sk182923 - Mobile Access SSL Network Extender (SNX) remote users with Windows 11 24H2 fail to connect
Mobile Access SSL Network Extender (SNX) remote users with Windows 11 24H2 fail to connect
Product: Mobile Access / SSL VPN
Version: R81.10 (EOS), R81.20, R82
Last Modified: 2026-02-18
Symptoms
- Endpoint users can log in to the Mobile Access page, but cannot connect to resources behind the Security Gateway using SSL Network Extender (SNX).
- The operating system of the endpoint computer is Windows 11 24H2.
- In Windows Console on the endpoint computer, the slimsvc.log file shows these messages:
[ 8272 6388]@DESKTOP-U2QHH8N[25 Nov 10:59:07][] cprti_create_req: normal add_route failed. Identified as vista, calling new api
[ 8272 6388]@DESKTOP-U2QHH8N[25 Nov 10:59:07][] cprti_getForwardType
[ 8272 6388]@DESKTOP-U2QHH8N[25 Nov 10:59:07][] cprti_create_req: normal add_route failed. Identified as vista, calling new api
[ 8272 6388]@DESKTOP-U2QHH8N[25 Nov 10:59:07][] cprti_getForwardType
[ 8272 6388]@DESKTOP-U2QHH8N[25 Nov 10:59:07][] cprti_getForwardType
[ 8272 6388]@DESKTOP-U2QHH8N[25 Nov 10:59:07][] cprti_getForwardType
[ 8272 6388][25 Nov 10:59:07][] cprti_change_route_metric
[ 8272 6388]@DESKTOP-U2QHH8N[25 Nov 10:59:07][] Failed to set route dst: 100007f mask: ffffffff
[ 8272 6388]@DESKTOP-U2QHH8N[25 Nov 10:59:07][] cprti_getForwardType
[ 8272 6388][25 Nov 10:59:07][] cprti_change_route_metric
[ 8272 6388]@DESKTOP-U2QHH8N[25 Nov 10:59:07][] Failed to set route dst: ffffff7f mask: ffffffff
[ 8272 6388]@DESKTOP-U2QHH8N[25 Nov 10:59:07][] cprti_getForwardType
[ 8272 6388]@DESKTOP-U2QHH8N[25 Nov 10:59:07][] cprti_getForwardType
Cause
The conflict resolution mechanism in Windows 11 24H2 is different than in earlier versions of Windows.
Solution
This problem was fixed. The fix is included in:
- Jumbo Hotfix Accumulator for R82 starting from Take 73
- Jumbo Hotfix Accumulator for R81.20 starting from Take 122
If you choose not to upgrade, Check Point can supply a Hotfix. Contact Check Point Support to get a Hotfix for this issue.
A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.
For faster resolution and verification, please collect CPinfo files from the Security Management Server and Security Gateways involved in the case.
Hotfix installation instructions:
Refer to sk168597 - How to install a Hotfix.
This workaround is available:
On the Windows endpoint computer, create a new Windows Registry parameter.
Procedure
On the Windows endpoint computer, open the Registry Editor.
Go to this location:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\cpextender
Create a new DWORD entry with the name
MetricSetMethod.Set the value of
MetricSetMethodto1.Restart the Windows endpoint computer.
NOTE
This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.
Article Properties
Access Level: General
Status: Approved by TAC
Date Created: 2024-12-13
Last Modified: 2026-02-18