sk183443 - Traffic dropped with "Matched Optimized Drop" message despite being allowed by Rulebase
Traffic dropped with "Matched Optimized Drop" message despite being allowed by Rulebase
Symptoms
- Network traffic is intermittently dropped with the log message: 'Matched optimized drop', even though the traffic should be allowed by the Rulebase.
Cause
This happens due to a drop template being allowed by one sub-policy while another sub-policy below does not allow it (because of some objects that cannot be offloaded - see sk175006).
As a result, the Security Gateway offloads a drop template even though it should not.
Solution
This problem was fixed. The fix is included in:
- Jumbo Hotfix Accumulator for R82 starting from Take 41
- Jumbo Hotfix Accumulator for R81.20 starting from Take 115
If you choose not to upgrade, Check Point can supply a Hotfix. Contact Check Point Support to get a Hotfix for this issue.
A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.
For faster resolution and verification, please collect CPinfo files from the Security Management Server and Security Gateways involved in the case.
Hotfix installation instructions:
Refer to sk168597 - How to install a Hotfix.
NOTE
This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.