> Source: [sk183396](https://support.checkpoint.com/results/sk/sk183396)

# sk183396 - Access to the Gaia Portal and SSH fails on both cluster members

| Property | Value |
|----------|-------|
| Solution ID | sk183396 |
| Date Created | 2025-05-20 |
| Last Modified | 2025-05-22 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82, R81.20 |
| OS | Gaia |
| Platform | 29000 |

## Symptoms

- * The Gaia Portal fails to load on both cluster members with error: `ERR_CONNECTION_CLOSED`.

* SmartConsole logs indicate that the Security Gateway accepted the connection attempt.

* Running the `fw unloadlocal` command on the cluster memebrs restores access to the Gaia Portal and to the command line interface through SSH. However, after policy installation, both Gaia Portal access and SSH connectivity are lost again.

* After running `fw ctl zdebug + drop`, these packet drop messages show:  

  `@;...[fw4_62];fw_log_drop_ex: Packet proto=6 <ip_address>:56529 -> <ip_address>:443 dropped by fw_first_packet_state_checks Reason: First packet isn't SYN;`  

  or  

  `@;...[fw4_62];fw_log_drop_ex: Packet proto=6 <ip_address>:56529 -> <ip_address>:22 dropped by fw_first_packet_state_checks Reason: First packet isn't SYN;` .

## Cause

After a policy installation, the Security Gateways drop existing connections because the default configuration does not preserve them.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
