CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have 72 attendees signed up from 20 countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Miscellaneous
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2005-08-14
roadrunner roadrunner is offline
Senior Member
 
Join Date: 2005-08-12
Posts: 162
Rep Power: 4
roadrunner has an average reputation (10+)
Default Token Ring PMTU and FireWall-1

Token Ring PMTU and FireWall-1
(Note: the info on this page was written by Thomas Piergallini) Here is the world of Path MTU as I have gathered the info from sites around the planet. Enjoy for your reference. Ignore the references to UUNET, I mainly wrote this for sales-engineer types. The info came from the Microsoft and Raptor sites, and then I verified all of it in the lab.
If a customer's internal network is a Microsoft Windows based Token Ring or FDDI network with hosts capable of Path MTU Discovery, significant performance degradation can occur when accessing other PMTU capable sites on the internet (for a detailed explanation, see the Microsoft Technical Note below). These performance problems are most evident when utilizing HTTP to download a typical web page.

The following is the UUNET recommended solution to this problem. Note well, that this problem is not directly related to any of the firewalls that UUNET sells, although a firewall could exacerbate the problem if improperly configured.

To solve PMTU performance degradation problems, do one of the following:


{NOT RECOMMENDED} All Windows NT and Windows95 Token Ring or FDDI workstations should have PMTU disabled (not recommended) or
{RECOMMENDED} Windows workstations should configure their web browsers to point to a proxy server that has PMTU disabled. This could be a proxy server behind the firewall, or the firewall itself. Although all the firewalls that UUNET sells have a proxy server capability, we recommend using an internal proxy server, for best performance and flexibility.
See the following Tech Note from Microsoft: http://support.microsoft.com/support.../q136/9/70.asp



-- RobertGraham - 16 Mar 2004


FAQForm
FAQs.Class: TroubleshootingFAQs
FAQs.OS:
FAQs.Version:
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 01:44.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0