sk184455 - Traffic is randomly dropped due to loop prevention

Traffic is randomly dropped due to loop prevention

Product: Security Gateways
Version: R82, R82.00.X, R82.10
OS: Gaia
Last Modified: 2026-07-08

Symptoms

Cause

The packets are dispatched to different CoreXL Firewall instances, causing a collision in the SecureXL.

Because the same connection cannot be registered twice in SecureXL, this results in a loop between the Firewall and SecureXL modules, ultimately leading to packet drops.

Solution

This problem was fixed (requires manual configuration).

The fix is included starting from:

Check Point recommends to always upgrade to the Recommended version.

If you choose not to upgrade, contact Check Point Support to get a Hotfix for your version.

A Support Engineer will make sure the Hotfix is compatible with your environment before providing it.

For faster resolution and verification, collect these files:

  1. CPinfo file from the Management Server involved in the case.
  2. CPinfo file from the Security Gateway / each Cluster Member involved in the case.

Instructions after hotfix installation:

  1. Connect to the command line on the Security Gateway / each Cluster Member / Security Group.

  2. Log in to the Expert mode.

  3. Get the value of the kernel parameter " fwmultik_dispatcher_in_tap_mode":

    fw ctl get int fwmultik_dispatcher_in_tap_mode

  4. If the returned value is "1" (one), then identify the configuration file that contains this parameter.

Run:

grep "fwmultik_dispatcher_in_tap_mode" $FWDIR/boot/modules/fwkern.conf $PPKDIR/conf/simkern.conf

  1. Edit each file that contains this parameter:
    1. Edit the relevant file:

      vi $FWDIR/boot/modules/fwkern.conf

      vi $PPKDIR/conf/simkern.conf

    2. Delete this line:

      fwmultik_dispatcher_in_tap_mode=1

    3. Save the changes in the file and exit Vi editor.

  2. Install the Jumbo Hotfix Accumulator / ad-hoc Hotfix.

Refer to sk168597 - How to install a Hotfix. 7. Reboot.

NOTE

This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.

Article Properties

Access Level: General
Status: Approved by TAC
Date Created: 2025-12-18
Last Modified: 2026-07-08