Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Highlighted
Participant

Fragment Reassembly Time Exceeded Errors

Jump to solution

I have 2 RADIUS servers that are trying to talk to each other through a Checkpoint R80.30 ClusterXL.

It seems to be failing with a lot of errors in the logs saying "Fragment_time_exceeded" traffic dropped.

I have tried to allow all ICMP between the end clients but there is no PMTUD taking place and there doesn't seem to be a way to enable this traffic to fragment and reassemble without failing with these errors.

We have all the latest hotfixes required.  Is there a reason for this?

errors.JPG

1 Solution

Accepted Solutions
Highlighted
Employee+
Employee+

it should be done via guidbedit and then push policy, see attached icmperrors.JPG

 

if you did it and still have an issue i suggest to open TAC case.

View solution in original post

4 Replies
Highlighted
Champion
Champion

If this was a connection using VPN i would have cried MTU, MTU! But this looks different. Maybe still the following can help: sk98074: MTU and Fragmentation Issues in IPsec VPN

0 Kudos
Highlighted
Employee+
Employee+

Please check under GuiDBedit "icmperrors", by default it should be allowed "true" looks like in your case the policy not allowing it, if it false change it to true and recheck.

Highlighted
Participant

Hi

I made this change, but I am still getting the same error.  I made the change on the management server - is this correct or did it need to get made on the firewalls themselves?

Yesterday I have also added an exception to the inspection settings for traffic between the 2 RADIUS servers in case this was the problem. It seemed to make it a little bit better but I still see the error and still have problems.

 

Thanks

Highlighted
Employee+
Employee+

it should be done via guidbedit and then push policy, see attached icmperrors.JPG

 

if you did it and still have an issue i suggest to open TAC case.

View solution in original post