<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: I am curious about DPD and TCP Clamp settings when connecting to Check Point and AWS IPsec VPN in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/I-am-curious-about-DPD-and-TCP-Clamp-settings-when-connecting-to/m-p/176489#M32311</link>
    <description>&lt;P&gt;Yes, this impacts all VPNs.&lt;BR /&gt;The main thing it accomplishes is ensuring IPsec packets aren’t getting fragmented because an application communicating through it is trying to use packets larger than can be accommodated.&lt;BR /&gt;Unless an particular system or application is especially poorly behaved, enabling this session should not cause a negative impact.&lt;/P&gt;</description>
    <pubDate>Tue, 28 Mar 2023 21:32:11 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2023-03-28T21:32:11Z</dc:date>
    <item>
      <title>I am curious about DPD and TCP Clamp settings when connecting to Check Point and AWS IPsec VPN</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/I-am-curious-about-DPD-and-TCP-Clamp-settings-when-connecting-to/m-p/176013#M32158</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I recently made a VPN connection between Check Point and AWS.&lt;/P&gt;&lt;P&gt;The method was Static-Route, and fortunately the tunnel comes up normally and communication is normal.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;All that remains are detailed settings for tunnel stability, but I have a question about the TCP MSS Clamp setting&lt;/P&gt;&lt;P&gt;The customer previously operated by connecting Cisco equipment and IPsec VPN on a domain basis, and recently connected AWS and VPN with Routed-Base.&lt;/P&gt;&lt;P&gt;In this situation, it is thought that setting the TCP MSS clamp will affect the existing VPN communication as well.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So, I am curious about how the above settings affect general traffic other than existing IPSec communication and VPN communication.&lt;/P&gt;&lt;P&gt;If anyone has tried the TCP MSS Clamp setting, please let me know if it has any effect on the service or what I am concerned about.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Refer to sk101219 for TCP MSS Clamp setting&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Mar 2023 02:43:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/I-am-curious-about-DPD-and-TCP-Clamp-settings-when-connecting-to/m-p/176013#M32158</guid>
      <dc:creator>ChoiYunSoo</dc:creator>
      <dc:date>2023-03-24T02:43:40Z</dc:date>
    </item>
    <item>
      <title>Re: I am curious about DPD and TCP Clamp settings when connecting to Check Point and AWS IPsec VPN</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/I-am-curious-about-DPD-and-TCP-Clamp-settings-when-connecting-to/m-p/176014#M32159</link>
      <description>&lt;P&gt;If you review &lt;A href="https://support.checkpoint.com/results/sk/sk101219" target="_self"&gt;sk101219&lt;/A&gt; closely, you'll see there are separate clamping settings for VPN and non-VPN traffic.&lt;BR /&gt;Which means that these settings won't affect non-VPN traffic unless you configure it to do so.&lt;/P&gt;
&lt;P&gt;The main reason for this feature is to solve the problem described here:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk98074" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk98074&lt;/A&gt;&lt;BR /&gt;I haven't heard of any issues caused by using this feature, except perhaps through misconfiguration (i.e. forcing a specific MSS value that is problematic).&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Mar 2023 03:14:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/I-am-curious-about-DPD-and-TCP-Clamp-settings-when-connecting-to/m-p/176014#M32159</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-03-24T03:14:13Z</dc:date>
    </item>
    <item>
      <title>Re: I am curious about DPD and TCP Clamp settings when connecting to Check Point and AWS IPsec VPN</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/I-am-curious-about-DPD-and-TCP-Clamp-settings-when-connecting-to/m-p/176021#M32160</link>
      <description>&lt;P&gt;In general you should be able to determine this for yourself with ping tests and the df-bit set in regards to validating MTU / MSS settings etc.&lt;/P&gt;
&lt;P&gt;From tests inside and outside the VPN you should be able to correlate accordingly.&lt;/P&gt;
&lt;P&gt;Tools like psping should allow TCP based probes rather than just ICMP also.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Mar 2023 06:49:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/I-am-curious-about-DPD-and-TCP-Clamp-settings-when-connecting-to/m-p/176021#M32160</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-03-24T06:49:52Z</dc:date>
    </item>
    <item>
      <title>Re: I am curious about DPD and TCP Clamp settings when connecting to Check Point and AWS IPsec VPN</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/I-am-curious-about-DPD-and-TCP-Clamp-settings-when-connecting-to/m-p/176416#M32304</link>
      <description>&lt;P&gt;As you said, I'm trying to change only VPN-related settings.&lt;/P&gt;&lt;P&gt;However, I am concerned that there may be an impact on the existing IPSec VPN&lt;/P&gt;</description>
      <pubDate>Tue, 28 Mar 2023 09:41:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/I-am-curious-about-DPD-and-TCP-Clamp-settings-when-connecting-to/m-p/176416#M32304</guid>
      <dc:creator>ChoiYunSoo</dc:creator>
      <dc:date>2023-03-28T09:41:25Z</dc:date>
    </item>
    <item>
      <title>Re: I am curious about DPD and TCP Clamp settings when connecting to Check Point and AWS IPsec VPN</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/I-am-curious-about-DPD-and-TCP-Clamp-settings-when-connecting-to/m-p/176489#M32311</link>
      <description>&lt;P&gt;Yes, this impacts all VPNs.&lt;BR /&gt;The main thing it accomplishes is ensuring IPsec packets aren’t getting fragmented because an application communicating through it is trying to use packets larger than can be accommodated.&lt;BR /&gt;Unless an particular system or application is especially poorly behaved, enabling this session should not cause a negative impact.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Mar 2023 21:32:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/I-am-curious-about-DPD-and-TCP-Clamp-settings-when-connecting-to/m-p/176489#M32311</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-03-28T21:32:11Z</dc:date>
    </item>
    <item>
      <title>Re: I am curious about DPD and TCP Clamp settings when connecting to Check Point and AWS IPsec VPN</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/I-am-curious-about-DPD-and-TCP-Clamp-settings-when-connecting-to/m-p/177078#M32448</link>
      <description>&lt;P&gt;Thank you for your reply, it helped me a lot&lt;/P&gt;</description>
      <pubDate>Mon, 03 Apr 2023 05:03:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/I-am-curious-about-DPD-and-TCP-Clamp-settings-when-connecting-to/m-p/177078#M32448</guid>
      <dc:creator>ChoiYunSoo</dc:creator>
      <dc:date>2023-04-03T05:03:39Z</dc:date>
    </item>
    <item>
      <title>Re: I am curious about DPD and TCP Clamp settings when connecting to Check Point and AWS IPsec VPN</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/I-am-curious-about-DPD-and-TCP-Clamp-settings-when-connecting-to/m-p/177079#M32449</link>
      <description>&lt;P&gt;thank you for your reply&lt;/P&gt;</description>
      <pubDate>Mon, 03 Apr 2023 05:03:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/I-am-curious-about-DPD-and-TCP-Clamp-settings-when-connecting-to/m-p/177079#M32449</guid>
      <dc:creator>ChoiYunSoo</dc:creator>
      <dc:date>2023-04-03T05:03:55Z</dc:date>
    </item>
  </channel>
</rss>

