- Products
- Learn
- Local User Groups
- Partners
- More
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Improve Your Security Posture with
Threat Prevention and Policy Insights
Overlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hey everyone,
Has someone seen this issue in R81? I did this on 2 firewalls and changed mtu from 1500 to 1350 or 1400 and as soon as I did that, lost ssh and web gui. I NEVER had this issue in R77.30 and before.
Could this be a bug??
Were you able to reconnect?
I wouldn’t be surprised if there was an interaction here with SecureXL.
Hey D,
I was able to reconnect once I changed it back to 1500. Even disabling sxl does not make any difference once you change mtu to 1350 or 1400.
Could be related to MSS which may also need to be changed.
See: https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...
Maybe, not real sure, but did this many times before R80 and never ever did I have to change mss or anything else once I changed mtu size, it simply worked.
Hi @the_rock,
Can you share which type of appliance is in use and which type of interface it is?
Thanks,
Ilya
I did not use physical appliance, as I dont have any on R81, this was only VM testing.
In my lab on VM it is working fine.
Do you see any failures/errors under /var/log/messages?
Nothing of interest in messages at all. I think we can park this issue for now, since we dont plan on upgrading any customers to R81 code on firewalls as of yet any time soon. I was just doing some tests myself for VPN tunnel with cloud provider, hence the reason why I had to change MTU size.
How you reduce the MTU? via clish or via ifconfig?
Hi...tried both via web UI and clish, same results.
Only really an aside but I've had issues like this related to MTU and encrypted sessions (HTTPS etc.), Generally it's where the MTU is forced but the client does not know about it and sends larger packets with the DF bit set. You can test this by lowering the MTU on the client device and see can you connect. Normally adjust-mss and path MTU discovery are required for the client to negotiate the correct MTU if you're not directly connected on the same Layer 2 subnet.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 37 | |
| 19 | |
| 9 | |
| 7 | |
| 7 | |
| 5 | |
| 5 | |
| 4 | |
| 3 | |
| 3 |
Wed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY