<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ipsec latency smb1570 in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/ipsec-latency-smb1570/m-p/178061#M8737</link>
    <description>&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;but i found first issue on 2nd step - no .conf file in dir:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[Expert@fw]# cp -v $FWDIR/modules/fwkern.conf{,_BKP}
cp: can't stat '/opt/fw1/modules/fwkern.conf': No such file or directory
[Expert@fw]# pwd
/opt/fw1/modules
[Expert@fw]# ls -la
drwxr-xr-x    2 root     root          4096 Feb 23 14:19 .
drwxr-xr-x    3 root     root          4096 Feb 23 14:19 ..
-rw-r--r--    1 105      80          500440 Nov 22 09:58 adp.o
-rw-r--r--    1 105      80        49280288 Nov 22 09:58 fw.o
-rw-r--r--    1 105      80        46326416 Nov 22 09:58 fwv6.o
-rw-r--r--    1 105      80        13251656 Nov 22 09:58 sim.o
-rw-r--r--    1 105      80        13049208 Nov 22 09:58 simv6.o
-rw-r--r--    1 105      80           25984 Nov 22 09:58 vpnt.o&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;Running version:&lt;/P&gt;&lt;DIV class=""&gt;The current firmware version is&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;R81.10 (996000575)&lt;/STRONG&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;I've found also this cmd in some topic, but not working:&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[Expert@fw]# fw ctl get int fw_clamp_tcp_mss
fw_clamp_tcp_mss = 0
[Expert@fw]# fw ctl set int fw_clamp_tcp_mss 1
 Set operation failed: failed to get parameter fw_clamp_tcp_mss​&lt;/LI-CODE&gt;&lt;P&gt;Thank you for help.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 14 Apr 2023 06:27:58 GMT</pubDate>
    <dc:creator>Thowtes</dc:creator>
    <dc:date>2023-04-14T06:27:58Z</dc:date>
    <item>
      <title>ipsec latency smb1570</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/ipsec-latency-smb1570/m-p/178043#M8734</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;i have a problem (probably) with high latency over IPSec (Site2Site) between SMB1570 (remote) and Mikrotik RB1100 (central).&lt;/P&gt;&lt;P&gt;When i try to add esxi host on remote site to vcenter on central branch, it always fails. Only host behind SMB1570 have this issue, so i think it is related to Checkpoint and/or this IPSec.&lt;/P&gt;&lt;P&gt;I tried some configurations with MTU, but no success.&lt;/P&gt;&lt;P&gt;Any idea, please?&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Thu, 13 Apr 2023 19:27:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/ipsec-latency-smb1570/m-p/178043#M8734</guid>
      <dc:creator>Thowtes</dc:creator>
      <dc:date>2023-04-13T19:27:09Z</dc:date>
    </item>
    <item>
      <title>Re: ipsec latency smb1570</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/ipsec-latency-smb1570/m-p/178056#M8735</link>
      <description>&lt;P&gt;It's most likely an MTU/fragmentation issue.&lt;BR /&gt;For a discussion of this topic in general, see:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk98074" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk98074&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;To confirm the issue, I recommend taking some packet captures.&lt;/P&gt;
&lt;P&gt;If your SMB appliance is locally managed (i.e. without SmartCenter), not sure it is possible to configure MSS Clamping, which is probably how you'd resolve this.&lt;BR /&gt;Recommend engaging with the TAC: &lt;A href="https://help.checkpoint.com" target="_blank"&gt;https://help.checkpoint.com&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Apr 2023 00:48:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/ipsec-latency-smb1570/m-p/178056#M8735</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-04-14T00:48:51Z</dc:date>
    </item>
    <item>
      <title>Re: ipsec latency smb1570</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/ipsec-latency-smb1570/m-p/178058#M8736</link>
      <description>&lt;P&gt;As&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;suggests you're probably looking at something like the following:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk121114" target="_self"&gt;sk121114: "Fragmentation needed" error on dropped packets sent through tunnel on Quantum Spark Appliances (checkpoint.com)&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Apr 2023 00:55:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/ipsec-latency-smb1570/m-p/178058#M8736</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-04-14T00:55:46Z</dc:date>
    </item>
    <item>
      <title>Re: ipsec latency smb1570</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/ipsec-latency-smb1570/m-p/178061#M8737</link>
      <description>&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;but i found first issue on 2nd step - no .conf file in dir:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[Expert@fw]# cp -v $FWDIR/modules/fwkern.conf{,_BKP}
cp: can't stat '/opt/fw1/modules/fwkern.conf': No such file or directory
[Expert@fw]# pwd
/opt/fw1/modules
[Expert@fw]# ls -la
drwxr-xr-x    2 root     root          4096 Feb 23 14:19 .
drwxr-xr-x    3 root     root          4096 Feb 23 14:19 ..
-rw-r--r--    1 105      80          500440 Nov 22 09:58 adp.o
-rw-r--r--    1 105      80        49280288 Nov 22 09:58 fw.o
-rw-r--r--    1 105      80        46326416 Nov 22 09:58 fwv6.o
-rw-r--r--    1 105      80        13251656 Nov 22 09:58 sim.o
-rw-r--r--    1 105      80        13049208 Nov 22 09:58 simv6.o
-rw-r--r--    1 105      80           25984 Nov 22 09:58 vpnt.o&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;Running version:&lt;/P&gt;&lt;DIV class=""&gt;The current firmware version is&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;R81.10 (996000575)&lt;/STRONG&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;I've found also this cmd in some topic, but not working:&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[Expert@fw]# fw ctl get int fw_clamp_tcp_mss
fw_clamp_tcp_mss = 0
[Expert@fw]# fw ctl set int fw_clamp_tcp_mss 1
 Set operation failed: failed to get parameter fw_clamp_tcp_mss​&lt;/LI-CODE&gt;&lt;P&gt;Thank you for help.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Apr 2023 06:27:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/ipsec-latency-smb1570/m-p/178061#M8737</guid>
      <dc:creator>Thowtes</dc:creator>
      <dc:date>2023-04-14T06:27:58Z</dc:date>
    </item>
    <item>
      <title>Re: ipsec latency smb1570</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/ipsec-latency-smb1570/m-p/178102#M8738</link>
      <description>&lt;P&gt;Sounds like fw_clamp_tcp_mss can not be set "on the fly" meaning the only way is by specifying it in fwkern.conf.&lt;BR /&gt;If this file does not exist, it must be created.&lt;/P&gt;</description>
      <pubDate>Fri, 14 Apr 2023 14:46:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/ipsec-latency-smb1570/m-p/178102#M8738</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-04-14T14:46:12Z</dc:date>
    </item>
  </channel>
</rss>

