I would consult TAC as this is VSX and First packet isn't syn rather sounds like a config error !
See sk117374:
It is possible to override the "Out of State" settings in the Global Properties on the Security Gateway by changing the values of the relevant kernel parameters on-the-fly.
The above procedure is only temporary and will not survive a reboot, restart of Check Point services (cpstop;cpstart
, or cprestart
), or policy installation.
While it is possible to make this setting permanent, this is strongly disapproved ! Why ? You will only cover an error in configuration that better is generally fixed, and sk117374 adds:
The implications of changing the TCP and ICMP out of state inspection settings should be fully understood before altering them.
CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist