sk181805 - SSL Network Extender (SNX) cannot connect after installing Jumbo Hotfix Accumulator
SSL Network Extender (SNX) cannot connect after installing Jumbo Hotfix Accumulator
Product
Mobile Access / SSL VPN, SSL Network Extender
Version
R80.40 (EOS), R81 (EOS), R81.10 (EOS), R81.20
OS
Gaia
Last Modified
2024-09-24
Symptoms
- SSL Network Extender (SNX) cannot connect (the connect button is not working) after installing a Jumbo Hotfix Accumulator on the Security Gateway.
- SNX fails to connect to the Security Gateway after logging into Mobile Access Portal when the IP address of the Mobile Access Portal (as resolved by the organization DNS from the Mobile Access Portal's FQDN) differs from the IP address of the Security Gateway object in SmartConsole.
Cause
The SSL Network Extender (SNX) behavior was changed in these Jumbo Hotfix Accumulators:
- R81.20 Jumbo Hotfix Accumulator Take 41
- R81.10 Jumbo Hotfix Accumulator Take 128
- R81 Jumbo Hotfix Accumulator Take 89
- R80.40 Jumbo Hotfix Accumulator Take 205
SNX used to connect back to Mobile Access Portal FQDN by resolving its IP address locally. This method makes it sensitive to DNS poisoning attacks, such as those specified by TunnelCrack. Therefore, SNX was modified to connect back to the Security Gateway's / Cluster Member's IP address by default, instead of connecting to the IP address from the DNS resolving of the Mobile Access Portal FQDN.
Solution
Behavior Change (PMTR-95099):
This problem was fixed. The fix is included in:
- Jumbo Hotfix Accumulator for R81.20 starting from Take 70
- Jumbo Hotfix Accumulator for R81.10 starting from Take 152
- Jumbo Hotfix Accumulator for R81 starting from Take 99
If you choose not to upgrade, Check Point can supply a Hotfix. Contact Check Point Support to get a Hotfix for this issue.
A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.
For faster resolution and verification, please collect CPinfo files from the Security Management Server and Security Gateways involved in the case.
Hotfix installation instructions:
Refer to sk168597 - How to install a Hotfix.
Customers who used the workaround need to revert it. Please contact TAC to assist with the procedure.
NOTE
This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.
Article Properties
Access Level: General
Status: Approved by TAC
Date Created: 2023-12-15
Last Modified: 2024-09-24