> Source: [sk181805](https://support.checkpoint.com/results/sk/sk181805)

# sk181805 - SSL Network Extender (SNX) cannot connect after installing Jumbo Hotfix Accumulator

| Property | Value |
|----------|-------|
| Solution ID | sk181805 |
| Date Created | 2023-12-15 |
| Last Modified | 2024-09-24 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R81.20, R81.10 (EOS), R81 (EOS) |
| OS | Gaia |

## Symptoms

- * SSL Network Extender (SNX) cannot connect (the connect button is not working) after installing a Jumbo Hotfix Accumulator on the Security Gateway.

* SNX fails to connect to the Security Gateway after logging into Mobile Access Portal when the IP address of the Mobile Access Portal (as resolved by the organization DNS from the Mobile Access Portal's FQDN) differs from the IP address of the Security Gateway object in SmartConsole.

## Cause

The SSL Network Extender (SNX) behavior was changed in these Jumbo Hotfix Accumulators:  

* R81.20 Jumbo Hotfix Accumulator Take 41
* R81.10 Jumbo Hotfix Accumulator Take 128
* R81 Jumbo Hotfix Accumulator Take 89
* R80.40 Jumbo Hotfix Accumulator Take 205

<br />

SNX used to connect back to Mobile Access Portal FQDN by resolving its IP address locally. This method makes it sensitive to DNS poisoning attacks, such as those specified by TunnelCrack. Therefore, SNX was modified to connect back to the Security Gateway's / Cluster Member's IP address by default, instead of connecting to the IP address from the DNS resolving of the Mobile Access Portal FQDN.

## Solution

Behavior Change (PMTR-95099):

This problem was fixed. The fix is included in:

* [Jumbo Hotfix Accumulator for R81.20](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.20/Default.htm) starting from Take 70
* [Jumbo Hotfix Accumulator for R81.10](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.10/Default.htm) starting from Take 152
* [Jumbo Hotfix Accumulator for R81](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81/Default.htm) starting from Take 99

If you choose not to upgrade, Check Point can supply a **Hotfix** . [Contact Check Point Support](https://www.checkpoint.com/support-services/contact-support/) to get a Hotfix for this issue.  
A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.  
For faster resolution and verification, please collect [CPinfo files](http://supportcontent.checkpoint.com/solutions?id=sk92739) from the Security Management Server and Security Gateways involved in the case.

**Hotfix installation instructions:**   
Refer to [sk168597 - How to install a Hotfix](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk168597).  

<br />

Customers who used the workaround need to revert it. Please contact TAC to assist with the procedure.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
