> Source: [sk105855](https://support.checkpoint.com/results/sk/sk105855)

# sk105855 - SecureXL drops DNS packets when "Drop Optimization" and "DNS fast expiry feature" are enabled

| Property | Value |
|----------|-------|
| Solution ID | sk105855 |
| Date Created | 2015-04-26 |
| Last Modified | 2017-02-08 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |
| OS | Gaia |

## Symptoms

- * SecureXL drops DNS packets in the following scenario:

  1. *Drop Optimization* is enabled in Security Gateway / Cluster object (per [sk90861](http://supportcontent.checkpoint.com/solutions?id=sk90861))  

  2. DNS fast expiry feature is enabled (value of "*delete_on_reply* " attribute in the "*domain-udp* " service is set to "*true*")
* SecureXL SIM debug ('`sim dbg -m mgr + add`' *and* '`sim dbg -m err + err`') shows the following failures:

  * ;\[SIM-...\]cphwd_api_add_connection: Adding partial conn over existing conn: not allowed \[\<*Client_IP* ,*Source_Port* ,*DNS_Server_IP* ,53,17\>\];  

  * ;\[SIM-...\]cphwd_api_add_connection: Adding partial conn over existing conn: not allowed \[\<*DNS_Server_IP* ,53,*Client_IP* ,*Dest_Port* ,17\>\];  

  * ;\[SIM-...\]cphwd_api_add_connection: Adding partial conn over existing conn: not allowed (during initialization);

## Cause

Firewall fails to offload partial DNS connections to SecureXL (failure in DNS fast expiry feature for Medium Path DNS connections).  
As a result, there is a conflict between the fast expiry functionality in the Firewall and the fast expiry functionality in SecureXL, which causes collisions upon offloading of the DNS connections for the DNS Reply packets.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
