> Source: [sk97882](https://support.checkpoint.com/results/sk/sk97882)

# sk97882 - "Unauthorized SSL VPN traffic" when SNX users are getting routes to resources that are not allowed to them

| Property | Value |
|----------|-------|
| Solution ID | sk97882 |
| Date Created | 2014-01-06 |
| Last Modified | 2018-03-01 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |

## Symptoms

- * When the SNX client is connected, the routing table changes to include routes via the gateway to:  
  * In Mobile Access/Connectra: all authorized locations in all the native applications defined in SmartDashboard, even to those the user is not allowed to access according to the MAB policy.
  * In IPSec SNX - the whole encryption domain of the gateway, even to resources the user is not allowed to access according to the firewall policy.

  * In the Mobile Access case, if the user initiates traffic to an IP that is routed to the gateway, but not allowed to that user, the traffic will be dropped on the Mobile Access equivalent of the clean-up rule - "Unauthorized SSL VPN traffic" in Smart View Tracker.  
  * This can sometimes cause connectivity issues for the SNX client. For example:  
    * If the client's local network has the same IP range as one of the configured native application, the client will not have connectivity to its LAN while connected to SNX.
    * If a native application was configured to allow one user group to work in hub mode (all traffic routed to the gateway), then all clients will be working in hub mode, but then users that are not included in the user group will not have access to the internet while connected.
    .

## Cause

This is the default behavior by design.

## Solution

If there is a need to limit the SNX-added routes to only include specific IP ranges for a specific user group - follow the procedure described in [sk32111](http://supportcontent.checkpoint.com/solutions?id=sk32111).

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
