> Source: [sk92803](https://support.checkpoint.com/results/sk/sk92803)

# sk92803 - Polycom Video conference over H323 (RSVP) dropped by Security Gateway running on SecurePlatform/Gaia OS due to IP options in packets

| Property | Value |
|----------|-------|
| Solution ID | sk92803 |
| Date Created | 2013-05-07 |
| Last Modified | 2025-04-05 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20, R81.10 (EOS), R81 (EOS) |
| OS | Gaia |

## Symptoms

- * Polycom Video conference over H323 is not able to register to the GateKeeper.  

* Kernel debug (`fw ctl debug -m fw + drop`) shows that RSVP traffic is dropped:  
  `fw_log_drop: Packet proto= ... dropped by asm_stateless_verifier Reason: Invalid IP option on packet`  

* Customer is using Polycom video conferencing equipment. This worked correctly when the Security Gateway was R65 on IPSO OS, but since they upgraded to R70 on SecurePlatform OS, packets for the video conferencing are being dropped.

## Cause

By default, Check Point Security Gateway does not allow traffic with "IP Options".

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
