> Source: [sk35113](https://support.checkpoint.com/results/sk/sk35113)

# sk35113 - Check Point support for SCTP IP protocol in R80.40 and lower

| Property | Value |
|----------|-------|
| Solution ID | sk35113 |
| Date Created | 2008-05-27 |
| Last Modified | 2023-04-09 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |

## Solution

Note - This article applies only to R80.40 and lower versions.

### Introduction

**Stream Control Transmission Protocol (SCTP)** (refer to [RFC 3286](https://tools.ietf.org/html/rfc3286) and [RFC 4960](https://tools.ietf.org/html/rfc4960)) is an end-to-end, connection-oriented protocol that transports data in independent sequenced streams.   
SCTP endpoints support multi-homing; therefore, interface redundancy is built into the protocol. Through selective transmission mechanisms, SCTP resolves errors and buffers the data transmission process.

SCTP provides applications with enhanced performance, reliability, and control functions. This protocol is essential where detection of connection failure and associated monitoring is mandatory. Furthermore, SCTP could be implemented in network systems and applications that deliver voice/data and support quality real-time services (e.g., streaming video and multimedia).

### Check Point support for SCTP IP protocol

SCTP protocol inspection and acceleration is supported by the following Check Point releases:

|----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| Supported deployment                                                                                                                                                                                                                                                                                                                                     | Requirements                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| [R80.40](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk160736) Security Gateway managed by [R80.40](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk160736) Single Security Management Server / Multi-Domain Management Server | Security Gateway must have [R80.40 Jumbo HFA](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk16545) Take 48 installed                                                                                                                                                                                                                                                           |
| [R80.30](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk144293) Security Gateway managed by [R80.30](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk144293) Single Security Management Server / Multi-Domain Management Server | Security Gateway must have [R80.30 Jumbo HFA](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk153152) Take 215 installed                                                                                                                                                                                                                                                         |
| [R80.20](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk122485) Security Gateway managed by [R80.20](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk122485) Single Security Management Server / Multi-Domain Management Server | Security Gateway must have [R80.20 Jumbo HFA Take](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk137592) 156 installed                                                                                                                                                                                                                                                         |
| [R80.10](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk111841) Security Gateway managed by [R80.10](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk111841) Single Security Management Server / Multi-Domain Management Server | N / A                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| [R77.30](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk104859) Security Gateway managed by [R77.30](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk104859) Single Security Management Server / Multi-Domain Management Server | [sk105412 - R77.30 Add-On](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk105412) must be installed on R77.30 Management Server                                                                                                                                                                                                                                                 |
| [R77.10](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk97617) Security Gateway managed by [R77.10](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk97617) Single Security Management Server / Multi-Domain Management Server   | [sk100446 - R77.10 LTE (Long Term Evolution) Hotfix](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk100446) *and* [sk105954 - R77.10 LTE (Long Term Evolution) Hotfix 010](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk105954) must be installed on both R77.10 Security Gateway *and* R77.10 Management Server |

**Important Note:** Upgrading from R77.30 to R80.10 when using SCTP service in rule base is not supported (refer to [sk117237 - R80.10 Pre-Upgrade Verifier notifications and their solutions](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk117237)).

### Configuration in Check Point SmartConsole R80.x

1. Create a new SCTP service:

   |--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
   | Press ***New*** at the right panel, then go to ***Service -\> SCTP*** [![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk35113/R80-11802270721.png)](https://sc1.checkpoint.com/sc/SolutionsStatics/sk35113/R80-11802270721.png "Click the image to see it in full size in a new tab/window") |

2. Configure the new SCTP service:

   |-----------------------------------------|----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
   | Where                                   | Image                                                                                                                                                                                                                      | Settings                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
   | SCTP Service Properties window          | [![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk35113/R80-21802270721.png)](https://sc1.checkpoint.com/sc/SolutionsStatics/sk35113/R80-21802270721.png "Click the image to see it in full size in a new tab/window") | * In the ***Name:*** field, enter the desired name for the service. The name assigned here must be the same as the server service name (as in the services file). If NIS is used, then the firewall automatically retrieves the information from NIS. * In the ***Port:*** field, enter the number of the port that gives this service.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
   | Advanced SCTP Service Properties window | [![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk35113/R80-31802270721.png)](https://sc1.checkpoint.com/sc/SolutionsStatics/sk35113/R80-31802270721.png "Click the image to see it in full size in a new tab/window") | * In the ***Source port:*** field, enter the port number for the client side service. If specified, only those Source port Numbers will be Accepted, Dropped, or Rejected during packet inspection. Otherwise, the source port is not inspected. * Checking the box ***Keep connections open after policy has been installed*** will override the settings on the ***Connection Persistence*** page in the Security Gateway object. * Checking the box ***Enable Aggressive Aging*** set short (aggressive) timeouts for idle connections. When a connection is idle for more than its aggressive timeout value, it is marked as "eligible for deletion" (refer to the IPS protection "Aggressive Aging"). * Checking the box ***Synchronize connections on cluster*** enables synchronization of these connections between cluster members. |

### Configuration in Check Point SmartDashboard R77.30 and lower

Note: Refer to the "LTE (Long Term Evolution) Hotfix" Release Notes in the above solutions articles.

1. Create a new SCTP service:

   |-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
   | Option 1                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  | Option 2                                                                                                                                                                                                                                                                                                                                                                     |
   | 1. Go to the ***Manage*** menu at the top - click on the ***Services...*** [![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk35113/R7x_2.png)](https://sc1.checkpoint.com/sc/SolutionsStatics/sk35113/R7x_2.png "Click the image to see it in full size in a new tab/window") 2. Click on the ***New...*** button - click on the ***SCTP...*** [![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk35113/R7x_3.png)](https://sc1.checkpoint.com/sc/SolutionsStatics/sk35113/R7x_3.png "Click the image to see it in full size in a new tab/window") | 1. At the top, go to the ***Firewall*** tab 2. In the lower left section, go to the ***Services*** pane 3. Right-click on an empty space - click on the ***SCTP...*** [![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk35113/R7x_1.png)](https://sc1.checkpoint.com/sc/SolutionsStatics/sk35113/R7x_1.png "Click the image to see it in full size in a new tab/window") |

2. Configure the new SCTP service:

   |-----------------------------------------|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
   | Where                                   | Image                                                                                                                                                                                                  | Settings                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
   | SCTP Service Properties window          | [![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk35113/R7x_4.png)](https://sc1.checkpoint.com/sc/SolutionsStatics/sk35113/R7x_4.png "Click the image to see it in full size in a new tab/window") | * In the ***Name:*** field, enter the desired name for the service. The name assigned here must be the same as the server service name (as in the services file). If NIS is used, then the firewall automatically retrieves the information from NIS. * In the ***Port:*** field, enter the number of the port that gives this service. * Checking the box ***Keep connections open after policy has been installed*** will override the settings on the ***Connection Persistence*** page in the Security Gateway object.                                                                                                                                |
   | Advanced SCTP Service Properties window | [![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk35113/R7x_5.png)](https://sc1.checkpoint.com/sc/SolutionsStatics/sk35113/R7x_5.png "Click the image to see it in full size in a new tab/window") | * In the ***Source port:*** field, enter the port number for the client side service. If specified, only those Source port Numbers will be Accepted, Dropped, or Rejected during packet inspection. Otherwise, the source port is not inspected. * Checking the box ***Enable Aggressive Aging*** set short (aggressive) timeouts for idle connections. When a connection is idle for more than its aggressive timeout value, it is marked as "eligible for deletion" (refer to the IPS protection "Aggressive Aging"). * Checking the box ***Synchronize connections on cluster*** enables synchronization of these connections between cluster members. |

### Related solutions

* [sk114957 - How to permanently disable the acceleration of SCTP in SecureXL](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk114957)
* [sk119872 - Policy installation on R75.40VS Security Gateway with LTE Hotfix fails due to a verification error about an unsupported SCTP service](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk119872)

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
