Hi All,
I would like to confirm that follow traffic is the same TCP session.
The traffic is dropped because the connection table is not synced (Blades 1 to 6) SYN-ACK packet received on member Id 2-4
the first traffic Accepted on PRT-VS1-TRUST-EXT as below;
Src: nsh-sci-02 (10.100.229.52) s_port: 65253 dst: 10.136.96.24 d_port:20001 -25 Jan 25, 3:53:29 a.m.
![vs1.png vs1.png](https://community.checkpoint.com/t5/image/serverpage/image-id/29489iE7071653C41651BF/image-size/large?v=v2&px=999)
the traffic Accepted next FW PRT-VS2-TRUST-InT-IAAS as below;
Src: nsh-sci-02 (10.100.229.52) s_port: 65253 dst: 10.136.96.24 d_port:20001 on Member Id: 2_ 2 -25 Jan 25, 3:53:29 a.m.
![vs1-accept.png vs1-accept.png](https://community.checkpoint.com/t5/image/serverpage/image-id/29490i9F05001EF99D4739/image-size/large?v=v2&px=999)
then traffic dropped on PRT-VS2-TRUST-InT-IAAS, Member Id 2_4 was dropped packet at 25 Jan 25, 3:56:42 a.m.
![vs2-dropped.png vs2-dropped.png](https://community.checkpoint.com/t5/image/serverpage/image-id/29488iEACB43CB82D9B63E/image-size/large?v=v2&px=999)
due to 3 minutes time differece Accect(25 Jan 25, 3:53:29 a.m.) and drop(25 Jan 25, 3:56:42 a.m.), someone advised that it might not be the same TCP session.
Are there any ways to confirm that this is the same TCP connection establishment travering different firewalls ?
![marker.png marker.png](https://community.checkpoint.com/t5/image/serverpage/image-id/29491i54B81077E5C0FFD6/image-size/large?v=v2&px=999)