Data received before SYN was acknowledged. Stripping all packet data" . Since we have a cluster of 3 External firewall and 2 internet ( Active / Passive ) . So where might be the asymmetric routing happen . between the 3 firewall cluster ?
Is there any solution ? I have see the drop is happening at " Inspection Setting - TCP SYN modified Retransmission " under the default profile . Currently its configured as drop , can we change to Accept ? whether that will create any security vulnerability ?
I changed the TCP SYN modified Retransmission from Drop to Accept , and user is able to access. This is only for a particular website which is hosted in a different site . Only issues for the users in VPN .
Traffic Flow :
User connected CP VPN -- > there is a site to site tunnel to different location