> Source: [sk39270](https://support.checkpoint.com/results/sk/sk39270)

# sk39270 - "Fragmentation needed and DF Set" message is sent every 10 minutes

| Property | Value |
|----------|-------|
| Solution ID | sk39270 |
| Date Created | 2009-04-14 |
| Last Modified | 2016-12-01 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |

## Cause

When packet is received which has DF (Don't Fragment) bit set, if this packet need to be encrypted, and the encapsulated packet size is expected to be larger than MTU, VPN kernel sends an ICMP Need-to-Fragment packet to sender host. Also, VPN kernel holds the source and destination address as found in the packet to be encrypted for a pre-defined time in table called IPSEC_mtu_icmp to mark the MTU behavior of the source host.

## Solution

Change VPN-1 settings to either fragment the packet even DF bit is set or send ICMP Need-to-Fragment to sender host and is controlled by �keep_DF_flag� attribute. For each Security Gateway object there are two attributes:

* keep_DF_flag (used for the Security gateway object).
* keep_DF_flag_SR (downloaded to SecureRemote during "Download topology" action).  

If the value of keep_DF_flag is set to 0, meaning the DF flag is disabled.   
If the value of keep_DF_flag is set to 1, Security gateway keeps the DF bit on the original packet.  

This behavior prevents packet fragmentation in kernel as much as possible since packet fragmentation consumes resources. By default VPN kernel remembers based on IPSEC_mtu_icmp table information for 10 minutes that an ICMP Need-to-Fragment packet has been sent. Next ICMP will be only sent when the entry expires from this table.   

To change the expiry and frequency of how often ICMP to be sent:

1. Edit the relevant `vpn_table.def` file on the Security Management Server per [sk92332 (Customizing the VPN configuration for Check Point Security Gateway - 'vpn_table.def' file)](http://supportcontent.checkpoint.com/solutions?id=sk92332).

2. Locate the line:   
   `IPSEC_mtu_icmp = dynamic expires 600;`   

   Change the value 600 (it is in seconds = 10 minutes) to any desired value. Do not set to less than 4 seconds, VPN kernel wait 4 seconds after each ICMP for the host to correct its behavior.

3. Install the Security Policy.

<br />

The above mechanism of sending ICMP and MTU behavior is only executed if:

* `ipsec_dont_fragment` is set to true ( Default ).
* Original packet has DF bit set.
* The encrypted packet is larger than MTU.
* Packet's source is not a multicast IP

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
