- Products
- Learn
- Local User Groups
- Partners
- More
AI Security Masters E7:
How CPR Broke ChatGPT's Isolation and What It Means for You
Blueprint Architecture for Securing
The AI Factory & AI Data Center
Call For Papers
Your Expertise. Our Stage
Good, Better, Best:
Prioritizing Defenses Against Credential Abuse
Ink Dragon: A Major Nation-State Campaign
Watch HereCheckMates Go:
CheckMates Fest
As you know new versions of SNX client is distributed within Jumbo Hotfix Accumulator. But we faced with problem when after hotfix installation on SSL Network Extender Portal (https://Gateway_IP_or_Name/CSHELL/snx_install.sh) remains old version but command
cat $CVPNDIR/htdocs/SNX/CSHELL/snx_ver.txt
from SNX Versions shows that we have new version
We have made some research and found that new version of SNX is placed in $CVPNDIR/htdocs/SNX/INSTALL/ but file which is downloaded from SSL Network Extender Portal is placed in $FWDIR/conf/extender/CSHELL
So if you want to have newest clien on your portal you shoul replace file snx_install.sh in $FWDIR/conf/extender/CSHELL by file from $CVPNDIR/htdocs/SNX/INSTALL/
I did check with R&D and it appears this is all expected behavior.
Officially we don’t support the legacy SNX portal any longer, thus why the updated SNX client is not placed there.
You can copy it to the correct location as you did and it should still work.
Further, using the legacy SNX portal appears to be the only way you can launch SNX via the CLI.
(As a parenthetical, SMB appliances use the legacy SNX portal only, which means launching SNX via CLI against an SMB gateway should work)
If Mobile Access Blade is used instead of the legacy SNX portal, then SNX must be launched from there.
Launching SNX via CLI is not supported in this case.
Are you talking about the legacy SNX portal here?
Not sure that's even officially supported anymore.
The functionality of auto-launching SNX hasn't worked for years since it relies on Internet Explorer, which isn't even supported any longer.
Yes, I am talking about SNX portal. We have just tried to find the way how to deliver newer version of SNX client to our users without involving our support. Users can download actual version by themself.
How are users launching SNX on Linux without the MAB portal?
Last I heard, launching SNX from CLI wasn’t supported, but perhaps this changed?
Maybe this indeed works with the legacy SNX portal and not the MAB portal, where there's an SK that says it is not: https://support.checkpoint.com/results/sk/sk180750
In any case, I'll clarify the situation with R&D.
We definitely don't use Mobile Access blade, only Remote Access VPN.
I did check with R&D and it appears this is all expected behavior.
Officially we don’t support the legacy SNX portal any longer, thus why the updated SNX client is not placed there.
You can copy it to the correct location as you did and it should still work.
Further, using the legacy SNX portal appears to be the only way you can launch SNX via the CLI.
(As a parenthetical, SMB appliances use the legacy SNX portal only, which means launching SNX via CLI against an SMB gateway should work)
If Mobile Access Blade is used instead of the legacy SNX portal, then SNX must be launched from there.
Launching SNX via CLI is not supported in this case.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 4 | |
| 4 | |
| 3 | |
| 3 | |
| 3 | |
| 2 | |
| 2 | |
| 1 | |
| 1 | |
| 1 |
Tue 28 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Securing your GenAI-enabled Web Applications with Check Point WAFThu 30 Apr 2026 @ 03:00 PM (PDT)
Hillsboro, OR: Securing The AI Transformation and Exposure ManagementTue 28 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Securing your GenAI-enabled Web Applications with Check Point WAFTue 12 May 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: Check Point Cloud Firewall delivered as a serviceThu 30 Apr 2026 @ 03:00 PM (PDT)
Hillsboro, OR: Securing The AI Transformation and Exposure ManagementAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY