> Source: [sk174368](https://support.checkpoint.com/results/sk/sk174368)

# sk174368 - On Spark Firewall, Site to Site VPN traffic is dropped with this message "fwpslglue_chain Reason: PSL Drop: MUX_PASSIVE"

| Property | Value |
|----------|-------|
| Solution ID | sk174368 |
| Date Created | 2021-07-06 |
| Last Modified | 2026-06-03 |
| Technical Level | General |
| Products | Spark Firewall (Locally Managed) |
| Versions | R82.00.X, R81.10.X |
| Platform | 1570R, 1500, 1600, 1800 |

## Symptoms

- * VPN Site to Site traffic drops with this message: "fwpslglue_chain Reason: PSL Drop: MUX_PASSIVE;"

* MUX_PASSIVE drops in zdebug across Site to Site VPN tunnel

## Cause

Drops were caused by the "Command Injection" IPS protection when users on a 1500 appliance attempted to access the server in another site over VPN.

These drops can also happen on 700/1400 appliances. However, those users do not usually experience drops as this IPS protection is not enabled by default.

## Solution

This problem was fixed. The fix is included in:  

* [**R80.20.25 for Quantum Spark Appliances**](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk171824) (starting from build 992002138)

Check Point recommends to always upgrade to the most recent version [(1600](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doShowproductpage&productTab=overview&product=516), [1500](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doShowproductpage&productTab=overview&product=512), [1570R](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doShowproductpage&productTab=overview&product=515), [1800](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doShowproductpage&productTab=overview&product=517)).  

<br />

The fix is a new advanced-setting created that makes it possible to bypass PSL inspection (IPS included) for VPN traffic. The command to enable this from clish is:

**set vpn site-to-site advanced-settings bypass-psl-inspection true**

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
