Please post outputs of Super Seven plus enabled_blades.
MSS clamping would normally only apply to IPSec traffic and not HTTPS traffic. This is because in IPSec the whole ESP packet (mostly) is digitally signed and therefore cannot be fragmented (DF flag). With HTTPS the payload stream of data is digitally signed, and the packets carrying it can be fragmented into a zillion pieces, as long as the payload stream of data being carried reassembles correctly. This is why HTTPS/TLS based Remote Access VPN clients are more resistant to low MTU performance issues.
New Book: "Max Power 2026" Coming Soon
Check Point Firewall Performance Optimization