> Source: [sk120792](https://support.checkpoint.com/results/sk/sk120792)

# sk120792 - "First packet isn't SYN" drop log for SIP over TLS traffic sent to Microsoft Lync Application Server

| Property | Value |
|----------|-------|
| Solution ID | sk120792 |
| Date Created | 2017-10-06 |
| Last Modified | 2017-11-28 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |

## Symptoms

- * SmartView Tracker / SmartLog log shows that SIP over TLS traffic that is used for the client connection to the Microsoft Lync Application Server is dropped:

  |-------------|-------------------------------------------------------------|
  | Action      | Drop                                                        |
  | Service     | sip_tls_authentication (5061)                               |
  | Information | TCP out of state: First packet isn't SYN tcp_flags: FIN-ACK |

  *Example* :  

  [![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk120792/Log.png)](https://sc1.checkpoint.com/sc/SolutionsStatics/sk120792/Log.png "Click the image to see it in full size in a new tab/window")
* Traffic captures on Security Gateway shows the full 3-way TCP handshake between the source client and the Microsoft Lync Application Server. However, the connection does not complete (because Security Gateway drops this traffic) and times out for the client.

## Cause

The involved security rule contains the "`sip_tls`" service, whose default Protocol Type "`SIP_TCP_PROTO`" causes an issue when it strips out the TLS traffic and sends the clear SIP traffic. This then causes the connection to be dropped as out of state.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
