Courseiva

CCSM Advanced VPN Troubleshooting Practice Question

A Security Administrator has configured a permanent site-to-site VPN between two Security Gateways. The tunnel is up, but large file transfers intermittently stall while small pings and HTTP requests succeed. The administrator notices the peer gateways advertise an MSS of 1460 on their external interfaces, and no NAT is involved. Which Check Point action is the most appropriate to resolve this?

⚠ Common exam trap

The trap here is assuming that enlarging the tunnel MTU setting will fix large-transfer stalls, when the real issue is that TCP peers are advertising an MSS too large for the encrypted path.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable TCP MSS clamping on the Security Gateway so that the gateway rewrites the MSS value advertised by hosts inside the VPN.

When the tunnel is up but bulk transfers stall while small requests succeed, the classic cause is an MTU/MSS mismatch on the encrypted path. TCP MSS clamping makes the gateway rewrite the MSS field so TCP senders create segments that fit inside the tunnel without requiring fragmentation, which restores reliable large transfers.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable aggressive mode for IKE Phase 1 so that the peers can negotiate a smaller MTU during tunnel setup.

    Why it's wrong here

    Aggressive mode changes how Phase 1 identities are exchanged; it does not negotiate or adjust MTU values for the data path. The tunnel is already established, so changing Phase 1 mode would not affect the fragmentation behaviour of bulk traffic and could weaken identity protection.

  • ✓

    Enable TCP MSS clamping on the Security Gateway so that the gateway rewrites the MSS value advertised by hosts inside the VPN.

    Why this is correct

    TCP MSS clamping lets the gateway reduce the MSS advertised by internal hosts so TCP segments fit within the tunnel path MTU without fragmenting. Since large transfers stall but small traffic succeeds, this directly addresses the MTU mismatch on the encrypted path and is the standard Check Point remedy for this symptom.

  • ✗

    Increase the IPsec tunnel MTU value in the gateway's encryption properties so that larger packets are allowed into the tunnel.

    Why it's wrong here

    Raising the configured tunnel MTU does not help when the physical path cannot carry the larger encapsulated packet; the added IPsec header still pushes the datagram over the path limit. The symptom is caused by packets exceeding the real path MTU, so allowing larger frames into the tunnel would worsen black-holing.

  • ✗

    Configure the peer gateways to use UDP encapsulation on port 4500 for the IPsec traffic.

    Why it's wrong here

    UDP encapsulation on port 4500 is used mainly to traverse NAT devices, not to solve an MTU problem. It adds encapsulation overhead, which can actually reduce the usable payload further. Because the scenario states no NAT is involved, this setting would not correct the large-transfer stalls.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

This CCSM question is part of Courseiva's 219-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Check Point exam blueprint

This CCSM practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSM exam.