# SSL Network Extender (SNX) Features

- Ability to run SNX from the command line on Linux and macOS (for the [IPsec VPN](https://sc1.checkpoint.com/documents/SSL_Network_Extender_AdminGuide/Content/Topics-SNX-Admin-Guide/SNX-Features.htm?TocPath=_____6#) only).

- Easy installation and deployment.

- Intuitive and easy interface for configuration and use.

- The SNX mechanism is based on Visitor Mode and Office Mode.

- Automatic proxy detection is implemented.

- Small size client:
  - Download size of the SNX client is smaller than 400,000 kilobytes.
  - After the installation, the size of SNX is approximately 650,000 kilobytes.

- All [Security Gateway](https://sc1.checkpoint.com/documents/SSL_Network_Extender_AdminGuide/Content/Topics-SNX-Admin-Guide/SNX-Features.htm?TocPath=_____6#) authentication schemes are supported:
  - Authentication can be performed using a certificate, Check Point password or external user databases, such as SecurID, LDAP, RADIUS, and so forth (for the [Mobile Access](https://sc1.checkpoint.com/documents/SSL_Network_Extender_AdminGuide/Content/Topics-SNX-Admin-Guide/SNX-Features.htm?TocPath=_____6#) Software Blade only).
  - Authentication for the IPsec VPN Software Blade: certificate and Check Point password.

- At the end of the session, no information about the user or Security Gateway remains on the client machine.

- Extensive logging capability, on the Security Gateway.

- SNX Upgrade is supported. SNX is upgraded in Jumbo [Hotfix](https://sc1.checkpoint.com/documents/SSL_Network_Extender_AdminGuide/Content/Topics-SNX-Admin-Guide/SNX-Features.htm?TocPath=_____6#) Accumulators.

- The SNX supports the RC4 encryption method.

- Users can authenticate using certificates issued by any trusted CA that is defined as such by the system administrator in [SmartConsole](https://sc1.checkpoint.com/documents/SSL_Network_Extender_AdminGuide/Content/Topics-SNX-Admin-Guide/SNX-Features.htm?TocPath=_____6#).

- SNX can be configured to work in Hub Mode.
  - VPN routing for remote access clients is enabled in Hub Mode.
  - In Hub mode, all traffic is directed through a central Hub.
