<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SNX on linux in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SNX-on-linux/m-p/125454#M8240</link>
    <description>&lt;P&gt;Form the gateway side error "SNX connection failed".&lt;/P&gt;</description>
    <pubDate>Mon, 02 Aug 2021 11:50:12 GMT</pubDate>
    <dc:creator>Mishgek</dc:creator>
    <dc:date>2021-08-02T11:50:12Z</dc:date>
    <item>
      <title>SNX on linux</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SNX-on-linux/m-p/125313#M8238</link>
      <description>&lt;P&gt;Hello guys! I have a problem with connection through SSL Extender on linux machine.&lt;/P&gt;&lt;P&gt;We have two gateways v.80.30, lets name it io.corp.com and sa.corp.com.&lt;/P&gt;&lt;P&gt;Client: CentOS 7.9, java-11-openjdk and all prerequisites from sk119772. SNX&amp;nbsp; build 800010003.&lt;/P&gt;&lt;P&gt;SSL Extender with io.corp.com working just fine. With first connections window with certificate fingerprint pops up, we accept it and connection is established. When we try to connect to sa.corp.com. SSL Extender window closing without any error. I found error in /var/log/cshell/cshell.log. Could it be that the root of a problem is server certificate with asterisk *?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;30/07/2021 10:09:47 INFO [global] (Log log) [SNXNetMode] Could not connect to SNX Network Mode, probably not installed.&lt;BR /&gt;30/07/2021 10:09:47 INFO [global] (Log log) [Launcher] Launching /usr/bin/snx -Z&lt;BR /&gt;30/07/2021 10:09:48 INFO [CpComponent] (CpComponent initPipe) Trying to create socket to 127.0.0.1:7776&lt;BR /&gt;30/07/2021 10:09:48 INFO [global] (Log log) [SNXNetMode] Successfully connected to SNX Network Mode.&lt;BR /&gt;30/07/2021 10:09:48 INFO [global] (Log log) [SNXNetMode] Connection to SNX Network Mode is ok&lt;BR /&gt;30/07/2021 10:09:48 INFO [CpComponent] (CpComponent connect) Connecting...&lt;BR /&gt;30/07/2021 10:09:48 INFO [global] (Log log) [Proxy] detectProxy, name = sa.corp.ru&lt;BR /&gt;30/07/2021 10:09:48 INFO [global] (Log log) [Proxy] detectProxy, proxyFullPath = /tmp/.proxy.ini&lt;BR /&gt;30/07/2021 10:09:48 INFO [global] (Log log) [Proxy] URI = &lt;A href="https://sa.corp.ru" target="_blank" rel="noopener"&gt;https://sa.corp.ru&lt;/A&gt;&lt;BR /&gt;30/07/2021 10:09:48 INFO [global] (Log log) [Proxy] about to get the system-wide proxy selector...&lt;BR /&gt;30/07/2021 10:09:48 INFO [global] (Log log) [Proxy] about select proxy list from the selector...&lt;BR /&gt;30/07/2021 10:09:48 INFO [global] (Log log) [Proxy] about iterate the proxy list...&lt;BR /&gt;30/07/2021 10:09:48 INFO [global] (Log log) [Proxy] about iterate the proxy #0...&lt;BR /&gt;30/07/2021 10:09:48 INFO [global] (Log log) [Proxy] about to get address from proxy...&lt;BR /&gt;30/07/2021 10:09:48 INFO [global] (Log log) [Proxy] no proxy - continue&lt;BR /&gt;30/07/2021 10:09:48 INFO [global] (Log log) [Proxy] done with the list - there is no proxy&lt;BR /&gt;30/07/2021 10:09:48 INFO [global] (Log log) [Messaging] Sending INIT_DATA message:&lt;BR /&gt;30/07/2021 10:09:48 INFO [global] (Log log) [Messaging] Gateway IP: 95.113.123.212&lt;BR /&gt;30/07/2021 10:09:48 INFO [global] (Log log) [Messaging] Gateway name: sa.corp.ru&lt;BR /&gt;30/07/2021 10:09:48 INFO [global] (Log log) [Messaging] Gateway port: 443&lt;BR /&gt;30/07/2021 10:09:48 INFO [global] (Log log) [Messaging] Proxy IP: 0.0.0.0&lt;BR /&gt;30/07/2021 10:09:48 INFO [global] (Log log) [Messaging] Proxy port: 0&lt;BR /&gt;30/07/2021 10:09:48 INFO [global] (Log log) [Messaging] Server CN: &lt;FONT color="#FF0000"&gt;*.corp.ru&lt;/FONT&gt;&lt;BR /&gt;30/07/2021 10:09:48 INFO [global] (Log log) [Messaging] User Name: USER&lt;BR /&gt;30/07/2021 10:09:48 INFO [global] (Log log) [Messaging] Server fingerprint: SAGE LAKE DAME HARD TIDY BROW DEL SEEK IKE GLEE CRUD ION&lt;BR /&gt;30/07/2021 10:09:48 INFO [global] (Log log) [Messaging] Automatic proxy replacement: true&lt;BR /&gt;30/07/2021 10:09:48 INFO [global] (Log log) [Messaging] Sending INIT_DATA_EX message:&lt;BR /&gt;30/07/2021 10:09:48 INFO [global] (Log log) [Messaging] Allow only packets from sws: false&lt;BR /&gt;30/07/2021 10:09:48 INFO [global] (Log log) [CShell] Initialized successfully&lt;BR /&gt;30/07/2021 10:09:49 INFO [CShellHTTPHandler] (CShellHTTPHandler proceedHandleRequest) Method name: get_is_connected&lt;BR /&gt;30/07/2021 10:09:49 INFO [CShellHTTPHandler] (CShellHTTPHandler proceedHandleRequest) Method name: get_finished&lt;BR /&gt;30/07/2021 10:09:49 INFO [global] (Log log) [Messaging] Received DISCONNECTED message, Error 32: Cannot establish connection to SSL Network Extender gateway. Try to reconnect.&lt;BR /&gt;30/07/2021 10:09:49 INFO [CpComponent] (CpComponent run) Received 'Disconnect' message from SNX:&lt;BR /&gt;ID: 32 MSG:Cannot establish connection to SSL Network Extender gateway. Try to reconnect.&lt;BR /&gt;30/07/2021 10:09:49 WARNING [TunnelChecker] (TunnelChecker disconnectTunnel) Can't disconnect tunnel, client director is not defined.&lt;BR /&gt;30/07/2021 10:09:49 WARNING [TunnelChecker] (TunnelChecker stop) Can't stop disconnect checker, processed handle is not defined.&lt;BR /&gt;30/07/2021 10:09:50 INFO [CShellHTTPHandler] (CShellHTTPHandler proceedHandleRequest) Method name: Uninitialize&lt;BR /&gt;30/07/2021 10:09:50 WARNING [TunnelChecker] (TunnelChecker disconnectTunnel) Can't disconnect tunnel, client director is not defined.&lt;BR /&gt;30/07/2021 10:09:50 WARNING [TunnelChecker] (TunnelChecker stop) Can't stop disconnect checker, processed handle is not defined.&lt;BR /&gt;30/07/2021 10:09:50 INFO [CShellHTTPHandler] (CShellHTTPHandler proceedHandleRequest) Method name: stop&lt;BR /&gt;30/07/2021 10:09:50 WARNING [TunnelChecker] (TunnelChecker disconnectTunnel) Can't disconnect tunnel, client director is not defined.&lt;BR /&gt;30/07/2021 10:09:50 WARNING [TunnelChecker] (TunnelChecker stop) Can't stop disconnect checker, processed handle is not defined.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Aug 2021 06:13:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SNX-on-linux/m-p/125313#M8238</guid>
      <dc:creator>Mishgek</dc:creator>
      <dc:date>2021-08-03T06:13:47Z</dc:date>
    </item>
    <item>
      <title>Re: SNX on linux</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SNX-on-linux/m-p/125408#M8239</link>
      <description>&lt;P&gt;What's the error message from the gateway side of things?&lt;/P&gt;</description>
      <pubDate>Mon, 02 Aug 2021 00:48:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SNX-on-linux/m-p/125408#M8239</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-08-02T00:48:59Z</dc:date>
    </item>
    <item>
      <title>Re: SNX on linux</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SNX-on-linux/m-p/125454#M8240</link>
      <description>&lt;P&gt;Form the gateway side error "SNX connection failed".&lt;/P&gt;</description>
      <pubDate>Mon, 02 Aug 2021 11:50:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SNX-on-linux/m-p/125454#M8240</guid>
      <dc:creator>Mishgek</dc:creator>
      <dc:date>2021-08-02T11:50:12Z</dc:date>
    </item>
    <item>
      <title>Re: SNX on linux</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SNX-on-linux/m-p/125508#M8241</link>
      <description>&lt;P&gt;Where precisely are you seeing that error message?&lt;BR /&gt;I believe you can get more information on the client side by using the -g option when invoking SNX.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 02 Aug 2021 20:22:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SNX-on-linux/m-p/125508#M8241</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-08-02T20:22:07Z</dc:date>
    </item>
    <item>
      <title>Re: SNX on linux</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SNX-on-linux/m-p/125515#M8242</link>
      <description>&lt;P&gt;Let me discuss this with one of my colleagues, see what he says about it, as I believe he made it work for one of our customers. Though based on errors you gave, I really agree with your logic that it could be certificate issue.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Aug 2021 00:37:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SNX-on-linux/m-p/125515#M8242</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-08-03T00:37:48Z</dc:date>
    </item>
    <item>
      <title>Re: SNX on linux</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SNX-on-linux/m-p/125546#M8243</link>
      <description>&lt;P&gt;I will find out about error from gateway administrator. There is logs from SNX when I invoking connection with gateways by doing command "snx -s sa.corp.ru -u user -g" and "snx -s io.corp.ru -u user -g". We dont use SNX to connect through CLI. I thought it was not supported any more? I am using Firefox 78 web browser on CentOS with java-11-openjdk (i tried 8,11,16 ande jre 8). We have Windows clients with IE which going throught sa.cotp.ru without problems.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Aug 2021 06:12:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SNX-on-linux/m-p/125546#M8243</guid>
      <dc:creator>Mishgek</dc:creator>
      <dc:date>2021-08-03T06:12:53Z</dc:date>
    </item>
    <item>
      <title>Re: SNX on linux</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SNX-on-linux/m-p/126213#M8244</link>
      <description>&lt;P&gt;Could it be that this hotfix &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk113410" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk113410&lt;/A&gt; not installed on the gateway? How to confirm it?&lt;/P&gt;</description>
      <pubDate>Tue, 10 Aug 2021 12:43:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SNX-on-linux/m-p/126213#M8244</guid>
      <dc:creator>Mishgek</dc:creator>
      <dc:date>2021-08-10T12:43:57Z</dc:date>
    </item>
    <item>
      <title>Re: SNX on linux</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SNX-on-linux/m-p/126273#M8245</link>
      <description>&lt;P&gt;If you can use it from a Windows machine with Chrome (versus Internet Explorer), then the hotfix is installed.&lt;BR /&gt;Otherwise, it's not.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Aug 2021 18:02:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SNX-on-linux/m-p/126273#M8245</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-08-10T18:02:09Z</dc:date>
    </item>
  </channel>
</rss>

