CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > VPN's (Virtual Private Networks)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-03-09
Junior Member
 
Join Date: 2006-01-04
Posts: 7
Rep Power: 0
elad_ has an average reputation (10+)
Default ssh problem

I have a Site to Site VPN both NG AI R55
when i'm open a ssh connection from one site to the other
i can work untill it's stuck
it happens when i'm trying to see a lot of data (ex. ls -R )
sometimes it's happen and sometimes not

anyone have a solution for me ?
Reply With Quote
  #2 (permalink)  
Old 2006-03-10
Junior Member
 
Join Date: 2006-03-09
Location: England
Posts: 2
Rep Power: 0
nicodiemus has an average reputation (10+)
Default Re: ssh problem

This may not be relevant, but have you excluded it from the VPN community?
It might just be sluggish due to travelling over VPN.
Reply With Quote
  #3 (permalink)  
Old 2006-03-11
Senior Member
 
Join Date: 2005-11-21
Location: Europe, Lithuania
Posts: 291
Rep Power: 4
Sergej has an average reputation (10+)
Default Re: ssh problem

It can be an MTU issues (small packets leaks, big one need to be fragmented, but DF=1. Packet need to be dropped. Information ICMP message about this incident missed out somewhere during transfer). Try to drill down to the Microsoft and CheckPoint Tech support articles.
Keywords:
EnablePMTUBHDetect
EnablePMTUDiscovery
ping x.x.x.x -l 1500 -f
Reply With Quote
  #4 (permalink)  
Old 2006-03-12
Junior Member
 
Join Date: 2006-01-04
Posts: 7
Rep Power: 0
elad_ has an average reputation (10+)
Default Re: ssh problem

No i dodn't exculed it
and the MTU is the default 1500 on both site
Reply With Quote
  #5 (permalink)  
Old 2006-03-12
Senior Member
 
Join Date: 2005-11-21
Location: Europe, Lithuania
Posts: 291
Rep Power: 4
Sergej has an average reputation (10+)
Default Re: ssh problem

That's it. Sometimes MTU discovery fails somewhere inbeetween of you firewalls. At this moments big SSH data transfers fails.
You can do a test:
1. (optional) Disable MTU Discovery on the SSH server (I'm not sure how to do this on unix)
2. Set MTU on SSH server to 1300 (fconfig interface_name mtu 1300)
3. Try whatever big commands you want (ls -la, or something like this) thought you Site to site VPN
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 00:03.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0