> Source: [sk104557](https://support.checkpoint.com/results/sk/sk104557)

# sk104557 - TCP packets are not dropped as Out-of-State when SecureXL is enabled

| Property | Value |
|----------|-------|
| Solution ID | sk104557 |
| Date Created | 2015-02-05 |
| Last Modified | 2018-10-15 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |
| OS | Gaia |

## Symptoms

- When SecureXL is enabled, TCP packets that are received several seconds after the TCP connection is set to expire are accepted instead of being dropped as out of state.

*Example*:

* '`TCP start timeout`' is set to 25 seconds (SmartDashboard - '`Policy`' menu - '`Global Properties...`' - '`Stateful Inspection`' pane)
* RST-ACK packet sent 30 seconds after the last SYN-ACK packet is accepted, although should be dropped
* RST-ACK packet sent 40 seconds after the last SYN-ACK packet is dropped as expected

## Cause

By default, SecureXL waits for 10 seconds from the moment it receives a last TCP packet before timing out the TCP connection. If the last TCP packet arrived within these 10 seconds, the new timeout would be set again to the configured '`TCP start timeout`'.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
