> Source: [sk79880](https://support.checkpoint.com/results/sk/sk79880)

# sk79880 - Traffic is dropped 'by cphwd_offload_conn Reason: VPN and/or NAT traffic between accelerated and non-accelerated interfaces or between non-accelerated interfaces is not allowed'

| Property | Value |
|----------|-------|
| Solution ID | sk79880 |
| Date Created | 2012-07-16 |
| Last Modified | 2019-06-06 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |
| OS | Linux, Gaia |

## Symptoms

- Kernel debug shows (`fw ctl zdebug -m fw + drop`) that traffic is dropped:  

'`... is dropped by cphwd_offload_conn Reason: VPN and/or NAT traffic between accelerated and non-accelerated interfaces or between non-accelerated interfaces is not allowed`'

## Cause

No fix is required; the system is functioning as designed.

SecureXL does not support Point-to-Point interfaces (PPP, PPTP, PPPoE). In case a PPP-interface is detected, SecureXL disables itself on that interface (hence the name '*non-accelerated interface*').

Refer to the following note in any '**Performance Pack Administration Guide** ' ([R65](http://supportcontent.checkpoint.com/documentation_download?ID=7250), [R70](http://supportcontent.checkpoint.com/documentation_download?ID=8739), [R71](http://supportcontent.checkpoint.com/documentation_download?ID=10310), [R75](http://supportcontent.checkpoint.com/documentation_download?ID=11664), [R75.20](http://supportcontent.checkpoint.com/documentation_download?ID=12274), [R75.40](http://supportcontent.checkpoint.com/documentation_download?ID=13101), [R75.40VS](http://supportcontent.checkpoint.com/documentation_download?ID=16203), [R76](http://supportcontent.checkpoint.com/documentation_download?ID=22917), [R77](http://supportcontent.checkpoint.com/documentation_download?id=24808), [R80.10](https://sc1.checkpoint.com/documents/R80.10/WebAdminGuides/EN/CP_R80.10_PerformanceTuning_AdminGuide/html_frameset.htm ), [R80.20](https://sc1.checkpoint.com/documents/R80.20_GA/WebAdminGuides/EN/CP_R80.20_PerformanceTuning_AdminGuide/html_frameset.htm), [R80.30](https://sc1.checkpoint.com/documents/R80.30/WebAdminGuides/EN/CP_R80.30_PerformanceTuning_AdminGuide/html_frameset.htm)):
> **Note:** Performance Pack is automatically disabled on PPTP and PPPoE interfaces.

If a connection is detected, which flows through even one such non-accelerated interface, **and this connection is NATed and/or sent over VPN**, it will be dropped, because SecureXL is not able to handle it: because of NAT (Client Side or Server Side) and/or VPN, some connection parameters are not available - SecureXL is not able to determine how to pass such connection.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
