sk181805 - SSL Network Extender (SNX) cannot connect after installing Jumbo Hotfix Accumulator

SSL Network Extender (SNX) cannot connect after installing Jumbo Hotfix Accumulator

Product

Mobile Access / SSL VPN, SSL Network Extender

Version

R80.40 (EOS), R81 (EOS), R81.10 (EOS), R81.20

OS

Gaia

Last Modified

2024-09-24

Symptoms

Cause

The SSL Network Extender (SNX) behavior was changed in these Jumbo Hotfix Accumulators:

SNX used to connect back to Mobile Access Portal FQDN by resolving its IP address locally. This method makes it sensitive to DNS poisoning attacks, such as those specified by TunnelCrack. Therefore, SNX was modified to connect back to the Security Gateway's / Cluster Member's IP address by default, instead of connecting to the IP address from the DNS resolving of the Mobile Access Portal FQDN.

Solution

Behavior Change (PMTR-95099):

This problem was fixed. The fix is included in:

If you choose not to upgrade, Check Point can supply a Hotfix. Contact Check Point Support to get a Hotfix for this issue.

A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.

For faster resolution and verification, please collect CPinfo files from the Security Management Server and Security Gateways involved in the case.

Hotfix installation instructions:

Refer to sk168597 - How to install a Hotfix.

Customers who used the workaround need to revert it. Please contact TAC to assist with the procedure.

NOTE

This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.

Article Properties

Access Level: General
Status: Approved by TAC
Date Created: 2023-12-15
Last Modified: 2024-09-24