> Source: [sk43033](https://support.checkpoint.com/results/sk/sk43033)

# sk43033 - The FW answers SYN packets on port 1720 - H.323

| Property | Value |
|----------|-------|
| Solution ID | sk43033 |
| Date Created | 2009-10-25 |
| Last Modified | 2025-05-14 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R81.10 (EOS) |

## Symptoms

- * Security Gateway drops packets on port 1720 (H.323).
* Security Gateway may accept the packets depending on the rule base configuration.

## Cause

The Security Gateway uses an active streaming mechanism - CPAS. One of its features is to intercept packets of known protocols (port 1720 for H.323, for example) and arrange them for inspection by the kernel.

There are predefined Check Point services on the security policy, which are configured with the port numbers used by these protocols. When used in rule-base, they cause the Security Gateway to enable the inspection code relevant to the specific protocol.

When other connections which are not related to the known protocols use the same port number, the Security Gateway inspection causes these connections to be dropped.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
