> Source: [sk160333](https://support.checkpoint.com/results/sk/sk160333)

# sk160333 - Traffic drop on  R80.20 Security Gateway when SecureXL is enabled

| Property | Value |
|----------|-------|
| Solution ID | sk160333 |
| Date Created | 2019-08-14 |
| Last Modified | 2019-12-30 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |
| OS | Gaia |

## Symptoms

- * Traffic drop on R80.20 Security Gateway when SecureXL is enabled.
* In Kernel Debug output the following flow can be seen:  
  \[-- Stateful VM outbound: Entering (1565357364) --\];  
  Before VM: \<dir 1, 192.168.161.1:4 -\> 10.10.10.186:3 IPP 1\> (len=576) ICMP protocol=1, type=3, code=4 Internal packet: \<dir 1, 10.20.10.18:46291 -\> 10.10.10.186:3225 IPP 6\> (ifn=15) (looked up) ;  
  fw_filter_chain: fwconn_chain_conn_exists returned 1 (conn=\<dir 1, 192.168.161.1:4 -\> 10.10.10.186:3 IPP 1\>, is new 0), chain 0xffffc20059fe3a20;  
  fw_cluster_ttl_anti_spoofing: conn=\<dir 1, 192.168.161.1:4 -\> 10.10.10.186:3 IPP 1\>;  
  fw_conn_inspect: Packet accepted (fast path);  
  fw_conn_post_inspect: First server side outbound packet is an ICMP error;  
  fw_log_drop_ex: Packet proto=1 192.168.161.1:772 -\> 10.10.10.186:45126 dropped by fw_conn_post_inspect Reason: First server side outbound packet is an ICMP error;  
  fw_filter_chain: fw_conn_post_inspect returned action VANISH;  
  fw_filter_chain: Final switch, action=VANISH;  
  After VM: \<dir 1, 192.168.161.1:4 -\> 10.10.10.186:3 IPP 1\> (len=576) ICMP protocol=1, type=3, code=4 Internal packet: \<dir 0, 10.20.10.18:46291 -\> 10.10.10.186:3225 IPP 6\> ;  
  VM Final action=VANISH;  
  ----- Stateful VM outbound Completed -----

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
