> Source: [sk94085](https://support.checkpoint.com/results/sk/sk94085)

# sk94085 - TCP traffic is dropped on "IP options" and problematic IP option could not be found in kernel debug

| Property | Value |
|----------|-------|
| Solution ID | sk94085 |
| Date Created | 2013-08-13 |
| Last Modified | 2019-12-11 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |

## Symptoms

- TCP traffic is dropped on "IP options" and problematic IP option could not be found in kernel debug per [sk62082](http://supportcontent.checkpoint.com/solutions?id=sk62082).

*Example*:

X11 in SSH traffic dropped on "IP options" in SmartView Tracker. When running debug per [sk62082](http://supportcontent.checkpoint.com/solutions?id=sk62082) to find and allow IP options:

```

[Expert@HostName]# fw ctl debug 0
[Expert@HostName]# fw ctl debug -buf 32000
[Expert@HostName]# fw ctl debug -m fw + drop ld ipopt filter packval
```

The *allowed_ipopts_proto* value cannot be found.

## Cause

By design, Check Point Security Gateway drops any TCP / UDP / ICMP / GRE packet with IP options (only IGMP packet with "Router Alert" IP option is allowed).

In certain environments, traffic going through Check Point Security Gateway may contain IP options. It may be necessary to allow these packets to pass.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
