If the SYN flag in a packet is not turned on, Versa FlexVNF rejects the first packet of a TCP connection.
FlexVNF devices reject the first packet if it does not have the SYN flag turned on. This FlexVNF behavior is a security measure in response to how TCP starts. A normal TCP connection starts with a three-way handshake, so if the first packet that the FlexVNF sees on the connection is not the SYN packet, the FlexVNF assumes that the packet is not valid, and it discards it. In some situations, such as asymmetric routing, you might want FlexVNF devices to accept the first packet of a TCP connection when the SYN flag is not turned on.
You can use Versa Director to modify the setting per zone:

