Support Center > Search Results > SecureKnowledge Details
"TCP packet out of state" drop message in log Technical Level
Symptoms
  • 'TCP packet out of state' drop message in log.
  • 'fw ctl zdebug drop' shows that traffic is being dropped for "TCP packet out of state: First packet isn't SYN"
  • Wireshark captures shows that the full TCP 3-way handshake is not completing.
Cause

The causes are one or more of the following:

  1. Connection halt during ClusterXL failover - services that are not synchronized on the cluster.
  2. Security Policy install occasionally causes ClusterXL failover - and if connections are not set to keep data or rematch, they are interrupted.
  3. Aggressive aging kicking in on a highly loaded gateway / cluster.
  4. The traffic is non-TCP RFC compliant.
  5. SmartLog shows that traffic is being dropped as "TCP packet out of state: First packet isn't SYN"
  6. Session has been expired.

Solution
Note: To view this solution you need to Sign In .