> Source: [sk184150](https://support.checkpoint.com/results/sk/sk184150)

# sk184150 - SNX CLI client on Linux cannot access resources when using Access Roles

| Property | Value |
|----------|-------|
| Solution ID | sk184150 |
| Date Created | 2025-10-10 |
| Last Modified | 2025-10-23 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R81.20 |

## Symptoms

- * The SSL Network Extender (SNX) CLI client on Linux connects successfully but cannot access internal resources.

* SmartConsole logs show that the cleanup rule drops traffic from the user's Office Mode IP instead of matching it to the Access Role rule. Other users using the same Access Role who connect with Endpoint Security VPN client do not experience this issue.

* The Dead Peer Detection (DPD) Monitor IP shows that no role is assigned to the user. To confirm this, run the `pdp monitor` command.

## Cause

The Access Role object is configured to allow only specific VPN client types, and the SNX client is not included.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
