Re: [fw-wiz] MTU issue routing traffic via Cisco GRE tunnel to Nokia/Check Point firewall

rainer.ginsberg_at_basf-it-services.com
Date: 12/08/03

  • Next message: Jason Ostrom: "Re: [fw-wiz] PIX DMZ inter-access via outside IP address"
    To: firewall-wizards@honor.icsalabs.com
    Date: Mon, 8 Dec 2003 12:33:37 +0100
    
    

    > We have been suffering an issue to do with Checkpoint, Cisco GRE tunnels
    > and MTU size for a number of months now, and I thought it might be worth
    > posting a description of our problem on this list in case someone is able
    > to help. We feel that we have exhausted most avenues of trying to
    > troubleshoot this issue.

    You might try the solution SK14995 of Check Point's knowledge base. It
    suggest to set "fw_clamp_tcp_mss = true" in objects_5_0.C in conjunction
    with tuning the MTU size of the Interface in question.

    Best regards,
    Rainer

    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


  • Next message: Jason Ostrom: "Re: [fw-wiz] PIX DMZ inter-access via outside IP address"

    Relevant Pages

    • Re: NdisMIndicateReceivePacket for large packets
      ... Chances are that we would -require- future NDIS filter, protocol and IM ... After all it is called MTU and not MRU! ... This posting is provided "AS IS" with no warranties, ...
      (microsoft.public.development.device.drivers)
    • RE: MTU Issues
      ... to 1460 and left the Netgear at 1500. ... The default MTU in SBS 2003 will depend on the media the network ... Microsoft Small Business Server Support ... This posting is provided "AS IS" with no warranties, ...
      (microsoft.public.windows.server.sbs)
    • Re: Strange PPPOE internet behavior
      ... Troubleshooting MTU Size in PPPoE Dialin Connectivity ... You know the MS tech kept looking at the MTU and as I was posting this ...
      (comp.dcom.sys.cisco)
    • Re: Server refusing access in OS10.5 - very odd
      ... and it does the congestion charge payment ... MTU helped him, I thought it might be worth a stab? ... Peter offered that he was ok but if not on AOL may not have ...
      (uk.comp.sys.mac)
    • Re: Server refusing access in OS10.5 - very odd
      ... For what it's worth, I'm using a DG834 but ... using the default MTU, and it does the congestion charge payment ...
      (uk.comp.sys.mac)