> Source: [sk175125](https://support.checkpoint.com/results/sk/sk175125)

# sk175125 - TCP SIP traffic does not pass through a Security Gateway in Bridge mode

| Property | Value |
|----------|-------|
| Solution ID | sk175125 |
| Date Created | 2021-08-20 |
| Last Modified | 2022-11-23 |
| Technical Level | General |
| Products | Security Gateway, Scalable Platforms |
| Versions | R81.10 (EOS), R81 (EOS), R81.10 (EOS), R81 (EOS) |
| OS | Gaia |

## Symptoms

- * TCP SIP traffic does not pass through a Security Gateway in Bridge mode.

* Kernel debug on the Security Gateway "`fw ctl zdebug + drop`" shows this drop message for the TCP SIP traffic:

  `dropped by fw_handle_first_packet Reason: fwconn_key_init_links (INBOUND) failed;`

## Cause

Chain of events:

1. When the TCP SIP connection opens, it is recorded in the Connections table on the Security Gateway
2. Subsequent packets of the connection arrive to the FireWall inbound chain, but the Security Gateway cannot find their connection in the Connections table because of a connection's link collision between CoreXL Firewall instances.

## Solution

This problem was fixed. The fix is included starting from:

* [Check Point R81.20 (Titan)](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk170416)

Check Point recommends to always upgrade to the most recent version   
([upgrade Security Gateway](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doShowproductpage&productTab=overview&product=435) / [upgrade Security Management Server](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doShowproductpage&productTab=overview&product=184) / [upgrade Multi-Domain Security Management](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doShowproductpage&productTab=overview&product=166)).

<br />

If you choose not to upgrade, Check Point can supply a **Hotfix** . [Contact Check Point Support](https://www.checkpoint.com/support-services/contact-support/) to get a Hotfix for this issue.  
A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.  
For faster resolution and verification, please collect [CPinfo files](http://supportcontent.checkpoint.com/solutions?id=sk92739) from the Security Management Server and Security Gateways involved in the case.

**Hotfix installation instructions:**   
Refer to [sk168597 - How to install a Hotfix](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk168597).

<br />

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
