> Source: [sk114976](https://support.checkpoint.com/results/sk/sk114976)

# sk114976 - Asymmetric traffic is dropped on Security Gateway with enabled SecureXL and several Bridge interfaces

| Property | Value |
|----------|-------|
| Solution ID | sk114976 |
| Date Created | 2016-12-13 |
| Last Modified | 2021-11-30 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |

## Symptoms

- * Asymmetric traffic is dropped on Security Gateway in the following scenario:

  1. SecureXL is enabled
  2. Two Bridge interfaces are configured:  
     Client --- \[Bridge1\] (Security Gateway with SecureXL) \[Bridge2\] --- Server
  3. Client-to-Server traffic passes through slaves of one of the Bridge interfaces:  
     Client \<===\> \[Bridge1\] (Security Gateway with SecureXL) \[Bridge2\] --- Server
  4. Server-to-Client traffic passes through slaves of the other the Bridge interface:  
     Client --- \[Bridge1\] (Security Gateway with SecureXL) \[Bridge2\] \<===\> Server
* Disabling SecureXL (SecureXL Address-Spoofing feature to be exact) resolves the issue.

* SecureXL debug may show *address spoofing* drops.

## Cause

SecureXL does not update the routes for bridged traffic.

As a result, instead of forwarding the Server-to-Client traffic from one slave of the Server's Bridge interface to the other slave of the Server's Bridge interface, SecureXL forwards the Server-to-Client traffic to the original Client's Bridge interface that was offloaded to SecureXL when Client-to-Server traffic passed for the first time:

1. Client-to-Server traffic enters the Security Gateway via the Client's Bridge interface "Bridge1":  
   Client ===\> \[Bridge1\] (Security Gateway with SecureXL) \[Bridge2\] --- Server

2. Client's Bridge interface "Bridge1" is offloaded to SecureXL

3. Client-to-Server traffic exits from the Security Gateway via the Client's Bridge interface "Bridge1":  
   Client \<=== \[Bridge1\] (Security Gateway with SecureXL) \[Bridge2\] --- Server

4. Server-to-Client traffic enters the Security Gateway via the Server's Bridge interface "Bridge2":  
   Client --- \[Bridge1\] (Security Gateway with SecureXL) \[Bridge2\] \<=== Server

5. SecureXL incorrectly calculates the route for Server-to-Client traffic

6. Server-to-Client traffic exits from the Security Gateway via the Client's Bridge interface "Bridge1" (instead of the Server's Bridge interface "Bridge2"):  
   Client \<=== \[Bridge1\] (Security Gateway with SecureXL) \[Bridge2\] --- Server

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
