sk182923 - Mobile Access SSL Network Extender (SNX) remote users with Windows 11 24H2 fail to connect

Mobile Access SSL Network Extender (SNX) remote users with Windows 11 24H2 fail to connect

Product: Mobile Access / SSL VPN
Version: R81.10 (EOS), R81.20, R82
Last Modified: 2026-02-18

Symptoms

[ 8272 6388]@DESKTOP-U2QHH8N[25 Nov 10:59:07][] cprti_create_req: normal add_route failed. Identified as vista, calling new api
[ 8272 6388]@DESKTOP-U2QHH8N[25 Nov 10:59:07][] cprti_getForwardType
[ 8272 6388]@DESKTOP-U2QHH8N[25 Nov 10:59:07][] cprti_create_req: normal add_route failed. Identified as vista, calling new api
[ 8272 6388]@DESKTOP-U2QHH8N[25 Nov 10:59:07][] cprti_getForwardType
[ 8272 6388]@DESKTOP-U2QHH8N[25 Nov 10:59:07][] cprti_getForwardType
[ 8272 6388]@DESKTOP-U2QHH8N[25 Nov 10:59:07][] cprti_getForwardType
[ 8272 6388][25 Nov 10:59:07][] cprti_change_route_metric
[ 8272 6388]@DESKTOP-U2QHH8N[25 Nov 10:59:07][] Failed to set route dst: 100007f mask: ffffffff
[ 8272 6388]@DESKTOP-U2QHH8N[25 Nov 10:59:07][] cprti_getForwardType
[ 8272 6388][25 Nov 10:59:07][] cprti_change_route_metric
[ 8272 6388]@DESKTOP-U2QHH8N[25 Nov 10:59:07][] Failed to set route dst: ffffff7f mask: ffffffff
[ 8272 6388]@DESKTOP-U2QHH8N[25 Nov 10:59:07][] cprti_getForwardType
[ 8272 6388]@DESKTOP-U2QHH8N[25 Nov 10:59:07][] cprti_getForwardType

Cause

The conflict resolution mechanism in Windows 11 24H2 is different than in earlier versions of Windows.

Solution

This problem was fixed. The fix is included in:

If you choose not to upgrade, Check Point can supply a Hotfix. Contact Check Point Support to get a Hotfix for this issue.

A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.

For faster resolution and verification, please collect CPinfo files from the Security Management Server and Security Gateways involved in the case.

Hotfix installation instructions:
Refer to sk168597 - How to install a Hotfix.

This workaround is available:

On the Windows endpoint computer, create a new Windows Registry parameter.

Procedure

  1. On the Windows endpoint computer, open the Registry Editor.

  2. Go to this location:

    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\cpextender

  3. Create a new DWORD entry with the name MetricSetMethod.

  4. Set the value of MetricSetMethod to 1.

  5. Restart the Windows endpoint computer.

NOTE

This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.

Article Properties

Access Level: General
Status: Approved by TAC
Date Created: 2024-12-13
Last Modified: 2026-02-18