> Source: [sk181464](https://support.checkpoint.com/results/sk/sk181464)

# sk181464 - Delay or failure in opening new connections through a Scalable Platform Security Group

| Property | Value |
|----------|-------|
| Solution ID | sk181464 |
| Date Created | 2023-09-11 |
| Last Modified | 2024-01-26 |
| Technical Level | General |
| Products | Scalable Platforms |
| Versions | R81.10 (EOS) |
| OS | Gaia |

## Symptoms

- Delay or failure in opening new connections through a Security Group after installing R81.10 Jumbo Hotfix Accumulator Take 106 or higher.

## Cause

This issue affects fully accelerated connections when the Client-to-Server (C2S) and Server-to-Client (S2C) traffic is distributed to different Maestro Security Group Members / Chassis Security Gateway Modules.

The allocated Security Group Member / Chassis Security Gateway Module drops the Client-to-Server (C2S) packets after the TCP \[SYN-ACK\] handshake phase with the error message "`Invalid response to SYN`".

## Solution

This problem was fixed. The fix is included in:  

* **[Jumbo Hotfix Accumulator for R81.10](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.10/Default.htm) starting from Take 128**

<br />

If you choose not to upgrade, the following **workaround** is available:

1. Connect to the command line on the Security Group.

2. If your default shell is Gaia gClish, go to the Expert mode:

   `expert`
3. Force the sticky behavior in the Correction Layer in the current session:

   `g_fw ctl set int ccl_force_sticky 1`
4. Force the sticky behavior in the Correction Layer permanently:

   `g_update_conf_file fwkern.conf ccl_force_sticky=1`

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
