<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: DF bit in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/DF-bit/m-p/216418#M35982</link>
    <description>&lt;P&gt;To fix a drop? Not sure, maybe worth TAC case.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
    <pubDate>Tue, 04 Jun 2024 17:25:40 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2024-06-04T17:25:40Z</dc:date>
    <item>
      <title>DF bit</title>
      <link>https://community.checkpoint.com/t5/General-Topics/DF-bit/m-p/216275#M35928</link>
      <description>&lt;P&gt;is there any way or command on checkpoint firewall gateway to ignore the DF bit flag and assemble traffic as normal.&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Mon, 03 Jun 2024 18:42:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/DF-bit/m-p/216275#M35928</guid>
      <dc:creator>knassif</dc:creator>
      <dc:date>2024-06-03T18:42:10Z</dc:date>
    </item>
    <item>
      <title>Re: DF bit</title>
      <link>https://community.checkpoint.com/t5/General-Topics/DF-bit/m-p/216279#M35932</link>
      <description>&lt;P&gt;and this is for regular traffic not for vpn traffic is there a way to ignore that DF bit flag on the firewall with a command ?&lt;/P&gt;</description>
      <pubDate>Mon, 03 Jun 2024 18:57:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/DF-bit/m-p/216279#M35932</guid>
      <dc:creator>knassif</dc:creator>
      <dc:date>2024-06-03T18:57:32Z</dc:date>
    </item>
    <item>
      <title>Re: DF bit</title>
      <link>https://community.checkpoint.com/t5/General-Topics/DF-bit/m-p/216284#M35935</link>
      <description>&lt;P&gt;Not sure about regular traffic, but this is best I can find.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk39270" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk39270&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Jun 2024 19:26:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/DF-bit/m-p/216284#M35935</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-06-03T19:26:14Z</dc:date>
    </item>
    <item>
      <title>Re: DF bit</title>
      <link>https://community.checkpoint.com/t5/General-Topics/DF-bit/m-p/216290#M35937</link>
      <description>&lt;P&gt;This SK is mostly relevant for VPN.&lt;BR /&gt;In Linux, at least according to &lt;A href="https://stackoverflow.com/questions/63791960/clear-dont-fragment-bit-on-linux" target="_self"&gt;here&lt;/A&gt;, the way you would do this would be something like:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;ip route add 192.168.1.0/24 dev eth0 mtu lock 1500&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;You can try this in expert mode and see if it works.&lt;BR /&gt;Replace 192.168.1.0/24 with the subnet that requires DF be cleared.&lt;BR /&gt;However, I cannot say if this command will work on Gaia or not.&lt;BR /&gt;Even if it does, it probably won't persist across reboots or even certain configuration changes in clish/WebUI.&lt;/P&gt;</description>
      <pubDate>Mon, 03 Jun 2024 20:07:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/DF-bit/m-p/216290#M35937</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-06-03T20:07:20Z</dc:date>
    </item>
    <item>
      <title>Re: DF bit</title>
      <link>https://community.checkpoint.com/t5/General-Topics/DF-bit/m-p/216298#M35938</link>
      <description>&lt;P&gt;You got it, thats it&lt;/P&gt;
&lt;P&gt;from my lab:&lt;/P&gt;
&lt;P&gt;[Expert@CP-gw:0]# ip route add 192.50.50.0/24 dev eth1 mtu lock 1500&lt;BR /&gt;[Expert@CP-gw:0]#&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 04 Jun 2024 00:27:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/DF-bit/m-p/216298#M35938</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-06-04T00:27:58Z</dc:date>
    </item>
    <item>
      <title>Re: DF bit</title>
      <link>https://community.checkpoint.com/t5/General-Topics/DF-bit/m-p/216414#M35978</link>
      <description>&lt;P&gt;is there anything can be done to fix a fragment drop? as you can see in screenshot below/attached&lt;/P&gt;</description>
      <pubDate>Tue, 04 Jun 2024 15:37:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/DF-bit/m-p/216414#M35978</guid>
      <dc:creator>knassif</dc:creator>
      <dc:date>2024-06-04T15:37:47Z</dc:date>
    </item>
    <item>
      <title>Re: DF bit</title>
      <link>https://community.checkpoint.com/t5/General-Topics/DF-bit/m-p/216415#M35979</link>
      <description>&lt;P&gt;also can you explain to me what that output means and if there is a way to fix it on the firewall&lt;/P&gt;</description>
      <pubDate>Tue, 04 Jun 2024 15:55:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/DF-bit/m-p/216415#M35979</guid>
      <dc:creator>knassif</dc:creator>
      <dc:date>2024-06-04T15:55:54Z</dc:date>
    </item>
    <item>
      <title>Re: DF bit</title>
      <link>https://community.checkpoint.com/t5/General-Topics/DF-bit/m-p/216417#M35981</link>
      <description>&lt;P&gt;we use VSX so not sure how we can add the lock for a route, as far as I know we shouldnt add routes from cli for VSX and I dont see that as an option in Smartconsole&lt;/P&gt;</description>
      <pubDate>Tue, 04 Jun 2024 16:06:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/DF-bit/m-p/216417#M35981</guid>
      <dc:creator>knassif</dc:creator>
      <dc:date>2024-06-04T16:06:15Z</dc:date>
    </item>
    <item>
      <title>Re: DF bit</title>
      <link>https://community.checkpoint.com/t5/General-Topics/DF-bit/m-p/216418#M35982</link>
      <description>&lt;P&gt;To fix a drop? Not sure, maybe worth TAC case.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 04 Jun 2024 17:25:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/DF-bit/m-p/216418#M35982</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-06-04T17:25:40Z</dc:date>
    </item>
    <item>
      <title>Re: DF bit</title>
      <link>https://community.checkpoint.com/t5/General-Topics/DF-bit/m-p/216601#M36040</link>
      <description>&lt;P&gt;If it's not an option from SmartConsole (where you have to define routes for a VS with VSX), then it's probably not supported.&lt;BR /&gt;A few TAC cases I reviewed suggest this isn't supported as well, but best to check with them to confirm: &lt;A href="https://help.checkpoint.com" target="_blank"&gt;https://help.checkpoint.com&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jun 2024 23:02:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/DF-bit/m-p/216601#M36040</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-06-05T23:02:41Z</dc:date>
    </item>
  </channel>
</rss>

