> Source: [sk158293](https://support.checkpoint.com/results/sk/sk158293)

# sk158293 - Reject action is seen in log for a rule with Drop action

| Property | Value |
|----------|-------|
| Solution ID | sk158293 |
| Date Created | 2019-09-05 |
| Last Modified | 2020-01-28 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |

## Symptoms

- Reject action is seen in log, on a rule with Drop action.

## Cause

A change was made in the Security Gateway's behaviour with connections which can not be re-directed.

Further explanation:

* In R77.30, connections which could not be redirected (to User Check Block portal, for example), were rejected. The available actions were: Block/Allow/Ask/Inform, while Drop/Accept were not available.

<!-- -->

* In R80.10 and above, User Check block action was translated to Drop . Therefore, connections which could not be redirected were dropped, and not rejected.

<!-- -->

Reject is sending a reset packet on the connection.

On User Check action cases, the Security Gateway should reject the connection when redirect is not possible, since rejecting the connection is the closest action to the User Check action.

Moreover, the reason for rejecting the connection and not dropping it is: retransmissions. If the Security Gateway will drop the connection, there will be retransmissions until the timeout of the connection. Rejecting and not dropping, avoids those unnecessary retransmissions - The client will have better user experience (faster loading) and the gateway will not handle unnecessary connections.

This behaviour change is implemented in:

* [Check Point R80.40](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk160736)
* [Check Point R80.30](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk144293)
* [Jumbo Hotfix Accumulator for R80.20](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk137592) - since *Take_75 and above*
* [Jumbo Hotfix Accumulator for R80.10](http://supportcontent.checkpoint.com/solutions?id=sk116380) - since *Take_215 and above*

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
