- Products
- Learn
- Local User Groups
- Partners
- More
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Improve Your Security Posture with
Threat Prevention and Policy Insights
Overlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hello i was wondering if its possible to lower the mtu on the remote access client endpoint vpn or the gw?
In my homelab i have built this MPLS network (in the cloud) that is the connection between my home + and summer house. It runs wireguard + gre in the bottom so the maximum mtu of a packet cannot go over 1380 mtu and with ipsec on top of that i think the mtu has to go down to like 1280-1300 on that ipsec tunnel is it possible to configure that on a Checkpoint? Cant find anything on it.
Best regards,
BW
Hello sorry late reply it seemed it was never a mtu problem (im doing mtu mss outside checkpoint) i had to open up ports 500 and 4500 but its wierd it always worked from my iphone which also says its using ipsec. Or does the iphone do it over 443?
Everything works fine now doing ipsec on top of wireguard + gre 🙂 however im just thinking of route leak ipsec traffic outside wireguard between the sites.
You can adjust the MTU of VPN traffic by setting the MSS size for VPN traffic.
See: https://support.checkpoint.com/results/sk/sk101219
You can change MTU on relevant interface from clich -> set interface ethxx mtu and then whatever size needed.
Then save config to save the setting.
Andy
Hello sorry late reply it seemed it was never a mtu problem (im doing mtu mss outside checkpoint) i had to open up ports 500 and 4500 but its wierd it always worked from my iphone which also says its using ipsec. Or does the iphone do it over 443?
Everything works fine now doing ipsec on top of wireguard + gre 🙂
Our VPN clients require a connection over HTTPS (TCP/443) to start the connection.
In some cases, this will also be used for the actual VPN transport (so called "Visitor Mode").
Hello sorry late reply it seemed it was never a mtu problem (im doing mtu mss outside checkpoint) i had to open up ports 500 and 4500 but its wierd it always worked from my iphone which also says its using ipsec. Or does the iphone do it over 443?
Everything works fine now doing ipsec on top of wireguard + gre 🙂 however im just thinking of route leak ipsec traffic outside wireguard between the sites.
Port 443 is always needed for remote access. Check out below post about it.
Andy
Yes but why is it working without opening 4500/500 when coming from Iphone vs mac/windows?
I believe iphone would need only udp port 500, not udp 4500.
Andy
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 29 | |
| 18 | |
| 7 | |
| 7 | |
| 4 | |
| 4 | |
| 3 | |
| 3 | |
| 2 | |
| 2 |
Wed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY