> Source: [sk114529](https://support.checkpoint.com/results/sk/sk114529)

# sk114529 - Traffic dropped with reason "TCP segment out of maximum allowed sequence"

| Property | Value |
|----------|-------|
| Solution ID | sk114529 |
| Date Created | 2016-11-15 |
| Last Modified | 2023-10-01 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R81.20, R81.10 (EOS), R81 (EOS) |

## Symptoms

- * SmartLog shows IPS drop for traffic with the reason: "`TCP segment out of maximum allowed sequence. Packet dropped.`"
* Memory on the Security Gateway is heavily utilized. Memory usage spikes or is constantly at/above 90% utilization.
* Procedure described in [sk66576](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk66576) does not affect the behavior.

## Cause

When memory usage on the Security Gateway goes above 90%, the window size of all connections going through the firewall is decreased. This can cause this IPS drop:

`Protection Name: TCP Segment Limit Enforcementt`  
` Attack: Streaming Engine: TCP Segment Limit Enforcement Attack`  
` Information: TCP segment out of maximum allowed sequence. Packet dropped.`

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
