<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic S2S VPN via Cellular Backup Issues in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/S2S-VPN-via-Cellular-Backup-Issues/m-p/278714#M14028</link>
    <description>&lt;P&gt;We have many 1595R appliances that setup a S2S tunnel to two main clusters (9000 appliances).&amp;nbsp; The firewall sits behind a Cisco router which is connected via MPLS and has a cellular backup connection.&amp;nbsp; While on MPLS, the tunnel works perfect and we have no issues but if MPLS goes down and the Cisco router fails over to cellular, the tunnel starts acting up.&amp;nbsp; Sometimes existing traffic continues to work and then after a while (presumably during the next rekey) traffic will stop working and connections will drop.&amp;nbsp; We determined during test that if we set the community to IKEv1 only that cellular failover works well.&amp;nbsp; All 1595R locations are configured for IKEv2 only currently and we'd prefer to stay there.&lt;/P&gt;
&lt;P&gt;Any idea on what settings on the firewalls we can tweak to help improve things?&amp;nbsp; If the network team tweaks the MTU on the router side we can get the tunnel working over cellular but the settings apparently get overwritten by the carrier so we're looking for a Check Point solution.&amp;nbsp; I'm guessing it will be tweaking of MTU and/or IKE fragmentation but not 100% sure on the correct commands and also if it can be done just on the 1595R side or if the 9000 clusters need to be changed (which I assume would impact all locations and we are trying to avoid that without more testing).&lt;/P&gt;
&lt;P&gt;Any guidance is appreciated.&amp;nbsp; Below is a snippet of how a typical Cisco router is configured for each location:&lt;/P&gt;
&lt;P&gt;interface Tunnel10&lt;BR /&gt;description "Tunnel via Verizon"&lt;BR /&gt;ip address X.X.X.X 255.255.255.252&lt;BR /&gt;ip mtu 1428&lt;BR /&gt;ip tcp adjust-mss 1364&lt;BR /&gt;load-interval 30&lt;BR /&gt;keepalive 10 3&lt;BR /&gt;tunnel source Cellular0/4/0&lt;BR /&gt;tunnel destination X.X.X.X&lt;BR /&gt;!&lt;/P&gt;
&lt;P&gt;//Set by Carrier&lt;BR /&gt;interface Cellular0/4/0&lt;BR /&gt;mtu 1428&lt;BR /&gt;ip address negotiated&lt;BR /&gt;no ip unreachables&lt;BR /&gt;ip tcp adjust-mss 1388&lt;BR /&gt;load-interval 30&lt;BR /&gt;dialer in-band&lt;BR /&gt;dialer idle-timeout 0&lt;BR /&gt;dialer enable-timeout 6&lt;BR /&gt;dialer watch-group 1&lt;BR /&gt;dialer-group 1&lt;BR /&gt;pulse-time 1&lt;/P&gt;</description>
    <pubDate>Fri, 19 Jun 2026 20:40:31 GMT</pubDate>
    <dc:creator>VikingsFan</dc:creator>
    <dc:date>2026-06-19T20:40:31Z</dc:date>
    <item>
      <title>S2S VPN via Cellular Backup Issues</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/S2S-VPN-via-Cellular-Backup-Issues/m-p/278714#M14028</link>
      <description>&lt;P&gt;We have many 1595R appliances that setup a S2S tunnel to two main clusters (9000 appliances).&amp;nbsp; The firewall sits behind a Cisco router which is connected via MPLS and has a cellular backup connection.&amp;nbsp; While on MPLS, the tunnel works perfect and we have no issues but if MPLS goes down and the Cisco router fails over to cellular, the tunnel starts acting up.&amp;nbsp; Sometimes existing traffic continues to work and then after a while (presumably during the next rekey) traffic will stop working and connections will drop.&amp;nbsp; We determined during test that if we set the community to IKEv1 only that cellular failover works well.&amp;nbsp; All 1595R locations are configured for IKEv2 only currently and we'd prefer to stay there.&lt;/P&gt;
&lt;P&gt;Any idea on what settings on the firewalls we can tweak to help improve things?&amp;nbsp; If the network team tweaks the MTU on the router side we can get the tunnel working over cellular but the settings apparently get overwritten by the carrier so we're looking for a Check Point solution.&amp;nbsp; I'm guessing it will be tweaking of MTU and/or IKE fragmentation but not 100% sure on the correct commands and also if it can be done just on the 1595R side or if the 9000 clusters need to be changed (which I assume would impact all locations and we are trying to avoid that without more testing).&lt;/P&gt;
&lt;P&gt;Any guidance is appreciated.&amp;nbsp; Below is a snippet of how a typical Cisco router is configured for each location:&lt;/P&gt;
&lt;P&gt;interface Tunnel10&lt;BR /&gt;description "Tunnel via Verizon"&lt;BR /&gt;ip address X.X.X.X 255.255.255.252&lt;BR /&gt;ip mtu 1428&lt;BR /&gt;ip tcp adjust-mss 1364&lt;BR /&gt;load-interval 30&lt;BR /&gt;keepalive 10 3&lt;BR /&gt;tunnel source Cellular0/4/0&lt;BR /&gt;tunnel destination X.X.X.X&lt;BR /&gt;!&lt;/P&gt;
&lt;P&gt;//Set by Carrier&lt;BR /&gt;interface Cellular0/4/0&lt;BR /&gt;mtu 1428&lt;BR /&gt;ip address negotiated&lt;BR /&gt;no ip unreachables&lt;BR /&gt;ip tcp adjust-mss 1388&lt;BR /&gt;load-interval 30&lt;BR /&gt;dialer in-band&lt;BR /&gt;dialer idle-timeout 0&lt;BR /&gt;dialer enable-timeout 6&lt;BR /&gt;dialer watch-group 1&lt;BR /&gt;dialer-group 1&lt;BR /&gt;pulse-time 1&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jun 2026 20:40:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/S2S-VPN-via-Cellular-Backup-Issues/m-p/278714#M14028</guid>
      <dc:creator>VikingsFan</dc:creator>
      <dc:date>2026-06-19T20:40:31Z</dc:date>
    </item>
    <item>
      <title>Re: S2S VPN via Cellular Backup Issues</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/S2S-VPN-via-Cellular-Backup-Issues/m-p/278725#M14029</link>
      <description>&lt;P&gt;Common issue in CGNAT environments...&lt;/P&gt;
&lt;P&gt;You can set the MTU &amp;amp; MSS clamping on the Check Point as long as your comfortable with imposing an artificial limit on both network paths to the lowest common denominator.&lt;/P&gt;</description>
      <pubDate>Sat, 20 Jun 2026 10:35:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/S2S-VPN-via-Cellular-Backup-Issues/m-p/278725#M14029</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2026-06-20T10:35:32Z</dc:date>
    </item>
  </channel>
</rss>

