> Source: [sk107324](https://support.checkpoint.com/results/sk/sk107324)

# sk107324 - Some traffic does not pass through Security Gateway and kernel debug shows "...dropped by fw_filter_chain Reason: chain hold"

| Property | Value |
|----------|-------|
| Solution ID | sk107324 |
| Date Created | 2015-08-30 |
| Last Modified | 2021-02-23 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |
| OS | Gaia |

## Symptoms

- * Some traffic does not pass through Security Gateway.

* Kernel debug ('`fw ctl debug -m fw + drop`') shows that the involved traffic is dropped by Security Gateway:  

  `... dropped by fw_filter_chain Reason: chain hold`

* Neither Domain Objects, nor Dynamic Objects are used in the involved policy.

## Cause

Due to high amount of traffic that passes through the Security Gateway, the number of packets in the kernel "hold" table (ID 8183) has reached the table's limit (200 packets).

This can be checked by running the following command on Security Gateway and looking at the "#PEAK" column:

*\[Expert@HostName\]# fw tab -t hold_table -s*

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
