> Source: [sk112119](https://support.checkpoint.com/results/sk/sk112119)

# sk112119 - After enabling IPS all traffic going over VPN tunnels dropped, although VPN tunnels never go down

| Property | Value |
|----------|-------|
| Solution ID | sk112119 |
| Date Created | 2016-06-27 |
| Last Modified | 2016-07-04 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |
| OS | Gaia |

## Symptoms

- * After enabling IPS, all traffic going over VPN tunnels is dropped, although the VPN tunnels never go down.
* Output of *fw ctl zdebug drop* shows the packet being dropped for "fwfrag_limit: Blocking all fragments".
* Traffic passing in the clear is unaffected.

## Cause

Due to added overhead, ESP packets are more likely to be fragmented than packets passing in the clear.

Configuring the IP Fragments protection with the additional setting of "Forbid IP Fragments" will have a large effect on VPN traffic.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
