The Check Point Firewall has different TCP timeouts defined than the Proxy-SG. The SG tries to Keep TCP sessions open to save handshakes for further requests. The Firewall tries to avoid inactive sessions.
A lot of „Out of state“ packets can be seen in the Check Point „Smart View Tracker“ log file, in case „Out of state“ Drops are logged.
These Drops can be reduced by increasing the HTTP session timeout in the Check Point FW config or decreasing the BlueCoat SG values.
BlueCoad CLI can be used to modify the behavior:
The http persistent-timeout references the amount of time a persistent Connection will remain idle before it will be closed.
To configure the http persistent-timeout, use the following command:
#(config) http persistent-timeout Server #OfSeconds