An administrator sees 'TCP out of state' drops. Which mechanism should be investigated to ensure the gateway has proper visibility into the traffic?
Asymmetric routing is the most common cause of stateful inspection drops. When traffic returns via a different path, the firewall fails to observe the initial handshake packets, causing subsequent packets to be flagged as 'out of state' because the firewall has no record of the established session.
Why this answer
Stateful inspection requires the firewall to see the entire TCP handshake (SYN, SYN-ACK, ACK). If the return traffic takes a different physical path (asymmetric routing), the gateway cannot validate the state. Adjusting the network topology or implementing features like 'TCP State Verification' bypass or 'Asymmetric Routing' configuration is necessary.
This is a core competency for troubleshooting enterprise networks where complex routing is common.
Exam trap
Candidates often blame the firewall configuration or rules, failing to recognize that 'TCP out of state' is a classic symptom of asymmetric routing where the return path is missing.