> Source: [sk133572](https://support.checkpoint.com/results/sk/sk133572)

# sk133572 - Automatic Upgrade for Endpoint Security VPN  fails on the Security Gateway

| Property | Value |
|----------|-------|
| Solution ID | sk133572 |
| Date Created | 2018-08-04 |
| Last Modified | 2026-01-25 |
| Technical Level | General |
| Products | Endpoint Security |
| Versions | Cloud, E89.X, E88.X |
| OS | Gaia |

## Symptoms

- * Automatic Upgrade for Endpoint Security VPN on the Security Gateway fails.

* When a user connects to the Security Gateway after installing the policy, the upgrade prompt appears. However, the upgrade fails immediately.

* If Mobile Access Blade is enabled, debug logs from the client show:  

  `
  [ PID1 PID2][Date Time][talkhttps] ATalkHttps::ssl_packet_receive_cb: called`  
  `
  [ PID1 PID2][Date Time][talkhttps] ATalkHttps::ssl_packet_receive_cb: HTTP server supports '1.1' version`  
  `
  [ PID1 PID2][Date Time][TalkCCC] talkccc::ReceiveEv: HTTP server supports '1.1' version`  
  `
  [ PID1 PID2][Date Time][TalkCCC] talkccc::ReceiveEv: Response status code - 403`  
  `
  [ PID1 PID2][Date Time][TalkCCC] talkccc::GetIdFromMsg: Invalid fwset. Cannot extract id.`  
  `
  [ PID1 PID2][Date Time][TalkCCC] talkccc::ReceiveEv: got http error response. Remove front download request`  
  `
  [ PID1 PID2][Date Time][TalkCCC] talkccc::RemoveRequest: Called with cccError 308`  
  `
  [ PID1 PID2][Date Time][TalkCCC] talkccc::RemoveRequest: Calling the notify callback for the request 4`  
  `
  [ PID1 PID2][Date Time][UPGRADE_MANAGER] UpgradeManager::Notify: Error, got 308 errorcode`  
  `
  [ PID1 PID2][Date Time][TR_FLOW_STEP] TR_FLOW_STEP::TrUpgradeClientStep::UpgradeCompletionCallback: entering...`  
  `
  [ PID1 PID2][Date Time][TR_FLOW_STEP] TR_FLOW_STEP::TrUpgradeClientStep::UpgradeCompletionCallback: Upgrade failed. Set user_upgrade_mode to REMIND_USER`  
  `
  [ PID1 PID2][Date Time][CONFIG_MANAGER] ConfigurationManager::removeParam remove 'user_upgrade_mode', source: '3'`  
  `
  [ PID1 PID2][Date Time][CONFIG_MANAGER] ConfigurationManager::save()`  
  `
  [ PID1 PID2][Date Time][CONFIG_MANAGER] ConfigurationManager::save()`  
  `
  [ PID1 PID2][Date Time][slim_utils] RaisDbSetValue: Trying to open or create registry: Software\CheckPoint\TRAC`  
  `
  [ PID1 PID2][Date Time][slim_utils] RaisDbSetValue: Successfully opened key Software\CheckPoint\TRAC`  
  `
  [ PID1 PID2][Date Time][slim_utils] RaisDbSetValue: Successfully set (DWORD) key UpgradeAskTime with value 1533107547`  
  `
  [ PID1 PID2][Date Time][String] String::String::Translate: String with id `

* If Mobile Access Blade is not enabled, debugs from the client show: (The difference is with the line: Response status code - 403)   
  \[ 12040 18636\]\[5 Dec 11:10:12\]\[cpwssl\] cpWinSSL_fwasync_read: cpWinSSL_Decrypt_buffer returned: 00000000   
  \[ 12040 18636\]\[5 Dec 11:10:12\]\[cpwssl\] cpWinSSL_fwasync_read: delivering 451 chars to application   
  \[ 12040 18636\]\[5 Dec 11:10:12\]\[talkssl\] talkssl::client_handler: state: SSL_RECV - entering   
  \[ 12040 18636\]\[5 Dec 11:10:12\]\[talkssl\] talkssl::client_handler: got 451 bytes, wanted 65536 bytes   
  \[ 12040 18636\]\[5 Dec 11:10:12\]\[talkssl\] talkssl::client_handler: calling recv with dlen 451   
  \[ 12040 18636\]\[5 Dec 11:10:12\]\[talkhttps\] ATalkHttps::ssl_packet_receive_cb: called   
  \[ 12040 18636\]\[5 Dec 11:10:12\]\[talkhttps\] ATalkHttps::ssl_packet_receive_cb: HTTP server supports '1.1' version   
  \[ 12040 18636\]\[5 Dec 11:10:12\]\[TalkCCC\] talkccc::ReceiveEv: HTTP server supports '1.1' version   
  \[ 12040 18636\]\[5 Dec 11:10:12\]\[TalkCCC\] talkccc::ReceiveEv: Response status code - 404   
  \[ 12040 18636\]\[5 Dec 11:10:12\]\[TalkCCC\] talkccc::GetIdFromMsg: Invalid fwset. Cannot extract id.   
  \[ 12040 18636\]\[5 Dec 11:10:12\]\[TalkCCC\] talkccc::ReceiveEv: got http error response. Remove front download   
  \[ 12040 18636\]\[5 Dec 11:10:12\]\[TalkCCC\] talkccc::RemoveRequest: Called with cccError 308   
  \[ 12040 18636\]\[5 Dec 11:10:12\]\[TalkCCC\] talkccc::RemoveRequest: Calling the notify callback for the request 2   
  \[ 12040 18636\]\[5 Dec 11:10:12\]\[UPGRADE_MANAGER\] UpgradeManager::Notify: Error, got 308 errorcode   
  \[ 12040 18636\]\[5 Dec 11:10:12\]\[TR_FLOW_STEP\] TR_FLOW_STEP::TrUpgradeClientStep::UpgradeCompletionCallback:   
  \[ 12040 18636\]\[5 Dec 11:10:12\]\[TR_FLOW_STEP\] TR_FLOW_STEP::TrUpgradeClientStep::UpgradeCompletionCallback: Upgrade failed. Set user_upgrade_mode to REMIND_USER   
  \[ 12040 18636\]\[5 Dec 11:10:12\]\[CONFIG_MANAGER\] ConfigurationManager::removeParam remove 'user

## Cause

**Environment:** R80.x Security Gateways with Mobile Access blade enabled.

*** ** * ** ***

The multi-portal daemon does not have a reference for the CSHELL portal when connecting to the site over port 443.  

Starting from R80.x, the CSHELL directory is not available for the endpoint client.

## Solution

**Option 1:** Mobile Access Blade Disabled (and not required)  

Enable SNX on the target Gateway on the Smart Console:  
Open the target Gateway object -\> VPN client -\> Under "Other" enable SNX  

**Option 2:** Mobile Access Blade Enabled

[Contact Check Point Support](https://www.checkpoint.com/support-services/contact-support/) to get a Hotfix for this issue.

A Support Engineer will make sure the Hotfix is compatible with your environment before providing it.  
For faster resolution and verification, collect these files:

1. [CPinfo](https://support.checkpoint.com/results/sk/sk92739) file from the Management Server involved in the case.
2. [CPinfo](https://support.checkpoint.com/results/sk/sk92739) file from the Security Gateway / each Cluster Member involved in the case.

**Hotfix installation instructions:**   
Refer to [sk168597 - How to install a Hotfix](https://support.checkpoint.com/results/sk/sk168597).
**Important Notes:**   

* In addition to the Hotfix, the Platform Portal (WebUI) must be set to port 4434 and not 443.
* The Mobile Access Portal Settings URL must match the site name used by the client.
  * If the site name is an IP, the MAB portal URL must be an IP
  * If the site name is a FQDN, then the MAB portal must be FQDN
* Give the files the required permissions. Run these commands on the Security Gateway in Expert mode:  
  chmod 755 $FWDIR/conf/extender/CSHELL/TRAC.cab  
  chmod o+x $FWDIR/conf/extender/CSHELL/.  
  chmod 755 $CVPNDIR/htdocs/SNX/CSHELL/TRAC.cab  

  Restart cvpnd  
  # cvpnrestart

<br />

The following steps are required for regular and VSX gateways. For VSX gateways, make sure they are ran from the correct VSX environment.  

1. If the gateway is a Virtual System, copy *$CVPNDIR/conf/includes/SNX.location.conf* from Virtual System VS-0 to all other relevant VSs (VS-1, VS-2, ...)  

   For example:  
   *`cp /opt/CPcvpn-R80.30/conf/includes/SNX.location.conf /opt/CPcvpn-R80.30/CTX/CT0000X/conf/includes/SNX.location.conf`* and give permissions to the *SNX.location.conf* files in the new CTX folder locations.  
   For each file, run the command:  
   *`chmod 775 /opt/CPcvpn-R80.30/CTX/CT0000X/conf/includes/SNX.location.conf`* where CT0000X is the relevant VS.  

2. Make sure the following files exist in the $FWDIR/conf/extender/CSHELL directory:
   * For Windows:   
     `TRAC.cab `  
     `trac_ver.txt`
   * For MacOS:   
     `TRAC.pkg`  
     `TRAC.pkg.signature`  
     `trac_ver_osx.txt`
3. Create a hard link for these files:
   * For Windows:   
     `ln $FWDIR/conf/extender/CSHELL/TRAC.cab $CVPNDIR/htdocs/SNX/CSHELL/TRAC.cab`
   * For MacOS:   
     `ln $FWDIR/conf/extender/CSHELL/TRAC.pkg $CVPNDIR/htdocs/SNX/CSHELL/TRAC.pkg`  
     `ln $FWDIR/conf/extender/CSHELL/TRAC.pkg.signature $CVPNDIR/htdocs/SNX/CSHELL/TRAC.pkg.signature`
4. Copy the version number file from $FWDIR/conf/extender/CSHELL to $CVPNDIR/htdocs/SNX/CSHELL/
   * For Windows:  
     `cp $FWDIR/conf/extender/CSHELL/trac_ver.txt $CVPNDIR/htdocs/SNX/CSHELL/trac_ver.txt`
   * For MacOS:  
     `cp $FWDIR/conf/extender/CSHELL/trac_ver_osx.txt $CVPNDIR/htdocs/SNX/CSHELL/trac_ver_osx.txt`
5. Give the files the required permissions.
   * For Windows:  
     *`chmod 755 $FWDIR/conf/extender/CSHELL/TRAC.cab`
     `chmod 755 $FWDIR/conf/extender/CSHELL/trac_ver.txt`* *`chmod o+x $FWDIR/conf/extender/CSHELL/.`* *`chmod 755 $CVPNDIR/htdocs/SNX/CSHELL/TRAC.cab`
     `chmod 755 $CVPNDIR/htdocs/SNX/CSHELL/trac_ver.txt`*
   * For MacOS:  
     `chmod 775 $FWDIR/conf/extender/CSHELL/TRAC.pkg`  
     `chmod 775 $FWDIR/conf/extender/CSHELL/TRAC.pkg.signature`  
     `chmod 775 $FWDIR/conf/extender/CSHELL/trac_ver_osx.txt`  
     `chmod o+x $FWDIR/conf/extender/CSHELL/.`  
     `chmod 775 $CVPNDIR/htdocs/SNX/CSHELL/TRAC.pkg`  
     `chmod 775 $CVPNDIR/htdocs/SNX/CSHELL/TRAC.pkg.signature`  
     `chmod 775 $CVPNDIR/htdocs/SNX/CSHELL/trac_ver_osx.txt`
6. Restart cvpnd:*`cvpnrestart`*

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
