> Source: [sk109405](https://support.checkpoint.com/results/sk/sk109405)

# sk109405 - After enabling IPS blade, specific traffic is dropped as Out of State, although "Drop out of state TCP packets" option is disabled

| Property | Value |
|----------|-------|
| Solution ID | sk109405 |
| Date Created | 2016-01-04 |
| Last Modified | 2021-07-10 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |

## Symptoms

- * Specific traffic is dropped as "Out of State" after enabling IPS blade, although "Drop out of state TCP packets" option is disabled in SmartDashboard (Policy menu - Global Properties - Stateful Inspection).

* Clients are able to connect to the server. However, after an hour of inactivity they get disconnected.

* When the connection is idle, the application server sends keep alive packets to the client after more than 1 hour.

## Cause

By default, connections are removed from Security Gateway's Connections Table after 1 hour (default timeout). If the stateful inspection "Drop out of state TCP packets" option is disabled, then Firewall blade will not drop "out of state" TCP packets.

However, when enabling IPS blade, it always enforces stateful inspection dropping all out of state packets, regardless of whether IPS mode is set to prevent or detect.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
