> Source: [sk184455](https://support.checkpoint.com/results/sk/sk184455)

# sk184455 - Traffic is randomly dropped due to loop prevention

| Property | Value |
|----------|-------|
| Solution ID | sk184455 |
| Date Created | 2025-12-18 |
| Last Modified | 2026-09-11 |
| Technical Level | General |
| Products | Security Gateway, Check Point Firewall |
| Versions | R82.10, R82, R82.20 |
| OS | Gaia |

## Symptoms

- * Traffic is intermittently dropped by the Security Gateway.

* Kernel debug on the Security Gateway (`fw ctl zdebug + drop`) shows that the relevant traffic is dropped with these messages:

  * `resume_inbound_from_vm_reinject: dropping packet ... due to loop prevention (nloops=4, pkt_type VM Reinject, prev state Lookup, next state Lookup, in flags 0x4)`

  * or

    `...;sim_db_save_conn: saving conn <SOURCE_IP,SOURCE_PORT,DEST_IP,5650,17> for vsid 0, instance 1 ci 0xNNN;`

    `...;sim_db_save_conn: failed to save conn <SOURCE_IP,SOURCE_PORT,DEST_IP,5650,17>, collision (-1);`

    `...;[<SOURCE_IP,SOURCE_PORT,DEST_IP,5650,17>][PPK0] Collides with an existing connection;`

    `...;sim_db_get_any_conn: found conn <SOURCE_IP,SOURCE_PORT,DEST_IP,5650,17>, ci 0xNNN;`

    `...;[<SOURCE_IP,SOURCE_PORT,DEST_IP,5650,17>][PPK0] Connection UUID mismatch, delete zombie connection`

## Cause

The packets are dispatched to different CoreXL Firewall instances, causing a collision in the SecureXL.

Because the same connection cannot be registered twice in SecureXL, this results in a loop between the Firewall and SecureXL modules, ultimately leading to packet drops.

## Solution

This problem was fixed (requires manual configuration).  
The fix is included starting from:

* Check Point R82.20
* [Jumbo Hotfix Accumulator for R82.10](https://sc1.checkpoint.com/documents/Jumbo_HFA/R82.10/Default.htm) starting from Take 19
* [Jumbo Hotfix Accumulator for R82](https://sc1.checkpoint.com/documents/Jumbo_HFA/R82/Default.htm) starting from Take 103
* SMB R82.00.10 Build 998002250 and above

Check Point recommends to always upgrade to the [Recommended version](https://support.checkpoint.com/results/sk/sk95746).

### Instructions for R82.20

In the R82.20 version, the kernel parameter was renamed from "`fwmultik_dispatcher_in_tap_mode`" to "`usdisp_check_reverse_key`".

1. Connect to the command line on the Security Gateway / each Cluster Member / Security Group.

2. Log in to the Expert mode.

3. Get the value of the kernel parameter "*usdisp_check_reverse_key*" from the configuration files:

   `fw ctl get int usdisp_check_reverse_key`
4. If the returned value is "`1`" (one), then identify the configuration file that contains this parameter.  
   Run:

   `grep "usdisp_check_reverse_key" $FWDIR/boot/modules/fwkern.conf $PPKDIR/conf/simkern.conf`
5. Edit each file that contains this parameter:

   1. Edit the relevant file:

      `vi $FWDIR/boot/modules/fwkern.conf`

      `vi $PPKDIR/conf/simkern.conf`
   2. Delete this line:

      `usdisp_check_reverse_key=1`
   3. Save the changes in the file and exit Vi editor.

6. Get the value of the kernel parameter "*usdisp_check_reverse_key*" from the Gaia Unified Configuration database:

   1. Go from the Expert mode to Gaia Clish.

   2. Get the value of the kernel parameter "*usdisp_check_reverse_key*":

      `show param path *usdisp_check_reverse_key`
7. If the column "`Value`" shows "`True`" in any of rows, then set the value of that parameter to its default (which is "`False`"):

   `set param path <FULL PATH> use-default true [comment "<RELEVANT TEXT>"]`

   Example:

   `set param path firewall.ipv4.connection.dispatcher.usdisp_check_reverse_key use-default true comment "Reverted value to default"`
8. Reboot.

### Instructions for R82 and R82.10

1. Connect to the command line on the Security Gateway / each Cluster Member / Security Group.

2. Log in to the Expert mode.

3. Get the value of the kernel parameter "*fwmultik_dispatcher_in_tap_mode*":

   `fw ctl get int fwmultik_dispatcher_in_tap_mode`
4. If the returned value is "`1`" (one), then identify the configuration file that contains this parameter.  
   Run:

   `grep "fwmultik_dispatcher_in_tap_mode" $FWDIR/boot/modules/fwkern.conf $PPKDIR/conf/simkern.conf`
5. Edit each file that contains this parameter:

   1. Edit the relevant file:

      `vi $FWDIR/boot/modules/fwkern.conf`

      `vi $PPKDIR/conf/simkern.conf`
   2. Delete this line:

      `fwmultik_dispatcher_in_tap_mode=1`
   3. Save the changes in the file and exit Vi editor.

6. Install the Jumbo Hotfix Accumulator that contains the fix (see above).

   Refer to [sk168597 - How to install a Hotfix](https://support.checkpoint.com/results/sk/sk168597).
7. Reboot.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
