sk182559 - Connections with fragmented packets drop with "Virt Defrag Timeout" error
Connections with fragmented packets drop with "Virt Defrag Timeout" error
Product
Maestro HyperScale Firewall, Scalable Chassis
Version
R81.10 (EOS), R81.20, R82
OS
Gaia
Last Modified
2026-07-23
Symptoms
Connections with fragmented packets drop on Scalable Platform/Maestro when there are multiple active Security Group Members (SGMs) on the site. However, the Scalable Platform does not drop the connections when there is a single active SGM.
Traffic capture with
g_tcpdumpshows that the SGM, which is not the Single Management Object (SMO), handles the connection, and at some point, some packets are forwarded to the Dynamic Routing (DR) Manager SGM.Kernel debug on the SMO/DR Manager shows packets are dropped by "reason: Virt Defrag Timeout":
# fw ctl zdebug + drop
[1_01] ... sim_pkt_send_drop_notification: (0,0) received drop, reason: Virt Defrag Timeout, conn: Connection tuple;
[1_01] ... cphwd_notif_packet_dropped: recieved packet dropped notification, reason: Virt Defrag Timeout;
- Kernel debug on the non-SMO/DR Manager shows packets are "dropped by fwfrag_expires Reason: timeout has expired for fragment":
# fw ctl zdebug + drop
[1_02] ... dropped by fwfrag_expires Reason: timeout has expired for fragment;
Turning off Layer 4 distribution mode does not resolve the issue.
Kernel debug on the non-SMO/DR Manager shows that packets are forwarded to the DR Manager SGM:
# fw ctl zdebug -m cluster + correction
[1_02] ... fwha_ccl_do_correct_by_dr_protocols: Should forward Dynamic Routing packet to DR manager;
[1_02] ... fwha_ccl_do_inbound_correct: Corrected statelessly to member 0 ;
Cause
As fragmented packets do not hold the port information, the Scalable Platform/Maestro mistakenly handles these packets as Dynamic Routing protocol packets and forwards them to the DR manager SGM.
Solution
This problem was fixed. The fix is included in:
- Jumbo Hotfix Accumulator for R82 starting from Take 103
- Jumbo Hotfix Accumulator for R81.20 starting from Take 158
- Jumbo Hotfix Accumulator for R81.10 starting from Take 177
If you choose not to upgrade, Check Point can supply a Hotfix. Contact Check Point Support to get a Hotfix for this issue.
A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.
For faster resolution and verification, please collect CPinfo files from the Security Management Server and Security Gateways involved in the case.
Hotfix installation instructions:
Refer to sk168597 - How to install a Hotfix.
NOTE
This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.
Article Properties
Access Level: General
Status: Approved by TAC
Date Created: 2024-08-01
Last Modified: 2026-07-23