sk182559 - Connections with fragmented packets drop with "Virt Defrag Timeout" error

Connections with fragmented packets drop with "Virt Defrag Timeout" error

Product

Maestro HyperScale Firewall, Scalable Chassis

Version

R81.10 (EOS), R81.20, R82

OS

Gaia

Last Modified

2026-07-23

Symptoms

  # fw ctl zdebug + drop

[1_01] ... sim_pkt_send_drop_notification: (0,0) received drop, reason: Virt Defrag Timeout, conn: Connection tuple;

[1_01] ... cphwd_notif_packet_dropped: recieved packet dropped notification, reason: Virt Defrag Timeout;
  # fw ctl zdebug + drop

[1_02] ... dropped by fwfrag_expires Reason: timeout has expired for fragment;
  # fw ctl zdebug -m cluster + correction

[1_02] ... fwha_ccl_do_correct_by_dr_protocols:  Should forward Dynamic Routing packet to DR manager;

[1_02] ... fwha_ccl_do_inbound_correct: Corrected statelessly  to member 0 ;

Cause

As fragmented packets do not hold the port information, the Scalable Platform/Maestro mistakenly handles these packets as Dynamic Routing protocol packets and forwards them to the DR manager SGM.

Solution

This problem was fixed. The fix is included in:

If you choose not to upgrade, Check Point can supply a Hotfix. Contact Check Point Support to get a Hotfix for this issue.

A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.

For faster resolution and verification, please collect CPinfo files from the Security Management Server and Security Gateways involved in the case.

Hotfix installation instructions:

Refer to sk168597 - How to install a Hotfix.

NOTE

This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.

Article Properties

Access Level: General

Status: Approved by TAC

Date Created: 2024-08-01

Last Modified: 2026-07-23