> Source: [sk147093](https://support.checkpoint.com/results/sk/sk147093)

# sk147093 - Security Gateway drops TCP packets on 'out of state', although the setting in SmartConsole is turned off

| Property | Value |
|----------|-------|
| Solution ID | sk147093 |
| Date Created | 2019-02-19 |
| Last Modified | 2022-12-22 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R81.20, R81.10 (EOS), R81 (EOS) |
| OS | Gaia |

## Symptoms

- * Security Gateway is dropping TCP packets on 'out of state', although the setting in SmartConsole: Global Properties -\> Stateful Inspection -\> Drop Out of state TCP Packets is not checked.

* Kernel debug (fw ctl zdebug + drop) shows the following packet drops:  

  `
  [DATE TIME];[kern];[tid_0];[SIM-206609312];update_tcp_state: invalid state detected (current state: 0x10000, th_flags=0x14, cdir=1) -> dropping packet, conn: [<SrouceIP,SourcePort,DestinationIP,DestinationPort,6>][PPK0];`  
  `
  [DATE TIME];[kern];[tid_0];[SIM-206609312];do_inbound: Possible TCP state violation for <SrouceIP,SourcePort,DestinationIP,DestinationPort,6> -> dropping packet ;`  
  `
  [DATE TIME];[kern];[tid_0];[SIM-206609312];do_packet_finish: SIMPKT_IN_DROP vsid=10, conn:<SrouceIP,SourcePort,DestinationIP,DestinationPort,6>;`

* Network topology was configured to run TCP traffic asymmetrically. The packets from a source to a destination in one path and takes a different path when it returns to the source.

* Issue does not replicate when SecureXL is off.

## Cause

Different functionality introduced in R80.20 causes SecureXL to drop the packets as "Drop Out of State TCP Packets".

The following Kernel parameters were added to control SecureXL's behavior in this regard:

* ***sim_get_tcp_accept_out_of_state_vs***   

  **Note:** In **[R80.20 Jumbo Hotfix Accumulator](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk137592)Take_48 and higher** , the *sim_get_tcp_accept_out_of_state_vs* will automatically be configured according to the setting in: SmartConsole -\> Global Properties -\> Stateful Inspection -\> Drop Out of state TCP Packets.  
  Every time this setting is changed, the policy needs to be installed again on the Security Gateway. Then verify the value of the parameter '*sim_get_tcp_accept_out_of_state_vs* ' with:  

  **`# fw ctl set int sim_get_tcp_accept_out_of_state_vs <vsid> -a`**   
  **`# fw ctl get int sim_get_tcp_accept_out_of_state_vs -a`**   

  The parameter value should be: '1'. If the output is '0':  

  * Configure the Policy to not drop packets on out of state in:  
    SmartConsole \> Global Properties \> Stateful Inspection \> Drop Out of state TCP Packets.

  <br />

  * Install Policy on the security Gateway

## Solution

This problem was fixed. The fix is included in:

* [Jumbo Hotfix Accumulator for R81](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk170114) starting from Take 34
* [Jumbo Hotfix Accumulator for R80.40](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk165456) starting from Take 114
* [Jumbo Hotfix Accumulator for R80.30](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk153152) added additional fixes since Take 210
* [Jumbo Hotfix Accumulator for R80.30](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk153152) from Take 163
* [Jumbo Hotfix Accumulator for R80.20](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk137592) added additional fixes since Take 160
* [Jumbo Hotfix Accumulator for R80.20](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk137592) from Take 134

<br />

**Important Note:** The kernel parameter was added to resolve the issue in asymmetric TCP traffic scenario. It is not recommended to apply this solution on other scenarios, since it might create security issues.  
The kernel parameters are enabled or disabled for**all** Security Gateways. In a VSX Gateway it is applied to **all** Virtual Systems and Virtual Routers.  

**Note:** For drop of SYN or SYN-ACK TCP packets, refer to: [sk170144 - Security Gateway drops SYN or SYN-ACK TCP packets on 'out of state'](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk170144).  

For **other [supported](http://www.checkpoint.com/support-services/support-life-cycle-policy/index.html) versions** , [Check Point Support](http://www.checkpoint.com/support-services/contact-support/index.html) can supply a **Hotfix** .  
A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.  
For faster resolution and verification, please collect [CPinfo files](http://supportcontent.checkpoint.com/solutions?id=sk92739) from the Security Management Server and Security Gateways involved in the case.  

**Note regarding R80.40 and higher versions:** The new SIM kernel parameter is already integrated, so no hotfix is required.

**Hotfix installation instructions:**

1. Hotfix has to be installed on ***Security Gateway / each cluster member***.

   **Note:** In cluster environment, this procedure must be performed on *all* members of the cluster.   
   **Note:** In Management HA environment, this procedure must be performed on *both* Management Servers.
2. Install the hotfix using CPUSE:

   Make sure to install the [latest build of the CPUSE Agent](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk92449#Latest build of CPUSE and What's New).

   Refer to [sk92449: CPUSE - Gaia Software Updates (including Gaia Software Updates Agent)](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk92449#How to work with CPUSE):
   * Section "[(4-A-c)](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk92449#How to work with CPUSE - How to download and import a CPUSE package - Import instructions for Offline procedure - Gaia Portal)" / "[(4-A-d)](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk92449#How to work with CPUSE - How to download and import a CPUSE package - Import instructions for Offline procedure - Gaia Clish)" - refer to import instructions for *Offline procedure*
   * Section "[(4-B-a)](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk92449#How to work with CPUSE - How to install a CPUSE package - Installing a Hotfix package / Minor Version package)" - refer to installation instructions for *Hotfixes*

   You can also use the [sk111158 - Central Deployment Tool (CDT)](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk111158) to install this hotfix on Security Gateways.

   **Note:** Reboot is required.

**After the Hotfix installation, or in version R80.40 and higher**:

1. Verify value of the parameter '*sim_get_tcp_accept_out_of_state_vs* ' with:  

   **`# fw ctl get int fw_allow_out_of_state_tcp`**   
   **`# fw ctl get int sim_get_tcp_accept_out_of_state_vs -a`**   

2. To enable the parameter on-the-fly, run:  

   **`# fw ctl set int sim_tcp_accept_out_of_state_vs <vsid> -a`**   

3. To drop out of state tcp packets for specifc VS or Gateway: :  

   **`# fw ctl set int sim_tcp_drop_out_of_state_vs <vsid> -a`**   

**Notes:**

* A policy installation will override these values.

* For non-VSX, use VS 0 to set/get the global parameter.

**IMPORTANT:** If you wish to configure this property per specific gateway and not automatically on all your gateways, [contact Check Point Support](https://www.checkpoint.com/support-services/contact-support/) to get a Hotfix for this

**Note:** Refer to [sk26202 - Changing the kernel global parameters for Check Point Security Gateway](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk26202).

**Related solutions:**

* [sk170144 - Security Gateway drops SYN or SYN-ACK TCP packets on 'out of state'](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk170144)
* [sk162092 - TCP traffic with undefined tcp option is dropped as "tcp out of state" when SecureXL is enabled](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk162092)

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
