> Source: [sk182746](https://support.checkpoint.com/results/sk/sk182746)

# sk182746 - UDP traffic is fragmented when sent from Centrally Managed Spark Firewall via Site to Site VPN tunnels

| Property | Value |
|----------|-------|
| Solution ID | sk182746 |
| Date Created | 2024-10-09 |
| Last Modified | 2024-10-10 |
| Technical Level | Advanced |
| Products | Spark Firewall (Locally Managed) |
| Versions | R81.10.X |
| Platform | 1570R, 1575R, 1500, 1900, 2000, 1600, 1800, 1595R |

## Symptoms

- * The issue occurs exclusively with UDP traffic(port 41014) used for communication between the client and server over a Site-to-Site VPN tunnel on Centrally Managed Quantum Spark appliances.

* In contrast, TCP traffic operates without issues, and allows successful communication through the same VPN tunnel, which indicates that the tunnel itself is functional.

* Following the resolution steps outlined in [sk98074](https://support.checkpoint.com/results/sk/sk98074), including any adjustments suggested for similar issues, does not rectify the UDP communication problem.

## Cause

In a Site-to-Site VPN configuration involving a Centrally Managed Quantum Spark appliance, UDP traffic may fail to traverse the VPN tunnel due to fragmentation issues. Specifically, when the communication path is defined as:  

**Client** \> **SMB VPN** \> **VPN Peer** \> **Internal Server**   

UDP packets, which are inherently connectionless and do not guarantee delivery, can become fragmented at the client side before entering the VPN tunnel. This fragmentation occurs because the original packet size exceeds the Maximum Transmission Unit (MTU) of the VPN tunnel. As a result, the fragmented packets cannot encapsulate the necessary VPN headers, preventing successful transmission through the tunnel.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
