> Source: [sk170775](https://support.checkpoint.com/results/sk/sk170775)

# sk170775 - How to use SNX with SAML authentication method in Mobile Access

| Property | Value |
|----------|-------|
| Solution ID | sk170775 |
| Date Created | 2020-12-01 |
| Last Modified | 2021-09-29 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R81 (EOS) |

## Symptoms

- * When the user configures the SAML (Identity Provider) authentication method for the Mobile Access Blade (MAB) in a Legacy Policy according to the Identity Awareness Administration Guide R80.40 (and higher), SSL Network Extender traffic is dropped due to "`Unauthorized SSL VPN traffic`" even though the generic external user profile and user groups are configured correctly.

* The same issue occurs in the Unified Policy.
  When Access Roles are configured with correct identity tags, users continue to not hit the rule using SNX. 
  On the other hand, other services like Web Applications, File Shares, and Citrix Services work and match the applicable rule.

## Solution

**For Legacy Policy:**   

SSL Network Extender is not supported with the SAML authentication procedure in Mobile Access with Legacy Policy mode.  

If you need SSL Network Extender, switch to Unified Policy instead and do the instructions in the [Identity Awareness Administration Guide](https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_IdentityAwareness_AdminGuide/Default.htm) for SAML authentication in MAB Unified Policy mode.

![](https://sc1.checkpoint.com/sc/SolutionsStatics/NEW_SK_NOID1606823512523/bbb202012011404271.jpg)  

<br />

**For Unified Policy:**This problem was fixed. The fix is included in:

* [Jumbo Hotfix Accumulator for R81](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk170114) starting from Take 42
* [Jumbo Hotfix Accumulator for R80.40](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk165456) starting from Take 114

Check Point recommends to always upgrade to the most recent version ([Mobile Access / SSL VPN](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doShowproductpage&product=72)).

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
