<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: R80.10 gateway, can't set sim_clamp_vpn_mss in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/R80-10-gateway-can-t-set-sim-clamp-vpn-mss/m-p/11878#M1817</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;To adjust&amp;nbsp;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;mss_value in cluster env I have to adjust on all gw object or cluster object?&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 18 Sep 2018 14:34:14 GMT</pubDate>
    <dc:creator>Worapong_Janloy</dc:creator>
    <dc:date>2018-09-18T14:34:14Z</dc:date>
    <item>
      <title>R80.10 gateway, can't set sim_clamp_vpn_mss</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-10-gateway-can-t-set-sim-clamp-vpn-mss/m-p/11852#M1791</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;We recently went from R75.46 to R80.10 on a new cluster.&lt;/P&gt;&lt;P&gt;But now we are experiencing IPSec VPN issues, mostly with Azure VPN gw.&lt;/P&gt;&lt;P&gt;We have verified that this is an MTU/MSS issue by temporarily lowering MTU on one of our AD DCs in-house as well as one of the Azure AD servers. However that is not a desirable configuration in the long run.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After plowing through a bunch of SKs I have concluded that what we need to do is enable the&amp;nbsp;sim_clamp_vpn_mss kernel parameter.&lt;/P&gt;&lt;P&gt;Following instructions in this SK doesn't work, even if it says that it applies to R80.10&lt;/P&gt;&lt;P&gt;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk101219" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk101219"&gt;New VPN features in R77.20&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So how can we enable&amp;nbsp;sim_clamp_vpn_mss?&lt;/P&gt;&lt;P&gt;Is it as simple as using GuiDBedit?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here are the relevant settings from one of the cluster gateways:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Edited &lt;SPAN&gt;simkern.conf&lt;/SPAN&gt; and rebooted, no effect.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;# @cat $PPKDIR/boot/modules/simkern.conf&lt;BR /&gt;sim_clamp_vpn_mss=1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;# fw ctl get int fw_clamp_vpn_mss &lt;BR /&gt;fw_clamp_vpn_mss = 1&lt;BR /&gt; &lt;BR /&gt;# fw ctl get int sim_clamp_vpn_mss&lt;BR /&gt;fw: Get operation failed: failed to get parameter&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;# fw ctl get int fw_clamp_tcp_mss &lt;BR /&gt;fw_clamp_tcp_mss = 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;# fw ctl get int fw_clamp_tcp_mss_control&lt;BR /&gt;fw: Get operation failed: failed to get parameter&lt;BR /&gt; &lt;BR /&gt;# fw ctl get int mss_value &lt;BR /&gt;fw: Get operation failed: failed to get parameter&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;# fw ctl get int sim_ipsec_dont_fragment&lt;BR /&gt;fw: Get operation failed: failed to get parameter&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;# fw ctl get int sim_keep_DF_flag &lt;BR /&gt;fw: Get operation failed: failed to get parameter&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any ideas?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.checkpoint.com/migrated-users/41867"&gt;Hakan Palmryd&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Nov 2017 20:05:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-10-gateway-can-t-set-sim-clamp-vpn-mss/m-p/11852#M1791</guid>
      <dc:creator>Johan_Hillstrom</dc:creator>
      <dc:date>2017-11-14T20:05:32Z</dc:date>
    </item>
    <item>
      <title>Re: R80.10 gateway, can't set sim_clamp_vpn_mss</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-10-gateway-can-t-set-sim-clamp-vpn-mss/m-p/11853#M1792</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hakan,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I recall changing these settings when setting up the tunnels to AWS VPG.&lt;/P&gt;&lt;P&gt;According to the document on AWS describing VPN with Check Point:&lt;/P&gt;&lt;P class="" style="background-color: #ffffff; font-size: 16px; margin-bottom: 12px;"&gt;&lt;STRONG&gt;To enable TCP MSS clamping&lt;/STRONG&gt;&lt;/P&gt;&lt;OL style="color: #444444; background-color: #ffffff;"&gt;&lt;LI style="font-size: 16px;"&gt;&lt;P style="font-size: 16px;"&gt;Navigate to the following directory:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;CODE class=""&gt;C:\Program Files (x86)\CheckPoint\SmartConsole\R77.10\PROGRAM\&lt;/CODE&gt;.&lt;/P&gt;&lt;/LI&gt;&lt;LI style="font-size: 16px;"&gt;&lt;P style="font-size: 16px;"&gt;Open the Check Point Database Tool by running the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;CODE class=""&gt;GuiDBEdit.exe&lt;/CODE&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;file.&lt;/P&gt;&lt;/LI&gt;&lt;LI style="font-size: 16px;"&gt;&lt;P style="font-size: 16px;"&gt;Choose&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Table&lt;/STRONG&gt;,&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Global Properties&lt;/STRONG&gt;,&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;properties&lt;/STRONG&gt;.&lt;/P&gt;&lt;/LI&gt;&lt;LI style="font-size: 16px;"&gt;&lt;P style="font-size: 16px;"&gt;For&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;CODE class=""&gt;fw_clamp_tcp_mss&lt;/CODE&gt;, choose&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Edit&lt;/STRONG&gt;. Change the value to&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;CODE class=""&gt;true&lt;/CODE&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;and choose&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;OK&lt;/STRONG&gt;.&lt;/P&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The source could be found here:&lt;/P&gt;&lt;P&gt;&lt;A class="link-titled" href="http://docs.aws.amazon.com/AmazonVPC/latest/NetworkAdminGuide/check-point-NoBGP.html#check-point-dpd" title="http://docs.aws.amazon.com/AmazonVPC/latest/NetworkAdminGuide/check-point-NoBGP.html#check-point-dpd"&gt;Example: Check Point Device without Border Gateway Protocol - Amazon Virtual Private Cloud&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Nov 2017 21:03:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-10-gateway-can-t-set-sim-clamp-vpn-mss/m-p/11853#M1792</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2017-11-14T21:03:17Z</dc:date>
    </item>
    <item>
      <title>Re: R80.10 gateway, can't set sim_clamp_vpn_mss</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-10-gateway-can-t-set-sim-clamp-vpn-mss/m-p/11854#M1793</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Vladimir.&lt;/P&gt;&lt;P&gt;Thanks for your quick reply.&lt;/P&gt;&lt;P&gt;The problem is that we only want to enable MSS clamping on VPN tunnels, not globally on the gateway.&lt;/P&gt;&lt;P&gt;Also, the "sim_clamp_vpn_mss" &amp;nbsp;parameter is not defined at all, searching for it in GuiDBEdit yields nothing.&lt;/P&gt;&lt;P&gt;(However fw_clamp_vpn_mss is enabled, so disabling SecureXL would probably work, but obviously that is not a desired solution)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So it is still a mystery how to define and enable this setting in R80.10...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;/Johan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Nov 2017 21:16:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-10-gateway-can-t-set-sim-clamp-vpn-mss/m-p/11854#M1793</guid>
      <dc:creator>Johan_Hillstrom</dc:creator>
      <dc:date>2017-11-14T21:16:22Z</dc:date>
    </item>
    <item>
      <title>Re: R80.10 gateway, can't set sim_clamp_vpn_mss</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-10-gateway-can-t-set-sim-clamp-vpn-mss/m-p/11855#M1794</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Johan,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am as well uncertain if it is possible to implement it exclusively on tunnels, but considering that creation of VTIs will disable CoreXL, maybe using Azure's (or AWS), default VPN gateways is not&amp;nbsp;the best option unless you have dedicated on-premises check point gateways allocated for cloud connectivity specifically.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Nov 2017 21:29:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-10-gateway-can-t-set-sim-clamp-vpn-mss/m-p/11855#M1794</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2017-11-14T21:29:34Z</dc:date>
    </item>
    <item>
      <title>Re: R80.10 gateway, can't set sim_clamp_vpn_mss</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-10-gateway-can-t-set-sim-clamp-vpn-mss/m-p/11856#M1795</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;sim_clamp_vpn_mss definitely exists in the simmod SecureXL driver in R80.10, so you have the right variable name and it hasn't changed.&amp;nbsp; Unfortunately there is no way to query the live value of SecureXL variables, unlike doing fw ctl get int for the INSPECT driver.&amp;nbsp; Looks like you have verified the proper variables are set for clamping in the INSPECT driver.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would suggest running "sim vpn off; fwaccel off; fwaccel on" and see if the situation improves.&amp;nbsp; That command will force all VPN traffic into INSPECT (where it will hopefully get clamped correctly) and keep SecureXL from handling it at all.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&lt;BR /&gt; My book "Max Power: Check Point Firewall Performance Optimization" &lt;BR /&gt; now available via &lt;A href="http://maxpowerfirewalls.com" target="_blank"&gt;http://maxpowerfirewalls.com&lt;/A&gt;.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Nov 2017 22:11:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-10-gateway-can-t-set-sim-clamp-vpn-mss/m-p/11856#M1795</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2017-11-14T22:11:58Z</dc:date>
    </item>
    <item>
      <title>Re: R80.10 gateway, can't set sim_clamp_vpn_mss</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-10-gateway-can-t-set-sim-clamp-vpn-mss/m-p/11857#M1796</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for your insight on this.&lt;/P&gt;&lt;P&gt;Yeah, crippling SecureXL would obviously verify that we are correct in our assumptions.&lt;/P&gt;&lt;P&gt;Not sure what the performance hit would be?&lt;/P&gt;&lt;P&gt;We run about a dozen IPSec tunnels across the globe...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyhow, I will disable VPN acceleration now and see if thing look better.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;/Johan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Nov 2017 22:22:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-10-gateway-can-t-set-sim-clamp-vpn-mss/m-p/11857#M1796</guid>
      <dc:creator>Johan_Hillstrom</dc:creator>
      <dc:date>2017-11-14T22:22:16Z</dc:date>
    </item>
    <item>
      <title>Re: R80.10 gateway, can't set sim_clamp_vpn_mss</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-10-gateway-can-t-set-sim-clamp-vpn-mss/m-p/11858#M1797</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Just nitpicking, but syntax appears to have changed to&amp;nbsp;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;fwaccel on|off&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;Change verified by fwaccel stat, showing "Cryptography Features Mask : not available"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;Let's see if it works.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;/Johan&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Nov 2017 22:28:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-10-gateway-can-t-set-sim-clamp-vpn-mss/m-p/11858#M1797</guid>
      <dc:creator>Johan_Hillstrom</dc:creator>
      <dc:date>2017-11-14T22:28:50Z</dc:date>
    </item>
    <item>
      <title>Re: R80.10 gateway, can't set sim_clamp_vpn_mss</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-10-gateway-can-t-set-sim-clamp-vpn-mss/m-p/11859#M1798</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Those commands don't really cripple SecureXL, it will still do all acceleration except site to site VPN.&amp;nbsp; Shouldn't be a huge performance hit.&amp;nbsp; Also fixed syntax in above commands.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&lt;BR /&gt; My book "Max Power: Check Point Firewall Performance Optimization" &lt;BR /&gt; now available via &lt;A class="" href="http://maxpowerfirewalls.com" rel="nofollow"&gt;http://maxpowerfirewalls.com&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Nov 2017 22:31:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-10-gateway-can-t-set-sim-clamp-vpn-mss/m-p/11859#M1798</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2017-11-14T22:31:56Z</dc:date>
    </item>
    <item>
      <title>Re: R80.10 gateway, can't set sim_clamp_vpn_mss</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-10-gateway-can-t-set-sim-clamp-vpn-mss/m-p/11860#M1799</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;SUCCESS!&lt;/P&gt;&lt;P&gt;Following &lt;A href="https://community.checkpoint.com/migrated-users/41625"&gt;Tim Hall&lt;/A&gt;‌ 's suggestions appear do have done the trick.&lt;/P&gt;&lt;P&gt;Running 'tcpdump -i &amp;lt;IF-name&amp;gt; host &amp;lt;a.b.c.d&amp;gt; and "tcp[13] == 2"' now shows MSS adjusted down to 1366 as opposed to 1460&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Lets just hop the AD-replications complete successfully now...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;/Johan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Nov 2017 22:48:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-10-gateway-can-t-set-sim-clamp-vpn-mss/m-p/11860#M1799</guid>
      <dc:creator>Johan_Hillstrom</dc:creator>
      <dc:date>2017-11-14T22:48:43Z</dc:date>
    </item>
    <item>
      <title>Re: R80.10 gateway, can't set sim_clamp_vpn_mss</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-10-gateway-can-t-set-sim-clamp-vpn-mss/m-p/11861#M1800</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Glad to hear it, however it sounds like MSS clamping (or setting the variable) has a problem with SecureXL for R80.10.&amp;nbsp; Are you running the latest R80.10 GA jumbo hotfix?&amp;nbsp; There don't seem to be any fixes related to your problem in the jumbo HFAs but I thought I'd ask anyway.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&lt;BR /&gt; My book "Max Power: Check Point Firewall Performance Optimization" &lt;BR /&gt; now available via &lt;A class="" href="http://maxpowerfirewalls.com" rel="nofollow"&gt;http://maxpowerfirewalls.com&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Nov 2017 22:55:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-10-gateway-can-t-set-sim-clamp-vpn-mss/m-p/11861#M1800</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2017-11-14T22:55:19Z</dc:date>
    </item>
    <item>
      <title>Re: R80.10 gateway, can't set sim_clamp_vpn_mss</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-10-gateway-can-t-set-sim-clamp-vpn-mss/m-p/11862#M1801</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, up-to-date on the maintrain release, no custom HFs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;# fw ver&lt;BR /&gt;This is Check Point's software version R80.10 - Build 423&lt;BR /&gt;# fwaccel ver&lt;BR /&gt;Firewall version: R80.10 - Build 025&lt;BR /&gt;Acceleration Device: Performance Pack &lt;BR /&gt;Accelerator Version 2.1&lt;BR /&gt;Firewall API version: 2.91NG (15/5/2014)&lt;BR /&gt;Accelerator API version: 2.91NG (15/5/2014)&lt;BR /&gt;# &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Nov 2017 22:59:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-10-gateway-can-t-set-sim-clamp-vpn-mss/m-p/11862#M1801</guid>
      <dc:creator>Johan_Hillstrom</dc:creator>
      <dc:date>2017-11-14T22:59:08Z</dc:date>
    </item>
    <item>
      <title>Re: R80.10 gateway, can't set sim_clamp_vpn_mss</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-10-gateway-can-t-set-sim-clamp-vpn-mss/m-p/11863#M1802</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;OK hopefully &lt;A _jive_internal="true" data-userid="2075" href="https://community.checkpoint.com/people/dwelccfe6e688-522c-305c-adaa-194bd7a7becc"&gt;Dameon Welch Abernathy&lt;/A&gt; will see this thread and can alert the SecureXL team about this possible issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&lt;BR /&gt; My book "Max Power: Check Point Firewall Performance Optimization" &lt;BR /&gt; now available via &lt;A class="" href="http://maxpowerfirewalls.com" rel="nofollow"&gt;http://maxpowerfirewalls.com&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Nov 2017 23:07:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-10-gateway-can-t-set-sim-clamp-vpn-mss/m-p/11863#M1802</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2017-11-14T23:07:55Z</dc:date>
    </item>
    <item>
      <title>Re: R80.10 gateway, can't set sim_clamp_vpn_mss</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-10-gateway-can-t-set-sim-clamp-vpn-mss/m-p/11864#M1803</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I eventually get to all the threads on CheckMates &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;P&gt;While I will alert the relevant R&amp;amp;D folks, your best bet is to open a TAC case:&amp;nbsp;&lt;A class="link-titled" href="http://www.checkpoint.com/support-services/contact-support/index.html" title="http://www.checkpoint.com/support-services/contact-support/index.html"&gt;Contact Support | Check Point Software&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Nov 2017 23:32:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-10-gateway-can-t-set-sim-clamp-vpn-mss/m-p/11864#M1803</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2017-11-14T23:32:01Z</dc:date>
    </item>
    <item>
      <title>Re: R80.10 gateway, can't set sim_clamp_vpn_mss</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-10-gateway-can-t-set-sim-clamp-vpn-mss/m-p/11865#M1804</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think I'll drop this in the Swedish SEs' lap... &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ping &lt;A href="https://community.checkpoint.com/migrated-users/41867"&gt;https://community.checkpoint.com/people/hakane93c2d47-872d-4ed8-a523-121a5b601b8e&lt;/A&gt;‌ &lt;A href="https://community.checkpoint.com/migrated-users/42651"&gt;https://community.checkpoint.com/people/fredre96b5099-96e3-3899-b4f8-9f1cb401955d&lt;/A&gt;‌&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Nov 2017 23:40:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-10-gateway-can-t-set-sim-clamp-vpn-mss/m-p/11865#M1804</guid>
      <dc:creator>Johan_Hillstrom</dc:creator>
      <dc:date>2017-11-14T23:40:10Z</dc:date>
    </item>
    <item>
      <title>Re: R80.10 gateway, can't set sim_clamp_vpn_mss</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-10-gateway-can-t-set-sim-clamp-vpn-mss/m-p/11866#M1805</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;One last thing: the &lt;STRONG&gt;sim vpn off&lt;/STRONG&gt; command will not survive a reboot.&amp;nbsp; To make it persistent add sim_is_vpn_disabled=1 to $PPKDIR/boot/modules/simkern.conf.&amp;nbsp; Because there is no way to pull the live state of SecureXL variables, I'm curious to see if adding this variable works properly in your environment, such that after a reboot &lt;STRONG&gt;fwaccel stat&lt;/STRONG&gt; says that cryptography features are disabled which &lt;EM&gt;can&lt;/EM&gt; easily be checked.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I find it odd that the clamping function in SecureXL is suddenly broken in R80.10, and wonder if the sim_clamp_vpn_mss variable is just not being set properly at boot time.&amp;nbsp; Might be interesting to run an &lt;STRONG&gt;od -c $PPKDIR/boot/modules/simkern.conf&lt;/STRONG&gt; to make sure there are no unprintable characters messing up the parsing of the file at boot, also did you see any sim errors written to syslog at boot time?&amp;nbsp; Pretty sure that's where simmod would complain if it had a boot-time problem parsing the simkern.conf file.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&lt;BR /&gt; My book "Max Power: Check Point Firewall Performance Optimization" &lt;BR /&gt; now available via &lt;A class="" href="http://maxpowerfirewalls.com" rel="nofollow"&gt;http://maxpowerfirewalls.com&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Nov 2017 12:48:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-10-gateway-can-t-set-sim-clamp-vpn-mss/m-p/11866#M1805</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2017-11-15T12:48:20Z</dc:date>
    </item>
    <item>
      <title>Re: R80.10 gateway, can't set sim_clamp_vpn_mss</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-10-gateway-can-t-set-sim-clamp-vpn-mss/m-p/11867#M1806</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;Unfortunately, sim vpn off led to a lot of problems with our tunnels to older GWs, both R77.30 and R75.46 (I know, we SHOULD update)&lt;/P&gt;&lt;P&gt;Really weird behavior where we saw outgoing traffic getting encrypted, but 0 packets coming back.&lt;/P&gt;&lt;P&gt;And at the far end of the tunnel we saw exactly nothing.&lt;/P&gt;&lt;P&gt;So I guess we completely broke MSS, leading to silent drops..&lt;/P&gt;&lt;P&gt;I have started the process of creating a TAC, will post case # here when we get it. (On Collaborative support ;-(&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the od -c, found no sim related errors, will do a reboot of passive gateway later tonight.&lt;/P&gt;&lt;P style="color: #000000; background-color: #ffffff; font-size: 19px;"&gt;&lt;SPAN&gt;# od -c $PPKDIR/boot/modules/simkern.conf&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="color: #000000; background-color: #ffffff; font-size: 19px;"&gt;&lt;SPAN&gt;0000000 &amp;nbsp; s &amp;nbsp; i &amp;nbsp; m &amp;nbsp; _ &amp;nbsp; c &amp;nbsp; l &amp;nbsp; a &amp;nbsp; m &amp;nbsp; p &amp;nbsp; _ &amp;nbsp; v &amp;nbsp; p &amp;nbsp; n &amp;nbsp; _ &amp;nbsp; m &amp;nbsp; s&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="color: #000000; background-color: #ffffff; font-size: 19px;"&gt;&lt;SPAN&gt;0000020 &amp;nbsp; s &amp;nbsp; = &amp;nbsp; 1&amp;nbsp; \n&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="color: #000000; background-color: #ffffff; font-size: 19px;"&gt;&lt;SPAN&gt;0000024&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;/Johan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Nov 2017 15:07:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-10-gateway-can-t-set-sim-clamp-vpn-mss/m-p/11867#M1806</guid>
      <dc:creator>Johan_Hillstrom</dc:creator>
      <dc:date>2017-11-15T15:07:17Z</dc:date>
    </item>
    <item>
      <title>Re: R80.10 gateway, can't set sim_clamp_vpn_mss</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-10-gateway-can-t-set-sim-clamp-vpn-mss/m-p/11868#M1807</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;We had a similar issue and here is how we solved it with TAC:&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;1. Enable MSS Clamping on the Gateway for VPN&lt;BR /&gt;fw ctl set int fw_clamp_vpn_mss 1&lt;/P&gt;&lt;P&gt;If SecureXL is enable you have to enable MSS Clamping in SecureXL&lt;BR /&gt;vi $PPKDIR/boot/modules/simkern.conf&lt;BR /&gt;sim_clamp_vpn_mss=1&lt;/P&gt;&lt;P&gt;Reboot the GW . I don't know how to reload this parameter on fly&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;2. Decrease MSS value via GUIDbEdit&lt;BR /&gt; Set "mss_value" to the desired value (1360 in our case) on each involved interface in the VPN communication&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Nicolas&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Nov 2017 19:56:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-10-gateway-can-t-set-sim-clamp-vpn-mss/m-p/11868#M1807</guid>
      <dc:creator>CP-NDA</dc:creator>
      <dc:date>2017-11-15T19:56:33Z</dc:date>
    </item>
    <item>
      <title>Re: R80.10 gateway, can't set sim_clamp_vpn_mss</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-10-gateway-can-t-set-sim-clamp-vpn-mss/m-p/11869#M1808</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry for late feedback on this.&lt;/P&gt;&lt;P&gt;We got the same answer as Nicolas from TAC.&lt;/P&gt;&lt;P&gt;Enabling&amp;nbsp;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;fw_clamp_vpn_mss, AND manually specifying&amp;nbsp;&lt;SPAN&gt;mss_value (we set 1350 per MS recommendations)&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;&lt;SPAN&gt;Previously we had&amp;nbsp;&lt;SPAN style="background-color: #ffffff;"&gt;mss_value set to 0 to facilitate automatic calculation of MSS.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;&lt;SPAN&gt;Strange thing is that this was working properly on R75.46, so apparently something has changed when it comes to automatically calculating MSS.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Nov 2017 07:47:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-10-gateway-can-t-set-sim-clamp-vpn-mss/m-p/11869#M1808</guid>
      <dc:creator>Johan_Hillstrom</dc:creator>
      <dc:date>2017-11-21T07:47:45Z</dc:date>
    </item>
    <item>
      <title>Re: R80.10 gateway, can't set sim_clamp_vpn_mss</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-10-gateway-can-t-set-sim-clamp-vpn-mss/m-p/11870#M1809</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Johan, thanks for the update.&lt;/P&gt;&lt;P&gt;Did you set mss_value globally or on specific interfaces? I'm curious to&amp;nbsp;learn if there are any negative side effects from setting it globally.. I have a client with the same issue as described in OP, except that we were able to set all values but with no effect.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Jan 2018 07:21:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-10-gateway-can-t-set-sim-clamp-vpn-mss/m-p/11870#M1809</guid>
      <dc:creator>Ilmo_Anttonen</dc:creator>
      <dc:date>2018-01-03T07:21:44Z</dc:date>
    </item>
    <item>
      <title>Re: R80.10 gateway, can't set sim_clamp_vpn_mss</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-10-gateway-can-t-set-sim-clamp-vpn-mss/m-p/11871#M1810</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes we set it globally on each interfaces involved in the VPN communication (External / Internal / DMZ / ...)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Jan 2018 07:39:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-10-gateway-can-t-set-sim-clamp-vpn-mss/m-p/11871#M1810</guid>
      <dc:creator>CP-NDA</dc:creator>
      <dc:date>2018-01-03T07:39:45Z</dc:date>
    </item>
  </channel>
</rss>

