Please see my response in this thread:
https://community.checkpoint.com/t5/General-Topics/First-packet-isn-t-SYN/m-p/7021
Whether you should do anything about it depends upon what TCP flags you see reported in the dropped packet. In your case of ACK accompanied by PSH, that would generally indicate that the connection was idled out of the firewall's state table due to inactivity (60 minutes default idle timer).
Attend my online "Be your Own TAC: Part Deux" CheckMates event
March 27th with sessions for both the EMEA and Americas time zones