Hi,
We are facing fragmentation issue on a Full Check Point topology
This setup is enabled on all Firewalls. MSS is defined to 1360 on all interfacs
echo 'fw_clamp_vpn_mss=1' >> $FWDIR/boot/modules/fwkern.conf
echo 'sim_clamp_vpn_mss=1' >> $PPKDIR/conf/simkern.conf
All TCP connections seems to be ok.
Our issue is related to RADIUS (EAP) traffic accros the tunnel. EAP needs fragementation but the negociation is dropped. if we reaplced the VPN tunnel with another vendor we are not gettng any problem so this lead to confirm that it's a Check Point issue / configuration
We tried to enable Fast_Accel to make sure nothing is dropped
I'm intending to enable this parameter as I don't know if default value is 0 or 1 in R81.20 ? Does anyboday has any experience with this ?
- sim_ipsec_dont_fragment=1
Thank you