# Introduction to SSL Network Extender (SNX)

SSL Network Extender is a thin client that remote users use to access internal resources that the administrator defines as applications.

SNX can work with the [Mobile Access](https://sc1.checkpoint.com/documents/SSL_Network_Extender_AdminGuide/Content/Topics-SNX-Admin-Guide/Introduction-to-SNX.htm#) Check Point Software Blade on a Security Gateway that provides a Remote Access VPN access for managed and unmanaged clients. Acronym: MAB.

or the [IPsec VPN](https://sc1.checkpoint.com/documents/SSL_Network_Extender_AdminGuide/Content/Topics-SNX-Admin-Guide/Introduction-to-SNX.htm#) Software Blade. The IPsec VPN Software Blade and the Mobile Access Software Blade require different licenses.

## Workflow:

1. The administrator configures a [Security Gateway](https://sc1.checkpoint.com/documents/SSL_Network_Extender_AdminGuide/Content/Topics-SNX-Admin-Guide/Introduction-to-SNX.htm#) as an SSL-enabled web server that supports Remote Access clients.
2. The remote user downloads the SNX client from the Security Gateway.
3. The remote user can access internal resources. In a Mobile Access Software Blade configuration, the remote user can access configured applications.

## Comparison of SNX supported features with the Mobile Access Software Blade and the IPsec VPN Software Blade

| Type of SNX | End User Experience | Supported Access Control Rules | Supported Operating Systems |
| --- | --- | --- | --- |
| SNX with Mobile Access Software Blade | The Mobile Access Portal downloads SNX from the Security Gateway automatically. | Supports Access Control rules in [SmartConsole](https://sc1.checkpoint.com/documents/SSL_Network_Extender_AdminGuide/Content/Topics-SNX-Admin-Guide/Introduction-to-SNX.htm#) based on:<br>- User groups<br>- User roles<br>- Networks<br>- Subnets<br>- IP addresses | - Windows<br>- Linux<br>- macOS<br>Supported only with Mobile Access Portal.<br>CLI is not supported. |
| SNX with Remote Access VPN Software Blade | Users download SNX from a Security Gateway portal. | Supports Access Control rules in SmartConsole based on:<br>- Networks<br>- Subnets<br>- IP addresses | - Linux (CLI only)<br>- macOS (CLI only)<br>- Windows (IPsec VPN portal - works only with Internet Explorer) |

If the Mobile Access Software Blade is enabled on the Security Gateway:
- SNX works through Mobile Access only.
- You must configure the Mobile Access policy:
  - [Management Server](https://sc1.checkpoint.com/documents/SSL_Network_Extender_AdminGuide/Content/Topics-SNX-Admin-Guide/Introduction-to-SNX.htm#) R82 and higher: In SmartConsole > Security Policies view > section Shared Policies > section Mobile Access > click the page Policy.
  - Management Server R81.20 and lower: In SmartConsole > Manage & Settings view > click Blades > in the section Mobile Access, click Configure in SmartDashboard > tab Mobile Access > click the page Policy.

If the Mobile Access Software Blade is disabled and the IPsec VPN Software Blade is enabled on the Security Gateway:
- SNX works through the IPsec VPN Software Blade.
- You must configure the Access Control Policy in SmartConsole.

|     |     |
| --- | --- |
|  | Important - If you configured the SSL Network Extender settings in the Security Gateway for the IPsec VPN Software Blade, and then you enabled the Mobile Access Software Blade, then you must reconfigure the required rules in the Mobile Access policy. The SSL Network Extender rules in the Access Control Policy do not apply anymore. |

## SNX Modes for Mobile Access Portal on an Endpoint Computer with Windows OS

SNX for Mobile Access supports **Network Mode** and **Application Mode**.

| Category | Network Mode | Application Mode |
| --- | --- | --- |
| Supported application types | All Native IP-based applications and web applications | Most Native IP-based applications and web applications are supported.<br>OPSEC-certified applications are tested and verified<br>UDP-based applications are not supported. |
| Supported web browsers on the client computer | - Google Chrome<br>- Mozilla Firefox<br>- Microsoft Edge<br>- Safari | - Google Chrome<br>- Mozilla Firefox<br>- Microsoft Edge<br>- Safari |
| Required privileges on the client computer | Administrator privileges required on the client computer | Administrator privileges not required on the client computer |
| How remote users open the application | Remote users can open applications in the Mobile Access portal or on the desktop of the endpoint computer. | Remote users can open applications only in the Mobile Access Portal.<br>An application that is not supported in Application Mode does not appear in the Mobile Access Portal. |

|     |     |
| --- | --- |
|  | Note - Some [Anti-Virus](https://sc1.checkpoint.com/documents/SSL_Network_Extender_AdminGuide/Content/Topics-SNX-Admin-Guide/Introduction-to-SNX.htm#) applications do not scan email when Microsoft Outlook is launched with SNX Application Mode because the mail is encrypted with SSL before the scanning begins. |

## Downloading SNX for Mobile Access or Remote Access VPN

| Software Blade | Endpoint Computer Operating System | How to Download SNX |
| --- | --- | --- |
| Mobile Access | Windows, Linux, or macOS | The endpoint computer automatically downloads SNX as a desktop application from the Mobile Access Portal. |
| Remote Access VPN | Windows | The endpoint computer automatically downloads SNX as a desktop application from the Remote Access VPN portal. |
| Remote Access VPN | Linux or macOS | You must download SNX manually as a command line application.<br>See [Basic Configuration of SSL Network Extender for Remote Access VPN](https://sc1.checkpoint.com/documents/SSL_Network_Extender_AdminGuide/Content/Topics-SNX-Admin-Guide/SNX-for-RA-Basic-Configuration.htm). |

## Commonly Used Concepts

These are commonly used concepts that you encounter when working with the SSL Network Extender:

[Remote Access VPN](https://sc1.checkpoint.com/documents/SSL_Network_Extender_AdminGuide/Content/Topics-SNX-Admin-Guide/Introduction-to-SNX.htm#) refers to remote users accessing the network with client software such as Endpoint VPN clients, SSL clients, or third party IPsec clients. The Security Gateway provides a _Remote Access VPN Service_ to the remote clients.

[Remote Access Community](https://sc1.checkpoint.com/documents/SSL_Network_Extender_AdminGuide/Content/Topics-SNX-Admin-Guide/Introduction-to-SNX.htm#) is a type of VPN community created specifically for users that usually work from remote locations, outside of the corporate LAN.

[Office Mode](https://sc1.checkpoint.com/documents/SSL_Network_Extender_AdminGuide/Content/Topics-SNX-Admin-Guide/Introduction-to-SNX.htm#) is a Check Point remote access VPN solution feature that enables a Security Gateway to assign a remote client an IP address. This IP address is only used internally for secure encapsulated communication and is not visible in the public network.

[Visitor Mode](https://sc1.checkpoint.com/documents/SSL_Network_Extender_AdminGuide/Content/Topics-SNX-Admin-Guide/Introduction-to-SNX.htm#) is a Check Point remote access VPN solution feature designed for firewalls and Proxy servers that are configured to block IPsec connectivity.

22 February 2026
