# Traffic dropped with "Matched Optimized Drop" message despite being allowed by Rulebase

## Symptoms

- Network traffic is intermittently dropped with the log message: 'Matched optimized drop', even though the traffic should be allowed by the Rulebase.

## Cause

This happens due to a drop template being allowed by one sub-policy while another sub-policy below does not allow it (because of some objects that cannot be offloaded - see [sk175006](https://support.checkpoint.com/results/sk/sk175006)).

As a result, the Security Gateway offloads a drop template even though it should not.

## Solution

This problem was fixed. The fix is included in:

- [Jumbo Hotfix Accumulator for R82](https://sc1.checkpoint.com/documents/Jumbo_HFA/R82/Default.htm) starting from Take 41
- [Jumbo Hotfix Accumulator for R81.20](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.20/Default.htm) starting from Take 115

If you choose not to upgrade, Check Point can supply a **Hotfix**. [Contact Check Point Support](https://www.checkpoint.com/support-services/contact-support/) to get a Hotfix for this issue.

A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.

For faster resolution and verification, please collect [CPinfo files](http://supportcontent.checkpoint.com/solutions?id=sk92739) from the Security Management Server and Security Gateways involved in the case.

**Hotfix installation instructions:**

Refer to [sk168597 - How to install a Hotfix](https://support.checkpoint.com/results/sk/sk168597).

#### NOTE

This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.
