# Traffic is randomly dropped due to loop prevention

**Product**: Security Gateways  
**Version**: R82, R82.00.X, R82.10  
**OS**: Gaia  
**Last Modified**: 2026-07-08

## Symptoms

- Traffic is intermittently dropped by the Security Gateway.
- Kernel debug on the Security Gateway (`fw ctl zdebug + drop`) shows that the relevant traffic is dropped with these messages:
  - `resume_inbound_from_vm_reinject: dropping packet ... due to loop prevention (nloops=4, pkt_type VM Reinject, prev state Lookup, next state Lookup, in flags 0x4)`
  - or
    `...;sim_db_save_conn: saving conn <SOURCE_IP,SOURCE_PORT,DEST_IP,5650,17> for vsid 0, instance 1 ci 0xNNN;`
    `...;sim_db_save_conn: failed to save conn <SOURCE_IP,SOURCE_PORT,DEST_IP,5650,17>, collision (-1);`
    `...;[<SOURCE_IP,SOURCE_PORT,DEST_IP,5650,17>][PPK0] Collides with an existing connection;`
    `...;sim_db_get_any_conn: found conn <SOURCE_IP,SOURCE_PORT,DEST_IP,5650,17>, ci 0xNNN;`
    `...;[<SOURCE_IP,SOURCE_PORT,DEST_IP,5650,17>][PPK0] Connection UUID mismatch, delete zombie connection`

## Cause

The packets are dispatched to different CoreXL Firewall instances, causing a collision in the SecureXL.

Because the same connection cannot be registered twice in SecureXL, this results in a loop between the Firewall and SecureXL modules, ultimately leading to packet drops.

## Solution

This problem was fixed (requires manual configuration).

The fix is included starting from:
- [Jumbo Hotfix Accumulator for R82.10](https://sc1.checkpoint.com/documents/Jumbo_HFA/R82.10/Default.htm) starting from Take 19
- [Jumbo Hotfix Accumulator for R82](https://sc1.checkpoint.com/documents/Jumbo_HFA/R82/Default.htm) starting from Take 103
- SMB R82.00.10 Build 998002250 and above

Check Point recommends to always upgrade to the [Recommended version](https://support.checkpoint.com/results/sk/sk95746).

If you choose not to upgrade, [contact Check Point Support](https://www.checkpoint.com/support-services/contact-support/) to get a Hotfix for your version.

A Support Engineer will make sure the Hotfix is compatible with your environment before providing it.

For faster resolution and verification, collect these files:
1. [CPinfo](https://support.checkpoint.com/results/sk/sk92739) file from the Management Server involved in the case.
2. [CPinfo](https://support.checkpoint.com/results/sk/sk92739) file from the Security Gateway / each Cluster Member involved in the case.

**Instructions after hotfix installation:**

1. Connect to the command line on the Security Gateway / each Cluster Member / Security Group.
2. Log in to the Expert mode.
3. Get the value of the kernel parameter " _fwmultik\_dispatcher\_in\_tap\_mode_":
   
   `fw ctl get int fwmultik_dispatcher_in_tap_mode`

4. If the returned value is "`1`" (one), then identify the configuration file that contains this parameter.

Run:
   
   `grep "fwmultik_dispatcher_in_tap_mode" $FWDIR/boot/modules/fwkern.conf $PPKDIR/conf/simkern.conf`

5. Edit each file that contains this parameter:
   1. Edit the relevant file:
      
      `vi $FWDIR/boot/modules/fwkern.conf`
      
      `vi $PPKDIR/conf/simkern.conf`
   2. Delete this line:
      
      `fwmultik_dispatcher_in_tap_mode=1`
   3. Save the changes in the file and exit Vi editor.
6. Install the Jumbo Hotfix Accumulator / ad-hoc Hotfix.

Refer to [sk168597 - How to install a Hotfix](https://support.checkpoint.com/results/sk/sk168597).
7. Reboot.

#### NOTE

This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.

## Article Properties
**Access Level**: General  
**Status**: Approved by TAC  
**Date Created**: 2025-12-18  
**Last Modified**: 2026-07-08
