> Source: [sk24960](https://support.checkpoint.com/results/sk/sk24960)

# sk24960 - "Smart Connection Reuse" feature modifies some SYN packets 

| Property | Value |
|----------|-------|
| Solution ID | sk24960 |
| Date Created | 2004-02-06 |
| Last Modified | 2026-01-14 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R81.20, R81.10 (EOS), R81 (EOS) |

## Symptoms

- * "`SYN packet on established connection`?" log in SmartView Tracker.

* FW Monitor shows that Security Gateway modifies a TCP \[SYN\] packet to a TCP \[ACK\] packet -
  between Pre-Inbound (small "i") and Post-Inbound (capital "I").

## Cause

This behavior is caused by the "Smart Connection Reuse" feature that solves the connectivity problems related to the TCP \[SYN\] packet on established connection. These problems are caused by a connection-reuse attempt.

Connection reuse can happen when the state of connection in the Security Gateway's Connections table (id 8158) does not match the actual connection state known to the Client and Server. As a result, attempts to establish a new connection using the same source IP address, source port, destination IP address, and destination port fail. This can happen in one of the two following cases:

* The connection was not closed by the Client or Server
* The connection was closed by the Client by sending a TCP \[RST\] packet that did not reach the Security Gateway

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
