message failed. state 0x7f6c99521c08. app CML AV LITE. res 4294967295.`

`[fw4_26];[vs_0];cmi_lite_process_message: ERROR: Failed to process message.`

`[fw4_26];[vs_0];ws_lite_mm_process_cmi_msg: ERROR: Failed to process message for CMI lite.`

`[fw4_26];[vs_0];mm_process_messages: ERROR: Process data for message type 13 returned error.`

`[fw4_26];[vs_0];ws_lite_enter_from_main: ERROR: Failed to process Multi Message.`

`[fw4_26];[vs_0];ws_lite_process_data_from_app: ERROR: Failed to enter from WS main.`

`[fw4_26];[vs_0];mux_task_handler: ERROR: Failed to handle task. task=0x7f6c7ec94d98, app_id=5 (WS), mux_state=0x7f6a84472e08, curr_side 1, prev_side 1.`

`[fw4_26];[vs_0];mux_read_handler: ERROR: Failed to handle task queue. mux_state=0x7f6a84472e08.`

`[fw4_26];[vs_0];mux_active_read_handler_cb: ERROR: Failed to forward data to Mux.`

Cause

There is an issue where the IOC feed updates the hash tasks (from default MD5 to SHA1, SHA256), and policy installation does not update these tasks for Hyperflow.

As a result, the HyperFlow defense mechanism does not allow this task because it waits for MD5 only.

Therefore, the traffic is dropped.

Solution

This problem was fixed. The fix is included in:

If you choose not to upgrade, Check Point can supply a Hotfix. Contact Check Point Support to get a Hotfix for this issue.

A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.

For faster resolution and verification, please collect CPinfo files from the Security Management Server and Security Gateways involved in the case.

As a workaround, disable the HyperFlow by running this command on the Security Gateway:

# connection_pipelining prevent

To enable it back, run

# connection_pipelining allow

NOTE

This solution has been verified for the specific scenario described by the combination of Product, Version and Symptoms. It may not work in other scenarios.

Article Properties

Access Level: General
Status: Approved by TAC
Date Created: 2025-04-22
Last Modified: 2025-09-02