# Connections with fragmented packets drop with "Virt Defrag Timeout" error

## Product
Maestro HyperScale Firewall, Scalable Chassis

## Version
R81.10 (EOS), R81.20, R82

## OS
Gaia

## Last Modified
2026-07-23

## Symptoms

- Connections with fragmented packets drop on Scalable Platform/Maestro when there are multiple active Security Group Members (SGMs) on the site. However, the Scalable Platform does not drop the connections when there is a single active SGM.

- Traffic capture with `g_tcpdump` shows that the SGM, which is not the Single Management Object (SMO), handles the connection, and at some point, some packets are forwarded to the Dynamic Routing (DR) Manager SGM.

- Kernel debug on the **SMO/DR Manager** shows packets are dropped by "reason: Virt Defrag Timeout":

```
  # fw ctl zdebug + drop

[1_01] ... sim_pkt_send_drop_notification: (0,0) received drop, reason: Virt Defrag Timeout, conn: Connection tuple;

[1_01] ... cphwd_notif_packet_dropped: recieved packet dropped notification, reason: Virt Defrag Timeout;
  ```

- Kernel debug on the **non-SMO/DR Manager** shows packets are "dropped by fwfrag_expires Reason: timeout has expired for fragment":

```
  # fw ctl zdebug + drop

[1_02] ... dropped by fwfrag_expires Reason: timeout has expired for fragment;
  ```

- Turning off Layer 4 distribution mode does not resolve the issue.

- Kernel debug on the **non-SMO/DR Manager** shows that packets are forwarded to the DR Manager SGM:

```
  # fw ctl zdebug -m cluster + correction

[1_02] ... fwha_ccl_do_correct_by_dr_protocols:  Should forward Dynamic Routing packet to DR manager;

[1_02] ... fwha_ccl_do_inbound_correct: Corrected statelessly  to member 0 ;
  ```

## Cause

As fragmented packets do not hold the port information, the Scalable Platform/Maestro mistakenly handles these packets as Dynamic Routing protocol packets and forwards them to the DR manager SGM.

## Solution

This problem was fixed. The fix is included in:

- [Jumbo Hotfix Accumulator for R82](https://sc1.checkpoint.com/documents/Jumbo_HFA/R82/Default.htm) starting from Take 103
- [Jumbo Hotfix Accumulator for R81.20](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.20/Default.htm) starting from Take 158
- [Jumbo Hotfix Accumulator for R81.10](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.10/Default.htm) starting from Take 177

If you choose not to upgrade, Check Point can supply a **Hotfix**. [Contact Check Point Support](https://www.checkpoint.com/support-services/contact-support/) to get a Hotfix for this issue.

A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.

For faster resolution and verification, please collect [CPinfo files](http://supportcontent.checkpoint.com/solutions?id=sk92739) from the Security Management Server and Security Gateways involved in the case.

**Hotfix installation instructions:**

Refer to [sk168597 - How to install a Hotfix](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk168597).

#### NOTE

This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.

## Article Properties

Access Level: General

Status: Approved by TAC

Date Created: 2024-08-01

Last Modified: 2026-07-23
