> Source: [sk107618](https://support.checkpoint.com/results/sk/sk107618)

# sk107618 - "First packet isn't SYN" drop logs detected in SmartView Tracker for TCP traffic from ClusterXL in Load Sharing Unicast mode with enabled SecureXL

| Property | Value |
|----------|-------|
| Solution ID | sk107618 |
| Date Created | 2015-09-07 |
| Last Modified | 2021-07-19 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |
| OS | Gaia |

## Symptoms

- * "`The First packet isn't SYN`" drop logs detected in SmartView Tracker for TCP traffic.

* Kernel debug ('`fw ctl debug -m fw + drop conn`') on cluster members shows:  
  * `;fw_log_drop_ex: Packet proto=6 Source_IP:Source_Port -> Dest_IP:Dest_Port dropped by fw_first_packet_state_checks Reason: First packet isn't SYN;`
  * `;FW-1: fw_log_tcp_out_of_state: reason First packet isn't SYN. th_flags 0x11;`
  * `;FW-1: fw_log_tcp_out_of_state: reason First packet isn't SYN. th_flags 0x12;`
  * `;FW-1: fw_log_tcp_out_of_state: reason First packet isn't SYN. th_flags 0x14;`
  * `;FW-1: fw_log_tcp_out_of_state: reason First packet isn't SYN. th_flags 0x18;`
* Issue occurs in the following scenario (all these conditions must exist):

  * ClusterXL in Load Sharing Unicast mode
  * SecureXL is enabled
  * IPS blade is enabled
  * NAT rules are configured for the involved traffic
* Connection is expired in 25 seconds

  * ;fwconn_ent_expire: \[now=xxxxxxxx\] conn Dest_IP:Dest_Port IPP 6\> is expired
  * ;fwconn_ent_expire: SXL/FLOWS decision: expire, new timeout=0, new ttl=0
* Disabling SecureXL resolves the issue.

## Cause

Asymmetric connections that were created as a result of NAT rules and that should be inspected by IPS (Medium Path), could be dropped as Out of State in ClusterXL Load Sharing Unicast with enabled SecureXL due to mismatch in the state of these TCP connections between FireWall and SecureXL.

## Solution

**This problem was fixed. The fix is included in:**

* **R80.10**

**Check Point recommends to always upgrade to the most recent version.
[Check Point R81.10](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk170416)**   
**Related sks:**   

[sk109735 - "TCP packet out of state: First packet isn't SYN; tcp_flags: SYN-ACK" drop log when SecureXL and Application Control / URL Filtering blade are enabled on Security Gateway in Bridge mode](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk109735&partition=Advanced&product=SecureXL)

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
