As the statement in the subject, for some reason, if application connection traffic traverses FW and has TCP long connection over the TCP session timeout setting in the FW, then the connection will be killed and dropped stateless packet by FW, correct?
I found a sk11088 which says the issue had been fixed if upgrade to the target JHF version. Does that fix mean even if the TCP session timeout is exceeded but the packet will not be dropped ? If not , what means for the fixed mentioned in the SK11088?
SK11088,
Symptoms
SmartView Tracker may show multiple logs for TCP packets being dropped as "TCP out of state" packets with the following TCP flag:
SYN packet for established connection
"First packet isn't SYN" drop logs in SmartView Tracker for TCP traffic.
Cause
Some applications do not maintain proper TCP state.
Solution
This problem was fixed. The fix is included starting from:
Jumbo Hotfix Accumulator for R81.10 starting from Take 14
Jumbo Hotfix Accumulator for R81 starting from Take 51
Jumbo Hotfix Accumulator for R80.40 starting from Take 150
Jumbo Hotfix Accumulator for R80.30 starting from Take 241
Jumbo Hotfix Accumulator for R80.20 starting from Take 208