<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Issues with mtu over vpn R81.20 in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issues-with-mtu-over-vpn-R81-10/m-p/155499#M26499</link>
    <description>&lt;P&gt;Hi Chris&lt;/P&gt;&lt;P&gt;Thanks for the response, we basically lowered the mtu to 1360 on the inside interface of the firewall.&lt;/P&gt;&lt;P&gt;My mistake, its R81.10&lt;/P&gt;&lt;P&gt;I ran the below commands on the firewall,&amp;nbsp;&lt;/P&gt;&lt;P&gt;[Expert@TEST-FW:0]# fw ctl get int fw_clamp_tcp_mss&lt;BR /&gt;fw_clamp_tcp_mss = 1&lt;/P&gt;&lt;P&gt;With this enabled, what does the firewall clamp it to? would it be the mtu minus the ip and tcp header?&lt;/P&gt;&lt;P&gt;The issue I think is that the ISP has the mtu set to 1400 on there router.&lt;/P&gt;&lt;P&gt;Do we need to do something with the VPN mtu ?&lt;/P&gt;&lt;P&gt;Do I need to enable it on the global properties if it looks like its already enabled on the Gateway itself?&lt;/P&gt;&lt;P&gt;cheers&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 23 Aug 2022 10:03:42 GMT</pubDate>
    <dc:creator>carl_t</dc:creator>
    <dc:date>2022-08-23T10:03:42Z</dc:date>
    <item>
      <title>Issues with mtu over vpn R81.10</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issues-with-mtu-over-vpn-R81-10/m-p/155489#M26497</link>
      <description>&lt;P&gt;Hi Guys&lt;/P&gt;
&lt;P&gt;we appear to be having issues accessing some webservers using https over a vpn between 2 sites.&lt;/P&gt;
&lt;P&gt;We have done some packet analsys and it appears to be when the https handshake is done, the servers certificate exchange packets dont appear to make it to the pc requesting the webpage.&lt;/P&gt;
&lt;P&gt;As with most traffic these days, the DF bit is set in the packet.&lt;/P&gt;
&lt;P&gt;When we lower the mtu on the pc or the inside interface of the firewall the issue appears to go away.&lt;/P&gt;
&lt;P&gt;This is obviously not good practice, when we lower the mtu on the outside interface it does not work, so it must not be applying to the vpn.&lt;/P&gt;
&lt;P&gt;Any ideas what the best thing to do for this?&lt;/P&gt;
&lt;P&gt;cheers&lt;/P&gt;
&lt;P&gt;Carl&lt;/P&gt;</description>
      <pubDate>Tue, 23 Aug 2022 11:56:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issues-with-mtu-over-vpn-R81-10/m-p/155489#M26497</guid>
      <dc:creator>carl_t</dc:creator>
      <dc:date>2022-08-23T11:56:17Z</dc:date>
    </item>
    <item>
      <title>Re: Issues with mtu over vpn R81.20</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issues-with-mtu-over-vpn-R81-10/m-p/155496#M26498</link>
      <description>&lt;P&gt;Is the version definitely R81.20 as this still remains in EA currently.&lt;/P&gt;
&lt;P&gt;Is MSS clamping already configured and what value did you attempt to lower the MTU to?&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="clamp.png" style="width: 823px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/17504i0B76E3997B835899/image-size/large?v=v2&amp;amp;px=999" role="button" title="clamp.png" alt="clamp.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Aug 2022 09:31:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issues-with-mtu-over-vpn-R81-10/m-p/155496#M26498</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-08-23T09:31:50Z</dc:date>
    </item>
    <item>
      <title>Re: Issues with mtu over vpn R81.20</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issues-with-mtu-over-vpn-R81-10/m-p/155499#M26499</link>
      <description>&lt;P&gt;Hi Chris&lt;/P&gt;&lt;P&gt;Thanks for the response, we basically lowered the mtu to 1360 on the inside interface of the firewall.&lt;/P&gt;&lt;P&gt;My mistake, its R81.10&lt;/P&gt;&lt;P&gt;I ran the below commands on the firewall,&amp;nbsp;&lt;/P&gt;&lt;P&gt;[Expert@TEST-FW:0]# fw ctl get int fw_clamp_tcp_mss&lt;BR /&gt;fw_clamp_tcp_mss = 1&lt;/P&gt;&lt;P&gt;With this enabled, what does the firewall clamp it to? would it be the mtu minus the ip and tcp header?&lt;/P&gt;&lt;P&gt;The issue I think is that the ISP has the mtu set to 1400 on there router.&lt;/P&gt;&lt;P&gt;Do we need to do something with the VPN mtu ?&lt;/P&gt;&lt;P&gt;Do I need to enable it on the global properties if it looks like its already enabled on the Gateway itself?&lt;/P&gt;&lt;P&gt;cheers&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Aug 2022 10:03:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issues-with-mtu-over-vpn-R81-10/m-p/155499#M26499</guid>
      <dc:creator>carl_t</dc:creator>
      <dc:date>2022-08-23T10:03:42Z</dc:date>
    </item>
    <item>
      <title>Re: Issues with mtu over vpn R81.20</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issues-with-mtu-over-vpn-R81-10/m-p/155514#M26504</link>
      <description>&lt;P&gt;What is the precise MTU set on all interfaces?&lt;BR /&gt;If your ISP is using 1400, that interface will for sure need to be set to that.&lt;BR /&gt;With the default MTU being 1500, that basically means you’ll have an issue with any packet with a DF bit set over 1400 bytes.&lt;BR /&gt;You will definitely need to adjust MTUs and possibly the policy configuration to allow PMTUD to do its job.&lt;BR /&gt;See:&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk98074&amp;amp;partition=Advanced&amp;amp;product=IPSec" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk98074&amp;amp;partition=Advanced&amp;amp;product=IPSec&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Aug 2022 11:53:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issues-with-mtu-over-vpn-R81-10/m-p/155514#M26504</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-08-23T11:53:49Z</dc:date>
    </item>
  </channel>
</rss>

