> Source: [sk106292](https://support.checkpoint.com/results/sk/sk106292)

# sk106292 - Traffic might be dropped with "Virtual defragmentation error: Timeout" log on 21000 series appliance with SAM card

| Property | Value |
|----------|-------|
| Solution ID | sk106292 |
| Date Created | 2015-05-31 |
| Last Modified | 2019-06-24 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |
| OS | Gaia |

## Symptoms

- * Traffic might be dropped with "*Virtual defragmentation error: Timeout*" log when sent over a VPN tunnel established with Check Point 21000 series appliance with SAM card.

  *Example of the log*:
  `
  Type = Log`  
  `
  Action = Drop`  
  `
  Protocol = tcp`  
  `
  Information = message: Virtual defragmentation error: Timeout`  
  `
  ip_id: 12433`  
  `
  ip_len: 152`  
  `
  ip_offset: 1336`  
  `
  fragments_dropped: 8`  
  `
  during_sec: 60`  
  `
  Product = Security Gateway/Management`  
  `
  Product Family = Network
  `
* Disabling SecureXL resolves the issue.

## Cause

**Unique scenario:** The problem occurs when a remote VPN endpoint fragments clear text packets (or receives clear text fragments) before encrypting them. The SAM card processes the encrypted packets successfully, but does not process the fragments within it. As a result, packets after the first fragment are dropped.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
