<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Troubleshooting Mobile Access SSL VPN in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Troubleshooting-Mobile-Access-SSL-VPN/m-p/235852#M4106</link>
    <description>&lt;P&gt;This SK article is now available again:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk31636" target="_blank" rel="noopener"&gt;https://support.checkpoint.com/results/sk/sk31636&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 16 Dec 2024 12:37:01 GMT</pubDate>
    <dc:creator>Sergei_Shir</dc:creator>
    <dc:date>2024-12-16T12:37:01Z</dc:date>
    <item>
      <title>Troubleshooting Mobile Access SSL VPN</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Troubleshooting-Mobile-Access-SSL-VPN/m-p/204516#M4103</link>
      <description>&lt;P&gt;Hi all!&lt;/P&gt;&lt;P&gt;I'm having a difficult time finding appropriate troubleshooting resources for SSL VPN connectivity our clients are having when connecting via their browser on the Mobile Access Blade, configured via SmartDashboard.&lt;/P&gt;&lt;P&gt;The issues is: mostly external but sometimes internal workers on Windows, Mac or Linux are having issues fetching their access policies, i.e. there's no packet logged indicating what resources they should have access to, which normally appears there.&lt;/P&gt;&lt;P&gt;I've checked:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;their AD group membership&lt;/LI&gt;&lt;LI&gt;the SNX version&lt;/LI&gt;&lt;LI&gt;the Java version&lt;/LI&gt;&lt;LI&gt;they get connected on the web portal fine&lt;/LI&gt;&lt;LI&gt;the web browser version&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;BR /&gt;How do I even "debug" this, can conventional methods be used, such as "tcpdump, zdebug + drop, fw monitor, vpn debug" be used?&lt;/P&gt;&lt;P&gt;Also, which file logs the SSL VPN user activity - vpnd.elg? Couldn't find anything in that file for the specific users in question...&lt;/P&gt;&lt;P&gt;Any advise would be much appreciated regarding this beast.&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jan 2024 09:30:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Troubleshooting-Mobile-Access-SSL-VPN/m-p/204516#M4103</guid>
      <dc:creator>T0r_Lak</dc:creator>
      <dc:date>2024-01-30T09:30:32Z</dc:date>
    </item>
    <item>
      <title>Re: Troubleshooting Mobile Access SSL VPN</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Troubleshooting-Mobile-Access-SSL-VPN/m-p/204525#M4104</link>
      <description>&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_MobileAccess_AdminGuide/Content/Topics-MABG/Troubleshooting.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_MobileAccess_AdminGuide/Content/Topics-MABG/Troubleshooting.htm&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk104577" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk104577&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jan 2024 11:10:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Troubleshooting-Mobile-Access-SSL-VPN/m-p/204525#M4104</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2024-01-30T11:10:50Z</dc:date>
    </item>
    <item>
      <title>Re: Troubleshooting Mobile Access SSL VPN</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Troubleshooting-Mobile-Access-SSL-VPN/m-p/204551#M4105</link>
      <description>&lt;P&gt;sk104577 provided some very useful insights and more advanced troubleshooting methods, as opposed what I already knew.&lt;/P&gt;&lt;P&gt;Thank you so much for your reply! Much appreciated!&lt;/P&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;FYI - Unfortunately when trying to access:&amp;nbsp;&lt;/P&gt;&lt;P&gt;Mobile Access R81.20 Administration Guide &amp;gt;&amp;nbsp;Troubleshooting Mobile Access &amp;gt; Troubleshooting Web Connectivity &amp;gt;&amp;nbsp;&amp;nbsp;"see sk31636", it leads to yet another "Deleted This SK no longer exists".&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jan 2024 13:13:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Troubleshooting-Mobile-Access-SSL-VPN/m-p/204551#M4105</guid>
      <dc:creator>T0r_Lak</dc:creator>
      <dc:date>2024-01-30T13:13:36Z</dc:date>
    </item>
    <item>
      <title>Re: Troubleshooting Mobile Access SSL VPN</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Troubleshooting-Mobile-Access-SSL-VPN/m-p/235852#M4106</link>
      <description>&lt;P&gt;This SK article is now available again:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk31636" target="_blank" rel="noopener"&gt;https://support.checkpoint.com/results/sk/sk31636&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 16 Dec 2024 12:37:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Troubleshooting-Mobile-Access-SSL-VPN/m-p/235852#M4106</guid>
      <dc:creator>Sergei_Shir</dc:creator>
      <dc:date>2024-12-16T12:37:01Z</dc:date>
    </item>
    <item>
      <title>Re: Troubleshooting Mobile Access SSL VPN</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Troubleshooting-Mobile-Access-SSL-VPN/m-p/235974#M4107</link>
      <description>&lt;P&gt;You can give my post a Kudo if it prooved usefull to you &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Dec 2024 09:45:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Troubleshooting-Mobile-Access-SSL-VPN/m-p/235974#M4107</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2024-12-17T09:45:10Z</dc:date>
    </item>
    <item>
      <title>Re: Troubleshooting Mobile Access SSL VPN</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Troubleshooting-Mobile-Access-SSL-VPN/m-p/236577#M4108</link>
      <description>&lt;P&gt;To debug Mobile Access SSL VPN issues in Check Point, you can follow these steps:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;FONT color="#00CCFF"&gt;Debugging the Gateway Side:&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;httpd Process&lt;/STRONG&gt;:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Backup the current configuration file:&lt;BR /&gt;[Expert@HostName:0]# cp -v $CVPNDIR/conf/httpd.conf $CVPNDIR/conf/httpd.conf_ORIGINAL&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Edit the configuration to change the log level:&lt;BR /&gt;[Expert@HostName:0]# vi $CVPNDIR/conf/httpd.conf&lt;/LI&gt;
&lt;LI&gt;Change "LogLevel" from "emerg" to "debug".&lt;/LI&gt;
&lt;LI&gt;Enable trace log collection for a specific user:&lt;BR /&gt;[Expert@HostName:0]# cvpnd_admin debug trace users=&amp;lt;USERNAME&amp;gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;cvpnd Process&lt;/STRONG&gt;:&lt;/P&gt;
1) Start the debug:
&lt;DIV class="co-chatbot-code-copy-btn" style="fill: #656d76;"&gt;[Expert@HostName:0]# cvpnd_admin debug set TDERROR_ALL_ALL=5&lt;/DIV&gt;
2) Stop the debug:&lt;BR /&gt;[Expert@HostName:0]# cvpnd_admin debug off&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;vpnd Process&lt;/STRONG&gt;:&lt;/P&gt;
1) Start the debug for SNX or other clients:
&lt;DIV class="co-chatbot-code-copy-btn" style="fill: #656d76;"&gt;[Expert@HostName:0]# vpn debug on ALL_ALL=5&lt;/DIV&gt;
2) Stop the debug:
&lt;DIV class="co-chatbot-code-copy-btn" style="fill: #656d76;"&gt;[Expert@HostName:0]# vpn debug off&lt;/DIV&gt;
&lt;BR /&gt;
&lt;UL&gt;
&lt;LI style="list-style-type: none;"&gt;&amp;nbsp;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;Check SSL Handshake&lt;/STRONG&gt;:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Use Wireshark to verify SSL handshake by looking for "client_hello" and "server_hello" messages.&lt;/LI&gt;
&lt;LI&gt;If there are SSL issues, collect kernel debug:
&lt;DIV class="co-chatbot-code-copy-btn" style="fill: #656d76;"&gt;[Expert@HostName:0]# fw ctl zdebug -m fw + drop crypt cptls&lt;/DIV&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;Verify SSLVPN Portal&lt;/STRONG&gt;:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Ensure the SSLVPN portal is running:
&lt;DIV class="co-chatbot-code-copy-btn" style="fill: #656d76;"&gt;[Expert@HostName:0]# mpclient status sslvpn&lt;/DIV&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;Log Analysis&lt;/STRONG&gt;:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Check the logs for errors:
&lt;UL&gt;
&lt;LI&gt;$CVPNDIR/log/httpd.log&lt;/LI&gt;
&lt;LI&gt;$CVPNDIR/log/cvpnd.elg&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;Additional Resources for more detailed procedures:&lt;BR /&gt;- &lt;A href="https://support.checkpoint.com/results/sk/sk104577" target="_blank" rel="noopener"&gt;ATRG: Mobile Access Blade&lt;/A&gt; &lt;BR /&gt;- &lt;A href="https://support.checkpoint.com/results/sk/sk99053" target="_blank" rel="noopener"&gt;How to Debug Mobile Access Web Applications&lt;/A&gt;.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 21 Dec 2024 19:58:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Troubleshooting-Mobile-Access-SSL-VPN/m-p/236577#M4108</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2024-12-21T19:58:37Z</dc:date>
    </item>
  </channel>
</rss>

