- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hello all,
We have encountered TCP out of state drops stating First Packet isn't SYN just after 10 mins of the connection initiation from the source. (After inactivity)
The timeout configured in the service port is default 3600 seconds so as per my understanding the connection entry should be there on the firewalls for 1 hour but in this case once the user returns to the application after 10 minutes the user gets disconnected and we can see out of state drop logs as mentioned above.
What could be the possible reasons for this behaviour?
Thanks for any suggestions in advance.
Version/JHF of gateway involved?
What is the precise service in question?
Have you performed any tcpdumps to see what the application is doing during this time?
How is the memory utilisation of the appliance, any signs that aggressive aging has been activated?
If it is R81.10 JHF 66, then R&D is working on it. The fix will be soon.
Did you do a policy install between establishing the connection and "the user returns to the application after 10 minutes"?
If yes, then you can check sk103598 to see if you match a scenario from there.
From R&D;
We have a new workaround to be implemented on the GW:
Please run # fw ctl set int fw_tcp_enforce_half_closed_timeout 1
Install policy.
Hi Cihat,
Is there some SK article regarding this or logged as open bug somewhere to read more details of this condition?
A little more details here: https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 19 | |
| 17 | |
| 14 | |
| 8 | |
| 7 | |
| 3 | |
| 3 | |
| 3 | |
| 3 | |
| 2 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY