<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to enable pmtud on gaia VSX R81 in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/How-to-enable-pmtud-on-gaia-VSX-R81/m-p/189036#M31699</link>
    <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;I can't find checkpoint SK that describes how to enable path mtu discovery on gaia. May be someone have it and share it here ?&lt;/P&gt;&lt;P&gt;I only found how to configure mss clamping but i'm not interested about this feature because this one is only for tcp trafic and not for udp.&lt;/P&gt;&lt;P&gt;Thanks a lot for your reply.&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;</description>
    <pubDate>Wed, 09 Aug 2023 10:00:42 GMT</pubDate>
    <dc:creator>DZ_KB</dc:creator>
    <dc:date>2023-08-09T10:00:42Z</dc:date>
    <item>
      <title>How to enable pmtud on gaia VSX R81</title>
      <link>https://community.checkpoint.com/t5/General-Topics/How-to-enable-pmtud-on-gaia-VSX-R81/m-p/189036#M31699</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;I can't find checkpoint SK that describes how to enable path mtu discovery on gaia. May be someone have it and share it here ?&lt;/P&gt;&lt;P&gt;I only found how to configure mss clamping but i'm not interested about this feature because this one is only for tcp trafic and not for udp.&lt;/P&gt;&lt;P&gt;Thanks a lot for your reply.&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Aug 2023 10:00:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/How-to-enable-pmtud-on-gaia-VSX-R81/m-p/189036#M31699</guid>
      <dc:creator>DZ_KB</dc:creator>
      <dc:date>2023-08-09T10:00:42Z</dc:date>
    </item>
    <item>
      <title>Re: How to enable pmtud on gaia VSX R81</title>
      <link>https://community.checkpoint.com/t5/General-Topics/How-to-enable-pmtud-on-gaia-VSX-R81/m-p/189039#M31700</link>
      <description>&lt;P&gt;Did you already review&amp;nbsp;&lt;SPAN&gt;sk98074?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Some previous discussion on this topic here:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://community.checkpoint.com/t5/General-Topics/Path-MTU-Discovery/td-p/65814#M13457" target="_blank"&gt;https://community.checkpoint.com/t5/General-Topics/Path-MTU-Discovery/td-p/65814#M13457&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Aug 2023 10:12:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/How-to-enable-pmtud-on-gaia-VSX-R81/m-p/189039#M31700</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-08-09T10:12:36Z</dc:date>
    </item>
    <item>
      <title>Re: How to enable pmtud on gaia VSX R81</title>
      <link>https://community.checkpoint.com/t5/General-Topics/How-to-enable-pmtud-on-gaia-VSX-R81/m-p/189040#M31701</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/3630"&gt;@Chris_Atkinson&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;These links seems to be for vpn ipsec. I don't have vpn ipsec.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Aug 2023 10:20:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/How-to-enable-pmtud-on-gaia-VSX-R81/m-p/189040#M31701</guid>
      <dc:creator>DZ_KB</dc:creator>
      <dc:date>2023-08-09T10:20:07Z</dc:date>
    </item>
    <item>
      <title>Re: How to enable pmtud on gaia VSX R81</title>
      <link>https://community.checkpoint.com/t5/General-Topics/How-to-enable-pmtud-on-gaia-VSX-R81/m-p/189050#M31703</link>
      <description>&lt;P&gt;Yes these articles highlight a common use case.&lt;/P&gt;
&lt;P&gt;PMTUD relies upon ICMP messages that aren't reliably allowed end-to-end which hampers the process.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Aug 2023 11:15:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/How-to-enable-pmtud-on-gaia-VSX-R81/m-p/189050#M31703</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-08-09T11:15:47Z</dc:date>
    </item>
    <item>
      <title>Re: How to enable pmtud on gaia VSX R81</title>
      <link>https://community.checkpoint.com/t5/General-Topics/How-to-enable-pmtud-on-gaia-VSX-R81/m-p/189051#M31704</link>
      <description>&lt;P&gt;all icmp messages are allowed on the path of my network. I only need to enable pmtud on my firewall gateway but i can't find checkpoint documentation wich explain how to.......Or may be it's enabled by default ?&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Aug 2023 11:22:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/How-to-enable-pmtud-on-gaia-VSX-R81/m-p/189051#M31704</guid>
      <dc:creator>DZ_KB</dc:creator>
      <dc:date>2023-08-09T11:22:49Z</dc:date>
    </item>
    <item>
      <title>Re: How to enable pmtud on gaia VSX R81</title>
      <link>https://community.checkpoint.com/t5/General-Topics/How-to-enable-pmtud-on-gaia-VSX-R81/m-p/189053#M31705</link>
      <description>&lt;P&gt;Do you see symptoms similar to this?&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/General-Topics/Fragment-Reassembly-Time-Exceeded-Errors/m-p/77289#M15726" target="_blank"&gt;https://community.checkpoint.com/t5/General-Topics/Fragment-Reassembly-Time-Exceeded-Errors/m-p/77289#M15726&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Aug 2023 11:41:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/How-to-enable-pmtud-on-gaia-VSX-R81/m-p/189053#M31705</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-08-09T11:41:31Z</dc:date>
    </item>
    <item>
      <title>Re: How to enable pmtud on gaia VSX R81</title>
      <link>https://community.checkpoint.com/t5/General-Topics/How-to-enable-pmtud-on-gaia-VSX-R81/m-p/189056#M31706</link>
      <description>&lt;P&gt;No&lt;/P&gt;</description>
      <pubDate>Wed, 09 Aug 2023 12:08:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/How-to-enable-pmtud-on-gaia-VSX-R81/m-p/189056#M31706</guid>
      <dc:creator>DZ_KB</dc:creator>
      <dc:date>2023-08-09T12:08:20Z</dc:date>
    </item>
    <item>
      <title>Re: How to enable pmtud on gaia VSX R81</title>
      <link>https://community.checkpoint.com/t5/General-Topics/How-to-enable-pmtud-on-gaia-VSX-R81/m-p/189101#M31710</link>
      <description>&lt;P&gt;Path MTU discovery is an available function of Gaia/Linux and is controlled by these /proc/sys/net/ipv4 variables:&lt;/P&gt;
&lt;P&gt;ip_forward_use_pmtu = 0&lt;/P&gt;
&lt;P&gt;ip_no_pmtu_disc = 0&lt;/P&gt;
&lt;P&gt;Both of these are set to zero by default, which I interpret as the Gaia OS is not trying to perform Path MTU Discovery for either forwarded packets, or packets that terminate connections on the gateway itself (ssh sessions, Gaia web interface, etc.)&amp;nbsp; However I'm seeing conflicting documentation about that second variable, with some claiming a value of 0 means it is on, but others saying that 0 means it is off.&amp;nbsp; Generally it is a very bad idea to include a negative like "no" in a variable name, since if it is set to zero is that then a double negative, which is equivalent to a positive (therefore enabled)?&amp;nbsp; My head hurts now...&lt;/P&gt;
&lt;P&gt;But anyway I suspect the PMTU for IPSec VPN traffic is being handled directly by the SecureXL/INSPECT code and not the Gaia OS.&amp;nbsp; Either way you need to make sure your firewall policy accepts ICMP type 3 code 4 traffic inbound from anywhere.&amp;nbsp; I don't know what will happen if you attempt to directly poke these two variables away from zero via expert mode; doing so would almost certainly not be supported and may cause other problems.&amp;nbsp; Will probably have to ask TAC.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Aug 2023 17:43:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/How-to-enable-pmtud-on-gaia-VSX-R81/m-p/189101#M31710</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2023-08-09T17:43:31Z</dc:date>
    </item>
    <item>
      <title>Re: How to enable pmtud on gaia VSX R81</title>
      <link>https://community.checkpoint.com/t5/General-Topics/How-to-enable-pmtud-on-gaia-VSX-R81/m-p/189469#M31782</link>
      <description>&lt;P&gt;I have done the test but unfortunately it does not work.&lt;/P&gt;</description>
      <pubDate>Sat, 19 Aug 2023 17:58:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/How-to-enable-pmtud-on-gaia-VSX-R81/m-p/189469#M31782</guid>
      <dc:creator>DZ_KB</dc:creator>
      <dc:date>2023-08-19T17:58:15Z</dc:date>
    </item>
    <item>
      <title>Re: How to enable pmtud on gaia VSX R81</title>
      <link>https://community.checkpoint.com/t5/General-Topics/How-to-enable-pmtud-on-gaia-VSX-R81/m-p/189926#M31835</link>
      <description>&lt;P&gt;I update my last post.&lt;/P&gt;&lt;P&gt;I did some deep troubleshooting on the network and the firewall generates icmp on the server, but the server ignored it.&lt;/P&gt;&lt;P&gt;Conclusion: pmtud works fine on gaia but it can't solve my problem. I must therefore direct my research towards other solutions such as mss clamping (the problem will be for udp applications) or increase the mtu on the network.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 19 Aug 2023 18:13:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/How-to-enable-pmtud-on-gaia-VSX-R81/m-p/189926#M31835</guid>
      <dc:creator>DZ_KB</dc:creator>
      <dc:date>2023-08-19T18:13:10Z</dc:date>
    </item>
  </channel>
</rss>

