# TCP and UDP traffic over VLAN IDs greater than 2048 does not pass through the Maestro Security Group when SecureXL works in the UPPAK mode

**Product**: Maestro HyperScale Firewall  
**Version**: R81.20, R82.10  
**OS**: Gaia  
**Last Modified**: 2025-05-19

## Symptoms

- TCP and UDP traffic over VLAN IDs greater than 2048 does not pass through the Maestro Security Group when SecureXL works in the UPPAK mode
- ICMP traffic passes as expected over the same VLAN IDs.
- Security Group does not generate any "Drop" logs.
- Traffic capture of TCP and UDP packets shows incomplete communication.

## Cause

This issue occurs only in Maestro Security Groups - in both the Gateway mode and VSX mode.

TCP and UDP traffic goes through SecureXL (that is enabled by default). In a Maestro Security Group, due to an issue in handling VLAN traffic, accelerated traffic cannot pass through the Security Group in this scenario:

1. The affected interfaces are configured with VLAN IDs greater than 2048.
2. SecureXL works in the UPPAK mode.

ICMP traffic is not affected because it goes through the Slow Path (F2F) and bypasses SecureXL.

## Solution

This problem was fixed. The fix is included in:

- [Jumbo Hotfix Accumulator for R81.20](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.20/Default.htm) starting from Take 101

If you choose not to upgrade, Check Point can supply a **Hotfix**. [Contact Check Point Support](https://www.checkpoint.com/support-services/.contact-support/) to get a Hotfix for this issue.

A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.

For faster resolution and verification, please collect [CPinfo files](http://supportcontent.checkpoint.com/solutions?id=sk92739) from the Security Management Server and Security Gateways involved in the case.

**Hotfix installation instructions:**

Refer to [sk168597 - How to install a Hotfix](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk168597).

#### NOTE

This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.

## Article Properties

**Access Level**: General  
**Status**: Approved by TAC  
**Date Created**: 2025-04-09  
**Last Modified**: 2025-05-19
