> Source: [sk108053](https://support.checkpoint.com/results/sk/sk108053)

# sk108053 - VPN Connections dropped because of "ICMP error does not match an existing connection"

| Property | Value |
|----------|-------|
| Solution ID | sk108053 |
| Date Created | 2015-12-21 |
| Last Modified | 2017-08-13 |
| Technical Level | Advanced |

## Symptoms

- * Connections are dropped when going through the Security Gateway.
* In SmartView Tracker there is no record of the traffic.
* Kernel debug (`fw ctl debug -m fw + conn log drop`) shows: `
  ;[cpu_x];[fw x_y];fw_log_drop_ex: Packet proto=1 [IP Address 1]:[Port1] -> [IP Address 2]:[Port2] dropped by fw_first_packet_state_checks Reason: ICMP error does not match an existing connection`

## Cause

The VPN traffic packets are being fragmented.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
