Please see my response in this thread:
https://community.checkpoint.com/t5/General-Topics/First-packet-isn-t-SYN/m-p/7021
Whether you should do anything about it depends upon what TCP flags you see reported in the dropped packet. In your case of ACK accompanied by PSH, that would generally indicate that the connection was idled out of the firewall's state table due to inactivity (60 minutes default idle timer).
Attend my 60-minute "Be your Own TAC: Part Deux" Presentation
Exclusively at CPX 2025 Las Vegas Tuesday Feb 25th @ 1:00pm