> Source: [sk162575](https://support.checkpoint.com/results/sk/sk162575)

# sk162575 - Failover breaks IPSec SNX client connection

| Property | Value |
|----------|-------|
| Solution ID | sk162575 |
| Date Created | 2019-09-24 |
| Last Modified | 2021-03-15 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |
| OS | Gaia |

## Symptoms

- * Upon failover, the new active member drops the traffic as out-of-state (first packet isn't syn).
* When checking the connections and userc_users tables, they contain the original connections.
* User has to reconnect the client.

## Cause

The connection does not survive failover of HTTPS traffic, including SSL Network Extender (SNX) traffic.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
