> Source: [sk101219](https://support.checkpoint.com/results/sk/sk101219)

# sk101219 - TCP Maximum Segment Size (MSS) adjustments for Clear and IPsec traffic

| Property | Value |
|----------|-------|
| Solution ID | sk101219 |
| Date Created | 2014-06-10 |
| Last Modified | 2026-06-24 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R82, R81.20, R81.10 (EOS), R81 (EOS) |

## Solution

MSS adjustments for Clear and IPsec traffic {#MSS adjustments for Clear and IPsec traffic}
------------------------------------------------------------------------------------------

During the TCP handshake, both the client and the server send MSS values in SYN and SYN/ACK packets to notify the other side of the Maximum Segment Size (MSS) they are willing to accept. To prevent packet fragmentation, the MSS value can't exceed the MTU along the communication path. Several variables are used to control TCP MSS clamping and VPN traffic clamping, and their configuration is listed below:

|--------------------------------|------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|-----------------------------------------------------------------------------------------------------------------------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| Property Name                  | Property Description                                                                                                                                                               | Configuration Method                                                                                                                                                                                                                                            | Configuration Scope                                                                                                         | Valid Values                                                                                                                                                                                                                                                                                                                                                            |
| ***fw_clamp_tcp_mss***         | Controls MSS Adjustment (Clamping) for *FireWall* level traffic on *all* managed Security Gateways. Refer to [sk61221](http://supportcontent.checkpoint.com/solutions?id=sk61221). | GuiDBedit Tool                                                                                                                                                                                                                                                  | 1) On Security Gateway - Per Gateway 2) On Management Server - Global                                                       | 1) On Security Gateway: * **1** - enabled * **0** - (default) disabled 2) On Management Server: * **true** - enabled * **false** - (default) disabled                                                                                                                                                                                                                   |
| ***fw_clamp_tcp_mss_control*** | Controls MSS Adjustment (Clamping) on *specific* Security Gateway.                                                                                                                 | GuiDBedit Tool                                                                                                                                                                                                                                                  | Per Gateway **Note:** On VSX Gateway, this attribute must be set for ***both*** Virtual System and for VSX Gateway itself   | * **true** - enabled * **false** - (default) disabled                                                                                                                                                                                                                                                                                                                   |
| ***mss_value***                | Controls MSS value for MSS Adjustment (Clamping) on *specific* interface on *specific* Security Gateway.                                                                           | GuiDBedit Tool **Note:** use [sk13009](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk13009) to enable GuiDBedit. MSS will be under "\<your gateway\> \> \<the external interface\> \> mss value". | Per interface **Note:** On VSX Gateway, this attribute must be set for ***both*** Virtual System and for VSX Gateway itself | * **-1** - disable MSS clamping * **0** - (default) enable MSS clamping - MSS value is derived from interface's MTU * **positive integer** - MSS clamping enabled and this value is used                                                                                                                                                                                |
| ***fw_clamp_vpn_mss***         | Controls MSS Adjustment (Clamping) for *IPsec VPN* blade traffic independent of TCP clamping described above. Must also enable the *sim_clamp_vpn_mss*.                            | Kernel parameter                                                                                                                                                                                                                                                | Per Gateway                                                                                                                 | * **1** - enabled * **0** - (default) disabled Can be enabled on Security Gateway: * Either *on-the-fly* (does not survive reboot): **`# fw ctl set int fw_clamp_vpn_mss 1`** * Or *permanently* per [sk26202](http://supportcontent.checkpoint.com/solutions?id=sk26202): Add this line to *$FWDIR/boot/modules/fwkern.conf* file and reboot: **`fw_clamp_vpn_mss=1`** |
| ***sim_clamp_vpn_mss***        | Controls MSS clamping in SecureXL (SecureXL VPN) *only* for *IPsec VPN* blade traffic independent of TCP clamping described above. Must also enable the *fw_clamp_vpn_mss*.        | Kernel parameter                                                                                                                                                                                                                                                | Per Gateway                                                                                                                 | * **1** - enabled * **0** - (default) disabled Can be enabled on Security Gateway with enabled SecureXL only *permanently*: Add this line to *$PPKDIR/conf/simkern.conf* and reboot: **`sim_clamp_vpn_mss=1`** **Important: In Gaia Embedded, the location of *simkern.conf* is *$FWDIR/modules/simkern.conf* . *$PPKDIR* does not exist.**                             |

**Important Notes:**

* All features that are enabled for clear traffic also affect the IPsec VPN traffic.  

* ***fw_clamp_vpn_mss*** and ***sim_clamp_vpn_mss*** should be enabled together. Otherwise, if SecureXL is enabled, only one traffic direction will be clamped. In addition, VPN MSS clamping will change only encrypted *outgoing* TCP traffic. If *incoming* encrypted traffic should be changed as well, it should be changed on the remote VPN peer.  

* In a cluster, the MSS value (***mss_value*** ) has to be set in the object of *each* cluster member, and not the cluster object.  

* The Cluster VIP interface names must match the physical interface names in the topology.

<!-- -->

* In VSX gateway / VSX cluster, the MSS value (***mss_value*** ) has to be set in the object of *each* Virtual System.  

* While working with traffic that undergoes CPAS (e.g., when Proxy mode is enabled, or HTTPS Inspection is enabled), then the connection will be broken by CPAS into two parts (between Client and the Security Gateway; and between Security Gateway and the Server). In that state, if MSS is enabled only on one interface of Security Gateway, then only one part of the connection will obey the new MSS value. To make sure the MSS value will continue to the next interface of Security Gateway, make sure to enable it on both interfaces involved in the connection.  

* The above applies to Centrally managed SMB devices such as 1100/1400 as well.

<br />

<br />

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
