> Source: [sk90200](https://support.checkpoint.com/results/sk/sk90200)

# sk90200 - Latency when working via Site-to-Site VPN

| Property | Value |
|----------|-------|
| Solution ID | sk90200 |
| Date Created | 2012-12-16 |
| Last Modified | 2017-09-27 |
| Technical Level | Advanced |
| OS | Gaia |

## Cause

When a packet is received on the Security Gateway that is larger than defined MTU, an ICMP packet is sent by the Check Point Security Gateway to the Server in order to lower the MTU, however then Server/Gateway ignores it, and keeps sending the big packets to the Check Point Security Gateway.

At that time, the VPN kernel holds the Source and Destination address as found in the packet to be encrypted for a pre-defined time in kernel table called *IPSEC_mtu_icmp* to mark the MTU behavior of the source host until it sends the ICMP packet to lower the packet size.

When using the workaround, the client MTU is 1200, then the client sends the packet with DF flag and its MSS MTU of 1200 to the Server on the Internet.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
