sk181155 - Users are not able to connect to RDP application with SNX in Application Mode
Users are not able to connect to RDP application with SNX in Application Mode
Product: Mobile Access / SSL VPN
Version: R80.40 (EOS), R81 (EOS), R81.10 (EOS), R81.20
OS: Gaia, Windows
Platform: All
Last Modified: 2024-03-13
Symptoms
RDP does not work with SSL Network Extender (SNX) in Application Mode.
In the STALog.txt (from sk104577, under "SNX client in Application Mode on Windows OS"):
[ ...][DATE TIME][apijack] apijack_CreateProcessW: flags=0x14 AppName:C:\WINDOWS\system32\mstsc.exe, CommandLine:c:\windows\\System32\\mstsc.exe /v 10.10.10.10 [ ...][DATE TIME][apijack] apijack_LoadLibraryExW: ntdll.dll - new ver [ ...][DATE TIME][apijack] apijack_should_hook_module: calling apijack_extract_module_name [ ...][DATE TIME][apijack] apijack_should_hook_module: module - C:\WINDOWS\SYSTEM32\ntdll.dll [ ...][DATE TIME][apijack] apijack_is_already_hooked: C:\WINDOWS\SYSTEM32\ntdll.dll already hooked [ ...][DATE TIME][apijack] apijack_GetProcAddress: Called - new ver [ ...][DATE TIME][apijack] apijack_GetProcAddress: modname=C:\WINDOWS\SYSTEM32\ntdll.dll, pszProcName=7726458c [ ...][DATE TIME][apijack] apijack_GetProcAddress: Load by name RtlGetNtSystemRoot [ ...][DATE TIME][apijack] apijack_GetProcAddress: Go get hook [ ...][DATE TIME][apijack] apijack_GetProcAddress: Check for notify procaddr [ ...][DATE TIME][apijack] apijack_GetProcAddress: return address: 77590270 [ ...][DATE TIME][apijack] apijack_inject_to_process: failed to obtain thread context data: Falscher Parameter. [ ...][DATE TIME][apijack] apijack_CreateProcessW: failed to inject code into process id (5732)
Solution
This problem was fixed. The fix is included in:
- Jumbo Hotfix Accumulator for R81.20 starting from Take 43
- Jumbo Hotfix Accumulator for R81.10 starting from Take 113
- Jumbo Hotfix Accumulator for R81 starting from Take 89
- Jumbo Hotfix Accumulator for R80.40 starting from Take 211
If you choose not to upgrade, Check Point can supply a Hotfix. Contact Check Point Support to get a Hotfix for this issue.
A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.
For faster resolution and verification, please collect CPinfo files from the Security Management Server and Security Gateways involved in the case.
Hotfix installation instructions:
Refer to sk168597 - How to install a Hotfix.
NOTE
This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.