> Source: [sk182103](https://support.checkpoint.com/results/sk/sk182103)

# sk182103 - Initial packet (SYN or 1st UDP) to a specific subnet is delayed for 6 seconds

| Property | Value |
|----------|-------|
| Solution ID | sk182103 |
| Date Created | 2024-03-25 |
| Last Modified | 2026-02-09 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R81.20, R81.10 (EOS) |
| OS | Gaia |

## Symptoms

- * Initial packet (SYN or 1st UDP) to a specific subnet is delayed for up to 6 seconds.

* Kernel debug shows: `"NAT rulematch required HOLD"` or `"Unified Rulebase returned HOLD"` logs.

* After the initial delay traffic flows smoothly for the same connection.

* Delay happens again for new connections when the connection entry is removed from the Security Gateways cache.

## Cause

The existence of Non-FQDN objects in the rule base (in Access Control **OR** in Threat Prevention Policy) requires the resolution of reverse DNS lookup queries.  
Until these queries are resolved, the rule base matching on these connections is on hold.  
The time to resolve these queries can change depending on the DNS server in use and their implementation.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
