<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SSL Network Extender Legacy policy in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SSL-Network-Extender-Legacy-policy/m-p/20481#M12779</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yup, the user record has an authentication method defined in it.&lt;/P&gt;&lt;P&gt;That must be set correctly.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 03 Jan 2019 18:02:55 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2019-01-03T18:02:55Z</dc:date>
    <item>
      <title>SSL Network Extender Legacy policy</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SSL-Network-Extender-Legacy-policy/m-p/20476#M12774</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ssl‌&amp;nbsp;ssl‌&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am trying to configure Mobile Access to establish VPN over SSL; the purpose is that the user that connects through the browser (SSL Network extender) have access to the entire internal network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;At the moment it worked for me only publishing a native application (RDP) but I need it to works as the "Checkpoint Mobile Client", without publishing applications.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;By the way, we are on R80, and I think we can only use "Legacy Policy" I mentioned this because if I use "Unified Access Policy" using R80.10 and R80.20 it works.&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" height="244" src="https://community.checkpoint.com/legacyfs/online/checkpoint/76661_pastedImage_1.png" width="427" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried this mode without success:&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-2 jive-image" height="269" src="https://community.checkpoint.com/legacyfs/online/checkpoint/76662_pastedImage_2.png" width="409" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any clue please?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Jan 2019 00:55:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SSL-Network-Extender-Legacy-policy/m-p/20476#M12774</guid>
      <dc:creator>Alejandro_Espin</dc:creator>
      <dc:date>2019-01-03T00:55:20Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Network Extender Legacy policy</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SSL-Network-Extender-Legacy-policy/m-p/20477#M12775</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Mobile Access Blade does not need to be enabled at all if you just want to use SNX as a VPN client.&lt;/P&gt;&lt;P&gt;You would configure it as if it were IPSec VPN (e.g. make sure the relevant gateway is part of the Remote Access Community and there is a rule permitting access via this community)&lt;/P&gt;&lt;P&gt;Make sure that SNX is enabled here:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/76665_pastedImage_1.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And that Visitor Mode is enabled:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-2 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/76666_pastedImage_2.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;See also the docs: &lt;A href="https://sc1.checkpoint.com/documents/R80.10/WebAdminGuides/EN/CP_R80.10_RemoteAccessVPN_AdminGuide/14702.htm"&gt;SSL Network Extender&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Jan 2019 01:43:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SSL-Network-Extender-Legacy-policy/m-p/20477#M12775</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-01-03T01:43:39Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Network Extender Legacy policy</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SSL-Network-Extender-Legacy-policy/m-p/20478#M12776</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you so much Dameon, it works! using a local user.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a different issue, I can't log in using RADIUS authentication when I try to connect to VPN with SSL Network Extender. with Checkpoint Mobile client it works fine using RADIUS you think we need to set something else?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Jan 2019 03:22:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SSL-Network-Extender-Legacy-policy/m-p/20478#M12776</guid>
      <dc:creator>Alejandro_Espin</dc:creator>
      <dc:date>2019-01-03T03:22:39Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Network Extender Legacy policy</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SSL-Network-Extender-Legacy-policy/m-p/20479#M12777</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Error messages?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Jan 2019 04:22:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SSL-Network-Extender-Legacy-policy/m-p/20479#M12777</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-01-03T04:22:04Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Network Extender Legacy policy</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SSL-Network-Extender-Legacy-policy/m-p/20480#M12778</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Nevermind, I created the user indicating that it will be authenticated by radius and it works&amp;nbsp;properly. Thank you Dameon.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Jan 2019 17:28:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SSL-Network-Extender-Legacy-policy/m-p/20480#M12778</guid>
      <dc:creator>Alejandro_Espin</dc:creator>
      <dc:date>2019-01-03T17:28:18Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Network Extender Legacy policy</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SSL-Network-Extender-Legacy-policy/m-p/20481#M12779</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yup, the user record has an authentication method defined in it.&lt;/P&gt;&lt;P&gt;That must be set correctly.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Jan 2019 18:02:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SSL-Network-Extender-Legacy-policy/m-p/20481#M12779</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-01-03T18:02:55Z</dc:date>
    </item>
  </channel>
</rss>

