> Source: [sk185260](https://support.checkpoint.com/results/sk/sk185260)

# sk185260 - SNX Native App Traffic Matches Incorrect MAB (Legacy) Policy after Upgrading to latest JHF (158,118,36)

| Property | Value |
|----------|-------|
| Solution ID | sk185260 |
| Date Created | 2026-08-11 |
| Last Modified | 2026-08-25 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |
| OS | Windows |

## Symptoms

- * After upgrading to the latest JHF of R81.20, R82 and R82.10, Mobile Access (SNX) traffic allowed by Native Application rules is dropped by the **MAB Rules** layer cleanup rule.  
* After the connection, the users do not have access to internal resources - the traffic hits the cleanup rule instead of the dedicated rule
* The log shows:   
  `Unauthorized SSL VPN traffic`.
* The rules worked fine on previous versions.
* The issue affects rules that use specific service definitions (for example, TCP/80 or TCP/443). Rules configured with **Any** service are not affected.
*
  * Affected versions:

    [R81.20 Jumbo Hotfix Accumulator](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.20/R81.20/Introduction.htm) Take 158  
    [R82 Jumbo Hotfix Accumulator](https://sc1.checkpoint.com/documents/Jumbo_HFA/R82/R82.00/Introduction.htm) Take 118  
    [R82.10 Jumbo Hotfix Accumulator](https://sc1.checkpoint.com/documents/Jumbo_HFA/R82.10/R82.10/Introduction.htm) Take 36

## Cause

A software condition introduced in R81.20 Jumbo Hotfix Accumulator Take 158 affects policy installation for certain Mobile Access rules.  
When multiple Mobile Access rules use the same service definition, the gateway creates an internal rule-matching object and reuse it. Under this condition, some rules that reuse the same service definition are not compiled correctly. As a result, those rules do not match traffic, and the traffic continues to the MAB Rules cleanup rule where it is dropped.  
The issue is related to the JHF take and is not caused by a configuration problem.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
