In this knowlege article we will discuss how to understand the TCP Handshake violation and how to address the issue
Resolution
Navigate to the Investigate|Event Logs and search for TCP handshake violation detected.
Run a capture and check the flags and timestamp
Compare it to the time stamp in the event log
The capture only shows SYN packets being received and not being forwarded.
Check the ARP table to determine if the destination IP address is listed. This can be found under Manage| Network | ARP
If no ARP entry is listed the the firewall will not forward the packets.
A TCP Handshake has not occurred in this particular instance, because only SYN packets are received, and therefore the 3 Way handshake cannot be completed. This is a TCP handshake violation and the connection will be dropped.