> Source: [sk183337](https://support.checkpoint.com/results/sk/sk183337)

# sk183337 - TCP and UDP traffic over VLAN IDs greater than 2048 does not pass through the Maestro Security Group when SecureXL works in the UPPAK mode

| Property | Value |
|----------|-------|
| Solution ID | sk183337 |
| Date Created | 2025-04-09 |
| Last Modified | 2025-05-19 |
| Technical Level | General |
| Products | Scalable Platforms |
| Versions | R82.10, R81.20 |
| OS | Gaia |

## Symptoms

- * TCP and UDP traffic over VLAN IDs greater than 2048 does not pass through the Maestro Security Group when SecureXL works in the UPPAK mode

* ICMP traffic passes as expected over the same VLAN IDs.

* Security Group does not generate any "Drop" logs.

* Traffic capture of TCP and UDP packets shows incomplete communication.

## Cause

This issue occurs only in Maestro Security Groups - in both the Gateway mode and VSX mode.

TCP and UDP traffic goes through SecureXL (that is enabled by default). In a Maestro Security Group, due to an issue in handling VLAN traffic, accelerated traffic cannot pass through the Security Group in this scenario:

1. The affected interfaces are configured with VLAN IDs greater than 2048.
2. SecureXL works in the UPPAK mode.

ICMP traffic is not affected because it goes through the Slow Path (F2F) and bypasses SecureXL.

## Solution

This problem was fixed. The fix is included in:

* [Jumbo Hotfix Accumulator for R81.20](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.20/Default.htm) starting from Take 101

If you choose not to upgrade, Check Point can supply a **Hotfix** . [Contact Check Point Support](https://www.checkpoint.com/support-services/.contact-support/) to get a Hotfix for this issue.  
A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.  
For faster resolution and verification, please collect [CPinfo files](http://supportcontent.checkpoint.com/solutions?id=sk92739) from the Security Management Server and Security Gateways involved in the case.

**Hotfix installation instructions:**   
Refer to [sk168597 - How to install a Hotfix](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk168597).

<br />

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
