<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Fragmentation issue on 750 Appliance in Checkpoint Mobil Client in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Fragmentation-issue-on-750-Appliance-in-Checkpoint-Mobil-Client/m-p/179420#M8851</link>
    <description>&lt;P&gt;Hi there,&lt;/P&gt;&lt;P&gt;is there a possibility to change some options concerning fragmentation and MSS-clamping on the 750 Appliance?&lt;/P&gt;&lt;P&gt;I see a lot of fragmented packets incoming on the Office-Mode-Clients resulting in a very bad performance for the clients. The clients use the Checkpoint Mobile Client to the 750 Appliance.&lt;/P&gt;&lt;P&gt;I have tried so far to set the MTU on the WAN and LAN-Interface to what I have figured out by using ping with don't fragment (1460Bytes). I also disabled the max-ping-IPS setting (1000Bytes) in the Checkpoint. I also set the MTU on client (Checkpoint Mobile) and server (behind 750 Appliance) to 1350Bytes. I also tried to trim the Windows-Server (Server2019) and Windows-Client (Windows10) to use the minimum MTU of 576 Bytes to avoid a "too big MTU). I still continuously see the fragments (TCP segment of reassembled PDU) in wireshark on the client with always a length of (MTU - 40Bytes).&lt;/P&gt;&lt;P&gt;Any ideas? Thank you in advance.&lt;/P&gt;&lt;P&gt;Daniel&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 28 Apr 2023 13:36:50 GMT</pubDate>
    <dc:creator>dakeil</dc:creator>
    <dc:date>2023-04-28T13:36:50Z</dc:date>
    <item>
      <title>Fragmentation issue on 750 Appliance in Checkpoint Mobil Client</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Fragmentation-issue-on-750-Appliance-in-Checkpoint-Mobil-Client/m-p/179420#M8851</link>
      <description>&lt;P&gt;Hi there,&lt;/P&gt;&lt;P&gt;is there a possibility to change some options concerning fragmentation and MSS-clamping on the 750 Appliance?&lt;/P&gt;&lt;P&gt;I see a lot of fragmented packets incoming on the Office-Mode-Clients resulting in a very bad performance for the clients. The clients use the Checkpoint Mobile Client to the 750 Appliance.&lt;/P&gt;&lt;P&gt;I have tried so far to set the MTU on the WAN and LAN-Interface to what I have figured out by using ping with don't fragment (1460Bytes). I also disabled the max-ping-IPS setting (1000Bytes) in the Checkpoint. I also set the MTU on client (Checkpoint Mobile) and server (behind 750 Appliance) to 1350Bytes. I also tried to trim the Windows-Server (Server2019) and Windows-Client (Windows10) to use the minimum MTU of 576 Bytes to avoid a "too big MTU). I still continuously see the fragments (TCP segment of reassembled PDU) in wireshark on the client with always a length of (MTU - 40Bytes).&lt;/P&gt;&lt;P&gt;Any ideas? Thank you in advance.&lt;/P&gt;&lt;P&gt;Daniel&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 28 Apr 2023 13:36:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Fragmentation-issue-on-750-Appliance-in-Checkpoint-Mobil-Client/m-p/179420#M8851</guid>
      <dc:creator>dakeil</dc:creator>
      <dc:date>2023-04-28T13:36:50Z</dc:date>
    </item>
    <item>
      <title>Re: Fragmentation issue on 750 Appliance in Checkpoint Mobil Client</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Fragmentation-issue-on-750-Appliance-in-Checkpoint-Mobil-Client/m-p/179487#M8852</link>
      <description>&lt;P&gt;Some related parameters are outlined in&amp;nbsp;sk121114.&lt;/P&gt;</description>
      <pubDate>Sat, 29 Apr 2023 00:46:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Fragmentation-issue-on-750-Appliance-in-Checkpoint-Mobil-Client/m-p/179487#M8852</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-04-29T00:46:22Z</dc:date>
    </item>
    <item>
      <title>Re: Fragmentation issue on 750 Appliance in Checkpoint Mobil Client</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Fragmentation-issue-on-750-Appliance-in-Checkpoint-Mobil-Client/m-p/179499#M8853</link>
      <description>&lt;P&gt;SK Chris gave is good reference. Keep in mind, if this is locally managed appliance, you can really only change things for MTU in gui or cli, but if its centrally managed, there are some settings that could be modified for MSS in Guidbedit database tool.&lt;/P&gt;
&lt;P&gt;Otherwise, I would say, for locally managed, do the backup and follow the steps in the article.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sat, 29 Apr 2023 13:00:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Fragmentation-issue-on-750-Appliance-in-Checkpoint-Mobil-Client/m-p/179499#M8853</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-04-29T13:00:50Z</dc:date>
    </item>
  </channel>
</rss>

