sk184455 - Traffic is randomly dropped due to loop prevention
Traffic is randomly dropped due to loop prevention
Product: Security Gateways
Version: R82, R82.00.X, R82.10
OS: Gaia
Last Modified: 2026-07-08
Symptoms
- Traffic is intermittently dropped by the Security Gateway.
- Kernel debug on the Security Gateway (
fw ctl zdebug + drop) shows that the relevant traffic is dropped with these messages:resume_inbound_from_vm_reinject: dropping packet ... due to loop prevention (nloops=4, pkt_type VM Reinject, prev state Lookup, next state Lookup, in flags 0x4)- or
...;sim_db_save_conn: saving conn <SOURCE_IP,SOURCE_PORT,DEST_IP,5650,17> for vsid 0, instance 1 ci 0xNNN;...;sim_db_save_conn: failed to save conn <SOURCE_IP,SOURCE_PORT,DEST_IP,5650,17>, collision (-1);...;[<SOURCE_IP,SOURCE_PORT,DEST_IP,5650,17>][PPK0] Collides with an existing connection;...;sim_db_get_any_conn: found conn <SOURCE_IP,SOURCE_PORT,DEST_IP,5650,17>, ci 0xNNN;...;[<SOURCE_IP,SOURCE_PORT,DEST_IP,5650,17>][PPK0] Connection UUID mismatch, delete zombie connection
Cause
The packets are dispatched to different CoreXL Firewall instances, causing a collision in the SecureXL.
Because the same connection cannot be registered twice in SecureXL, this results in a loop between the Firewall and SecureXL modules, ultimately leading to packet drops.
Solution
This problem was fixed (requires manual configuration).
The fix is included starting from:
- Jumbo Hotfix Accumulator for R82.10 starting from Take 19
- Jumbo Hotfix Accumulator for R82 starting from Take 103
- SMB R82.00.10 Build 998002250 and above
Check Point recommends to always upgrade to the Recommended version.
If you choose not to upgrade, contact Check Point Support to get a Hotfix for your version.
A Support Engineer will make sure the Hotfix is compatible with your environment before providing it.
For faster resolution and verification, collect these files:
- CPinfo file from the Management Server involved in the case.
- CPinfo file from the Security Gateway / each Cluster Member involved in the case.
Instructions after hotfix installation:
Connect to the command line on the Security Gateway / each Cluster Member / Security Group.
Log in to the Expert mode.
Get the value of the kernel parameter " fwmultik_dispatcher_in_tap_mode":
fw ctl get int fwmultik_dispatcher_in_tap_modeIf the returned value is "
1" (one), then identify the configuration file that contains this parameter.
Run:
grep "fwmultik_dispatcher_in_tap_mode" $FWDIR/boot/modules/fwkern.conf $PPKDIR/conf/simkern.conf
- Edit each file that contains this parameter:
Edit the relevant file:
vi $FWDIR/boot/modules/fwkern.confvi $PPKDIR/conf/simkern.confDelete this line:
fwmultik_dispatcher_in_tap_mode=1Save the changes in the file and exit Vi editor.
- Install the Jumbo Hotfix Accumulator / ad-hoc Hotfix.
Refer to sk168597 - How to install a Hotfix. 7. Reboot.
NOTE
This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.
Article Properties
Access Level: General
Status: Approved by TAC
Date Created: 2025-12-18
Last Modified: 2026-07-08