> Source: [sk184181](https://support.checkpoint.com/results/sk/sk184181)

# sk184181 - Intermittent client timeouts when reusing source ports through a Maestro Security Group with multiple Security Group Members

| Property | Value |
|----------|-------|
| Solution ID | sk184181 |
| Date Created | 2025-11-10 |
| Last Modified | 2026-09-10 |
| Technical Level | General |
| Products | Scalable Platforms |
| Versions | R82.10, R82, R81.20 |
| OS | Gaia |

## Symptoms

- * Intermittent client timeouts occur when reusing source ports through a Maestro Security Group with more than one Security Group Member.

* TCP and UDP connections that reuse the same source ports experience long delays or fail to re-establish.

* The connections remain in the connection table for an extended period, preventing new connections on the reused port.

## Cause

This behavior is caused by delayed or unreliable synchronization of connection deletion events in the gconn table across Security Group Members, particularly under high connection rates and heavy port reuse conditions.

## Solution

This problem was fixed. The fix is included in:

* [Jumbo Hotfix Accumulator for R82.10](https://sc1.checkpoint.com/documents/Jumbo_HFA/R82.10/Default.htm) starting from Take 44
* [Jumbo Hotfix Accumulator for R82](https://sc1.checkpoint.com/documents/Jumbo_HFA/R82/Default.htm) starting from Take 126

If you choose not to upgrade, Check Point can supply a **Hotfix** . [Contact Check Point Support](https://www.checkpoint.com/support-services/contact-support/) to get a Hotfix for this issue.  
A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.  
For faster resolution and verification, please collect [CPinfo files](http://supportcontent.checkpoint.com/solutions?id=sk92739) from the Security Management Server and Security Gateways involved in the case.

**Hotfix installation instructions:**   
Refer to [sk168597 - How to install a Hotfix](https://support.checkpoint.com/results/sk/sk168597).

After installing the Hotfix:  

1. Enable the new kernel parameter to synchronize connection deletion events:  
   `## fw ctl set -f int fwha_sync_conn_on_delete 1`  
   Note: Run this command on **each**Security Group Member.
2. Reboot each Security Group Member one by one.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
