> Source: [sk112014](https://support.checkpoint.com/results/sk/sk112014)

# sk112014 - "Cannot establish connection to SSL Network Extender gateway. Try to reconnect." error when connecting with SSL Network Extender on VSX after installing the "TLS 1.2 Hotfix for R77.30"

| Property | Value |
|----------|-------|
| Solution ID | sk112014 |
| Date Created | 2016-06-22 |
| Last Modified | 2020-11-02 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |
| OS | Gaia |

## Symptoms

- * "`Cannot establish connection to SSL Network Extender gateway. Try to reconnect.`" error when connecting with SSL Network Extender (SNX) to Mobile Access Portal on R77.30 VSX Virtual System in the following scenario:

  1. Installed "TLS 1.2 Hotfix for R77.30" from [sk107166 - TLS1.2 Support Plan for Check Point Products](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk107166) on R77.30 VSX Gateway / VSX Cluster
  2. In SmartDashboard: set the lowest TLS version for portals to either "`TLS1.1`", or "`TLS1.2`" and installed policy   
     (*Policy* menu - click on *Global Properties...* - go to *SmartDashboard Customization* pane - click on the *Configure...* button - go to *Portal Properties* - in the *snx_ssl_min_ver* field, select either "TLS1.1", or "TLS1.2" - click on OK)
  3. On SNX client Windows-machine: Internet Explorer - *Tools* menu - *Internet options* - *Advanced* tab - checked either the "`Use TLS 1.1`", or the "`Use TLS 1.2`" box
* SSL Network Extender (SNX) is able to connect to Mobile Access Portal on this VSX Gateway / VSX Cluster only if:

  * "TLS 1.0" is selected in SmartDashboard
  * "Use TLS 1.0" is selected in Internet Explorer on SNX client
* Different versions of Mobile Access SNX Client are installed in the context of VS0 (VSX Gateway itself) and in the context of the involved Virtual System:

  * */opt/CPcvpn-R77/htdocs/SNX/CSHELL/snx_ver.txt* file shows version 800008005
  * */opt/CPcvpn-R77/CTX/CTX0000\<VSID\>/htdocs/SNX/CSHELL/snx_ver.txt* file shows version 800007102

## Cause

The hotfix installation script did not copy the required Mobile Access SNX Client files from the context of VS0 (VSX Gateway itself) to the contexts of the involved Virtual Systems.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
