> Source: [sk97444](https://support.checkpoint.com/results/sk/sk97444)

# sk97444 - Applications that use IPv4-mapped to IPv6, are not supported with SNX in Application Mode

| Property | Value |
|----------|-------|
| Solution ID | sk97444 |
| Date Created | 2013-12-04 |
| Last Modified | 2017-05-17 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |
| OS | Windows |
| Platform | Intel/PC |

## Symptoms

- * Applications under SNX in Application Mode fail to reach encryption domain.

* Applications under SNX in Application Mode reach encryption domain, but directly and not through the SSL tunnel.

## Cause

SNX in Application Mode does not support IPv6 and does not support IPv4-mapped to IPv6.

## Solution

No fix is required; the system is functioning as designed.

Since **[R77.20](http://supportcontent.checkpoint.com/solutions?id=sk101208)**, by default, IPv6 connections and IPv4-mapped to IPv6 connections will go directly to destination and not through the SSL tunnel, even if it is destination in the encryption domain.

In order to enhance the security, SNX user can change the default behaviour for such connections to be dropped.

In Windows Registry, set the decimal value of the following DWORD 32 key to **11**:

**HKEY_CURRENT_USER\\Software\\Checkpoint\\SSL Network Extender\\parameters\\DropIpv6**

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
