<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SSL VPN extender Linux/Mozilla Firefox in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SSL-VPN-extender-Linux-Mozilla-Firefox/m-p/93055#M3942</link>
    <description>&lt;P&gt;Installing SNX via browser is not currently possible on SMB appliances.&lt;BR /&gt;Assuming an RFE would be accepted/delivered on SMB appliances, it would not apply to the 750 as we are only fixing bugs and not adding new features on these appliances.&lt;/P&gt;
&lt;P&gt;However, what you can do is manually install SNX from here:&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk90240" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk90240&lt;/A&gt;&lt;BR /&gt;This will allow you to invoke an SNX connection from the CLI, avoiding the issue with the browser not supporting Java plugins.&lt;BR /&gt;I did a brief test on 1490 and it appears to work.&lt;/P&gt;</description>
    <pubDate>Fri, 31 Jul 2020 21:26:34 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2020-07-31T21:26:34Z</dc:date>
    <item>
      <title>SSL VPN extender Linux/Mozilla Firefox</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SSL-VPN-extender-Linux-Mozilla-Firefox/m-p/92849#M3937</link>
      <description>&lt;DIV class="_3xX726aBn29LDbsDtzr_6E _1Ap4F5maDtT1E1YuCiaO0r D3IL3FD0RFy_mkKLPwL4"&gt;&lt;DIV class="_292iotee39Lmt0MkQZ2hPV RichTextJSON-root"&gt;&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;&lt;FONT color="#000000"&gt;Hi Everyone. Im really struggling to get our checkpoint VPN to work for SLLVPN. I am using Ubuntu so the Checkpoint Client is out of the question (Stupid) ive tried doing the SSL extender option and it works to a point, i receive the Java unavailable error.&lt;/FONT&gt;&lt;/P&gt;&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;&lt;FONT color="#000000"&gt;my problem is im using checkpoint 750. there is apparently a hotfix for mobile access hotfix. my checkpoint is 'up to date' with update R77.20.87 (990173004) but the hotfix only applies to R77.30 i think. is there anyway i could get this working at all? its so frustrating as i need to teamviewer to my Server to access anything intranet. im not the biggest fan of checkpoint. help would be greatly appreciated as i have tried everything, even L2TP.&lt;/FONT&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Thu, 30 Jul 2020 10:59:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SSL-VPN-extender-Linux-Mozilla-Firefox/m-p/92849#M3937</guid>
      <dc:creator>Realming_Grape</dc:creator>
      <dc:date>2020-07-30T10:59:08Z</dc:date>
    </item>
    <item>
      <title>Re: SSL VPN extender Linux/Mozilla Firefox</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SSL-VPN-extender-Linux-Mozilla-Firefox/m-p/92887#M3939</link>
      <description>&lt;P&gt;did you read&amp;nbsp;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk65210&amp;amp;partition=Basic&amp;amp;product=SSL" target="_blank" rel="noopener"&gt;sk65210: SSL Network Extender&lt;/A&gt;&amp;nbsp;?&amp;nbsp;&lt;SPAN&gt;All Linux OSs require &lt;/SPAN&gt;&lt;A href="http://www.oracle.com/technetwork/java/javase/downloads/index.html" target="_blank" rel="noopener"&gt;Oracle JRE&lt;/A&gt;&lt;SPAN&gt; to install.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Use the snx -h command to make sure that the SSL Network Extender client is installed correctly.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The Hotfix is from&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk113410" target="_blank" rel="noopener"&gt;sk113410 - Mobile Access Portal and Java Compatibility - New Mobile Access Portal Agent technology&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Here we read:&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Note for locally and centrally managed SMB appliances [Embedded Gaia]&lt;/STRONG&gt;:&lt;/P&gt;
&lt;P&gt;This feature is not included in the product. If you need it, please submit a&lt;A href="https://www.checkpoint.com/rfe/rfe.htm" target="_blank"&gt; Request for Enhancement&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jul 2020 15:40:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SSL-VPN-extender-Linux-Mozilla-Firefox/m-p/92887#M3939</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2020-07-30T15:40:51Z</dc:date>
    </item>
    <item>
      <title>Re: SSL VPN extender Linux/Mozilla Firefox</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SSL-VPN-extender-Linux-Mozilla-Firefox/m-p/92893#M3938</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/21294"&gt;@G_W_Albrecht&lt;/a&gt;is correct in that the hotfix described in sk113410 is only for firewalls running the Mobile Access Blade.&amp;nbsp; It's an update to the Mobile Access Portal to support extra browsers.&amp;nbsp; The Mobile Access Blade is not supported on SMB firewalls tuning embedded Gaia.&lt;/P&gt;&lt;P&gt;Having said that, I have read a number of CheckPoint documents stating that the SNX client and Remote Access is possible and supported on SMB appliances running Embedded Gaia.&amp;nbsp; One would presume that the SMB appliances have some sort of alternate portal.&lt;/P&gt;&lt;P&gt;What I have not been able to find is any CheckPoint documentation on how to enable Remote Access on an SMB firewall, nor on how to write policy rules to limit access to remote clients.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jul 2020 16:34:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SSL-VPN-extender-Linux-Mozilla-Firefox/m-p/92893#M3938</guid>
      <dc:creator>Dale_Lobb</dc:creator>
      <dc:date>2020-07-30T16:34:24Z</dc:date>
    </item>
    <item>
      <title>Re: SSL VPN extender Linux/Mozilla Firefox</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SSL-VPN-extender-Linux-Mozilla-Firefox/m-p/92897#M3940</link>
      <description>&lt;P&gt;SMB Appliances managed with Smart enter are configured exactly the same way as regular gateways in terms of remote access (I.e. nothing on the device itself).&lt;BR /&gt;For locally managed SMB appliances, the “alternate” portal to download SNX is gateway-IP:444 though I will admit I haven’t tried invoking snx on Linux.&amp;nbsp;&lt;BR /&gt;You can also configure local rules to allow remote users to access specific resources.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jul 2020 17:09:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SSL-VPN-extender-Linux-Mozilla-Firefox/m-p/92897#M3940</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-07-30T17:09:18Z</dc:date>
    </item>
    <item>
      <title>Re: SSL VPN extender Linux/Mozilla Firefox</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SSL-VPN-extender-Linux-Mozilla-Firefox/m-p/92985#M3941</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;Thank you for your response.&lt;/P&gt;&lt;P&gt;i have Java installed but unfortunately most browsers dont support Java anymore so its useless. ive tried with different browsers and i get the same error.&lt;/P&gt;&lt;P&gt;im also new to Linux, as i want to increase my knowledge in the OS. the endpoint works for windows but i just cannot seems to get this going for some reason.&lt;/P&gt;&lt;P&gt;ive tried everything.&lt;/P&gt;&lt;P&gt;does this request for enhancement upgrade my current device?&lt;/P&gt;</description>
      <pubDate>Fri, 31 Jul 2020 08:40:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SSL-VPN-extender-Linux-Mozilla-Firefox/m-p/92985#M3941</guid>
      <dc:creator>Realming_Grape</dc:creator>
      <dc:date>2020-07-31T08:40:23Z</dc:date>
    </item>
    <item>
      <title>Re: SSL VPN extender Linux/Mozilla Firefox</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SSL-VPN-extender-Linux-Mozilla-Firefox/m-p/93055#M3942</link>
      <description>&lt;P&gt;Installing SNX via browser is not currently possible on SMB appliances.&lt;BR /&gt;Assuming an RFE would be accepted/delivered on SMB appliances, it would not apply to the 750 as we are only fixing bugs and not adding new features on these appliances.&lt;/P&gt;
&lt;P&gt;However, what you can do is manually install SNX from here:&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk90240" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk90240&lt;/A&gt;&lt;BR /&gt;This will allow you to invoke an SNX connection from the CLI, avoiding the issue with the browser not supporting Java plugins.&lt;BR /&gt;I did a brief test on 1490 and it appears to work.&lt;/P&gt;</description>
      <pubDate>Fri, 31 Jul 2020 21:26:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SSL-VPN-extender-Linux-Mozilla-Firefox/m-p/93055#M3942</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-07-31T21:26:34Z</dc:date>
    </item>
    <item>
      <title>Re: SSL VPN extender Linux/Mozilla Firefox</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SSL-VPN-extender-Linux-Mozilla-Firefox/m-p/93814#M3992</link>
      <description>&lt;P&gt;Hello everyone. I had headache with SNX too, but after many hours searching and reading I did resolve this problem.&lt;/P&gt;&lt;P&gt;SK's:&amp;nbsp;&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;&lt;FONT face="courier new,courier"&gt;sk43935 Failure to connect with SSL Network Extender via Ubuntu 7 CLI&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;sk114267 How to install SSL Network Extender (SNX) client on Linux machine&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;sk65210 SSL Network Extender&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;sk90240 SNX Installation Package for Linux OS client &lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;My linux host is Linux Mint, which I updated and upgraded to last patches:&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;&lt;FONT face="courier new,courier"&gt;Linux vmLinuxMint 4.15.0-20-generic #21-Ubuntu SMP Tue Apr 24 06:16:15 UTC 2018 x86_64 x86_64 x86_64 GNU/Linux&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;Java coming with such linux flavor, is ...&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;&lt;FONT face="courier new,courier"&gt;openjdk version "10.0.2" 2018-07-17&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;OpenJDK Runtime Environment (build 10.0.2+13-Ubuntu-1ubuntu0.18.04.4)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;OpenJDK 64-Bit Server VM (build 10.0.2+13-Ubuntu-1ubuntu0.18.04.4, mixed mode)&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;With all above installed, I ran:&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;&lt;FONT face="courier new,courier"&gt;&lt;STRONG&gt;prompt&amp;gt;&lt;/STRONG&gt;sudo apt install libpam0g:i386&amp;nbsp; libx11-6:i386 libstdc++6:i386 libstdc++5:i386 libnss3-tools&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;Then I installed SNX, but something rare, snx client that donwloaded from my FW remote access portal don't work for me, so I downloaded snx client from &lt;FONT face="courier new,courier"&gt;sk90240&lt;/FONT&gt;. and made it executable, after that...&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;&lt;FONT face="courier new,courier"&gt;&lt;STRONG&gt;prompt&amp;gt;&lt;/STRONG&gt;sudo sh ./snx_install_linux30.sh&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;and connect to remote FW&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;&lt;FONT face="courier new,courier"&gt;&lt;STRONG&gt;prompt&amp;gt;&lt;/STRONG&gt;snx -s (ip-wan-fw) -u user&lt;/FONT&gt;&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;&lt;FONT face="courier new,courier"&gt;Check Point's Linux SNX&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;build 800010003&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Please enter your password:&lt;/FONT&gt;&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;&lt;FONT face="courier new,courier"&gt;SNX - connected.&lt;/FONT&gt;&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;&lt;FONT face="courier new,courier"&gt;Session parameters:&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;===================&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Office Mode IP : A.B.C.D&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Timeout : 8 hours&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;I&amp;nbsp; hope this work for you.&lt;/P&gt;&lt;P&gt;...&lt;/P&gt;</description>
      <pubDate>Tue, 11 Aug 2020 07:37:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SSL-VPN-extender-Linux-Mozilla-Firefox/m-p/93814#M3992</guid>
      <dc:creator>LuisSP</dc:creator>
      <dc:date>2020-08-11T07:37:00Z</dc:date>
    </item>
    <item>
      <title>Re: SSL VPN extender Linux/Mozilla Firefox</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SSL-VPN-extender-Linux-Mozilla-Firefox/m-p/93866#M3993</link>
      <description>&lt;P&gt;FYI almost all linux vendors have stopped supporting i386. Ubuntu's latest LTS (20.04) doesn't. Checkpoint is going to need to come up with a SNX build for 64bit at some point.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Aug 2020 15:41:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SSL-VPN-extender-Linux-Mozilla-Firefox/m-p/93866#M3993</guid>
      <dc:creator>John_Fleming</dc:creator>
      <dc:date>2020-08-11T15:41:52Z</dc:date>
    </item>
    <item>
      <title>Re: SSL VPN extender Linux/Mozilla Firefox</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SSL-VPN-extender-Linux-Mozilla-Firefox/m-p/93906#M3994</link>
      <description>&lt;P&gt;LuisSP, Thank you, youre amazing&lt;/P&gt;&lt;P&gt;It is finally working. i was doing everything exactly as you were doing except, my firewall was giving me an older version of SNX (800007075)&lt;BR /&gt;going through your clues led me to download the right version and now i can connect. thank you once again.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Aug 2020 09:26:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SSL-VPN-extender-Linux-Mozilla-Firefox/m-p/93906#M3994</guid>
      <dc:creator>Realming_Grape</dc:creator>
      <dc:date>2020-08-12T09:26:23Z</dc:date>
    </item>
    <item>
      <title>Re: SSL VPN extender Linux/Mozilla Firefox</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SSL-VPN-extender-Linux-Mozilla-Firefox/m-p/117357#M5133</link>
      <description>&lt;P&gt;I faced similar issue so thought of sharing the solution as it may help someone else:&lt;/P&gt;&lt;P&gt;At UBUNTU client, install the following prerequisites&amp;nbsp;&lt;/P&gt;&lt;P&gt;sudo apt-get install libstdc++5:i386 libpam0g:i386&lt;/P&gt;&lt;P&gt;It worked for me, Gateway: R80 , client: Ubuntu 16 and Ubuntu 18.&lt;/P&gt;&lt;P&gt;Hope it helps.&lt;/P&gt;</description>
      <pubDate>Fri, 30 Apr 2021 13:27:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SSL-VPN-extender-Linux-Mozilla-Firefox/m-p/117357#M5133</guid>
      <dc:creator>SushilS</dc:creator>
      <dc:date>2021-04-30T13:27:35Z</dc:date>
    </item>
  </channel>
</rss>

