> Source: [sk185095](https://support.checkpoint.com/results/sk/sk185095)

# sk185095 - Strict IPS Profile Drops PIM Traffic Due to Cisco IOS IPv4 DoS Protection

| Property | Value |
|----------|-------|
| Solution ID | sk185095 |
| Date Created | 2026-06-26 |
| Last Modified | 2026-06-30 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |

## Symptoms

- * Protocol Independent Multicast (PIM) traffic is dropped in environments using a Strict IPS profile.
* PIM neighbors are not established.  
  Example:  
  There are no PIM neighbors present.  
* The issue occurs when the relevant IPS protection is active, regardless of configuration consistency.
* The behavior may be inconsistent (for example, PIM neighbors are established only after multiple reboots, but not reliably).
* Logs show drops similar to these:  
  `fw ctl zdebug + drop`  
  `dropped by fw_spii_execute_inspections Reason: spii inspection matrix drop`  
* IPS logs show drops caused by:  
  `Cisco IOS IPv4 Denial of Service`  
* Legitimate PIM traffic may get affected in multicast environments.

## Cause

The IPS protection **Cisco IOS IPv4 Denial of Service** is associated with the legacy vulnerability: **CVE-2003-0567** .  
This vulnerability affected older Cisco IOS devices and is no longer relevant for most modern environments.  
Profile behaviour:  

* Basic / Optimized profiles - Protection is typically **Inactive**.
* Strict profile - Protection may be set to **Prevent**.

When enabled, the protection identifies certain PIM packets as matching the legacy attack pattern and drop them.  
This behavior is related to IPS profile configuration rather than a defect in the IPS engine.  
However, in environments using PIM, it may appear as a false positive because legitimate multicast traffic is dropped.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
