<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco PIX compactability with Checkpoint in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-pix-compactability-with-checkpoint/m-p/866276#M494577</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You do not need to change anything.  What &lt;/P&gt;&lt;P&gt;is the checkpoint version?  Is it NG, NG with&lt;/P&gt;&lt;P&gt;AI or NGx?  Make sure you use the latest&lt;/P&gt;&lt;P&gt;HotFix Accumulator (HFA) on the checkpoint side.&lt;/P&gt;&lt;P&gt;When in doubt, run "fw ver" and it will tell&lt;/P&gt;&lt;P&gt;the current version on the firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Try to upgrade to the latest HFA first.&lt;/P&gt;&lt;P&gt;if you still has issues, then the next &lt;/P&gt;&lt;P&gt;thing to do is to use dbedit to modify some&lt;/P&gt;&lt;P&gt;parameters on the checkpoint firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 28 Nov 2007 17:53:20 GMT</pubDate>
    <dc:creator>kevin.jones1</dc:creator>
    <dc:date>2007-11-28T17:53:20Z</dc:date>
    <item>
      <title>Cisco PIX compactability with Checkpoint</title>
      <link>https://community.cisco.com/t5/network-security/cisco-pix-compactability-with-checkpoint/m-p/866274#M494565</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We need your assistance &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Issue: VPN Pkts get dropped. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) A Site-to-Site VPN is established b/w Checkpoint &amp;amp; Cisco PIX. &lt;/P&gt;&lt;P&gt;2) Often the connectvitiy Flaps, i.e. the pkst get dropped.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Error:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Pix: Duplicate pkt on Phase 2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Checkpoint: Virtual defragmentation error: Timeout&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When checked in Google, the solution is 'caused to due to jumbo packets traversing thru the tunnel' and need to change the MTU size.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have S-2-S tunnels with multiple customers and have issue with only one customer and he is asking to change the MTU Size. To my knowledge we can only change MTU for an interface and not for tunnel.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kindly advice me on this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Thebull.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 09:48:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-pix-compactability-with-checkpoint/m-p/866274#M494565</guid>
      <dc:creator>tkstkstks</dc:creator>
      <dc:date>2020-02-21T09:48:17Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco PIX compactability with Checkpoint</title>
      <link>https://community.cisco.com/t5/network-security/cisco-pix-compactability-with-checkpoint/m-p/866275#M494572</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can change the MTU for a tunnel. Each tunnel has a virtual interface associated with it. You can go to the virtual interface config and specify the required MTU size.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Nov 2007 22:43:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-pix-compactability-with-checkpoint/m-p/866275#M494572</guid>
      <dc:creator>tstanik</dc:creator>
      <dc:date>2007-11-27T22:43:04Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco PIX compactability with Checkpoint</title>
      <link>https://community.cisco.com/t5/network-security/cisco-pix-compactability-with-checkpoint/m-p/866276#M494577</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You do not need to change anything.  What &lt;/P&gt;&lt;P&gt;is the checkpoint version?  Is it NG, NG with&lt;/P&gt;&lt;P&gt;AI or NGx?  Make sure you use the latest&lt;/P&gt;&lt;P&gt;HotFix Accumulator (HFA) on the checkpoint side.&lt;/P&gt;&lt;P&gt;When in doubt, run "fw ver" and it will tell&lt;/P&gt;&lt;P&gt;the current version on the firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Try to upgrade to the latest HFA first.&lt;/P&gt;&lt;P&gt;if you still has issues, then the next &lt;/P&gt;&lt;P&gt;thing to do is to use dbedit to modify some&lt;/P&gt;&lt;P&gt;parameters on the checkpoint firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Nov 2007 17:53:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-pix-compactability-with-checkpoint/m-p/866276#M494577</guid>
      <dc:creator>kevin.jones1</dc:creator>
      <dc:date>2007-11-28T17:53:20Z</dc:date>
    </item>
  </channel>
</rss>

