> Source: [sk87880](https://support.checkpoint.com/results/sk/sk87880)

# sk87880 - TCP traffic with ECN-setup SYN packets is dropped without logs

| Property | Value |
|----------|-------|
| Solution ID | sk87880 |
| Date Created | 2012-11-16 |
| Last Modified | 2018-10-09 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |

## Symptoms

- * TCP traffic is silently being dropped by the Security Gateway.  

* Kernel debug shows the drop occurs on the explicit rule that allows this traffic.  

* The TCP connection has the Explicit Congestion Notification (ECN) flag set (ECN-setup SYN).

## Cause

Client sends CWR + ECE + SYN, which is a valid combination of TCP flags according to [RFC3168](http://www.ietf.org/rfc/rfc3168.txt) (this is referred to as a "ECN-setup SYN packet" in Section 6.1.1)

When Check Point Active Streaming (CPAS) technology in Security Gateway detects such a new TCP connection, in which the SYN flag is not set, it determines that such a connection cannot be processed. CPAS kernel debug (fw ctl debug -m CPAS + api) shows:  
`cpas_newconn : called upon something other than tcp SYN. Aborting`

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
