> Source: [sk119303](https://support.checkpoint.com/results/sk/sk119303)

# sk119303 - Traffic from a Linux host through Security Gateway is disconnected minutes after the connection is established

| Property | Value |
|----------|-------|
| Solution ID | sk119303 |
| Date Created | 2017-07-26 |
| Last Modified | 2017-07-30 |
| Technical Level | Advanced |
| Products | Security Gateway, Endpoint Security |
| Versions | R82.10, R82, R81.20, Cloud, E89.X, E88.X, R82.20, R82.10, R82, R81.20 |

## Symptoms

- * Traffic from a Linux host through Security Gateway / Cluster is disconnected minutes after the connection is established (e.g., FTP or SSH connection):

  \[Client Host running a Linux OS\] --- \[Check Point Security Gateway\] --- \[Server\]
* Checking for this specific connection repeatedly in the Connections table (ID 8158) on the Security Gateway / Cluster Members (using the `watch "fw tab -t connections -u -f | grep <IP_Address_of_Linux_Host>"` command) shows the following chain of events:

  1. The connection is established and has some TCP Session Timeout
  2. The TCP Session timeout is refreshing
  3. All of a sudden, the connection disappears from the Connections table

## Cause

Cooperative Enforcement is enabled on the Security Gateway / Cluster to authorize clients using an Endpoint Security Server:  
Security Gateway / Cluster properties - expand the "Other" - click on the "Cooperative Enforcement" pane.

*Example* :  
[![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk119303/Check_authorization_1707301348.png)](https://sc1.checkpoint.com/sc/SolutionsStatics/sk119303/Check_authorization_1707301348.png "Click the image to see it in full size in a new tab/window")

Since the host runs on Linux OS, which does not have an Endpoint Security Client / Remote Access, the connection can not be verified and authorized by an Endpoint Security Server. As a result, the Endpoint Security Server creates and installs a Suspicious Activity Monitoring (SAM) Rule (see [sk112061](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk112061)) on the Security Gateway / Cluster Members to drop this traffic.

For additional details, refer to [R77 Security Gateway Technical Administration Guide](http://downloads.checkpoint.com/dc/download.htm?ID=24836) - chapter "Cooperative Enforcement".

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
