- Products
- Learn
- Local User Groups
- Partners
- More
What's New in Check Point SASE
Wednesday, 9 September @ 5pm CET / 11am EDT
The State of Ransomware Q2 2026:
This Quarter's Trends, and Their Impact on Your Defenses
AI Security Masters
Implementing the AI Security Trifecta
CheckMates Go:
Half is Not Enough
As you know new versions of SNX client is distributed within Jumbo Hotfix Accumulator. But we faced with problem when after hotfix installation on SSL Network Extender Portal (https://Gateway_IP_or_Name/CSHELL/snx_install.sh) remains old version but command
cat $CVPNDIR/htdocs/SNX/CSHELL/snx_ver.txt
from SNX Versions shows that we have new version
We have made some research and found that new version of SNX is placed in $CVPNDIR/htdocs/SNX/INSTALL/ but file which is downloaded from SSL Network Extender Portal is placed in $FWDIR/conf/extender/CSHELL
So if you want to have newest clien on your portal you shoul replace file snx_install.sh in $FWDIR/conf/extender/CSHELL by file from $CVPNDIR/htdocs/SNX/INSTALL/
As you know new versions of SNX client is distributed within Jumbo Hotfix Accumulator. But we faced with problem when after hotfix installation on SSL Network Extender Portal (https://Gateway_IP_or_Name/CSHELL/snx_install.sh) remains old version but command
cat $CVPNDIR/htdocs/SNX/CSHELL/snx_ver.txt
from SNX Versions shows that we have new version
We have made some research and found that new version of SNX is placed in $CVPNDIR/htdocs/SNX/INSTALL/ but file which is downloaded from SSL Network Extender Portal is placed in $FWDIR/conf/extender/CSHELL
So if you want to have newest clien on your portal you shoul replace file snx_install.sh in $FWDIR/conf/extender/CSHELL by file from $CVPNDIR/htdocs/SNX/INSTALL/
As you know new versions of SNX client is distributed within Jumbo Hotfix Accumulator. But we faced with problem when after hotfix installation on SSL Network Extender Portal (https://Gateway_IP_or_Name/CSHELL/snx_install.sh) remains old version but command
cat $CVPNDIR/htdocs/SNX/CSHELL/snx_ver.txt
from SNX Versions shows that we have new version
We have made some research and found that new version of SNX is placed in $CVPNDIR/htdocs/SNX/INSTALL/ but file which is downloaded from SSL Network Extender Portal is placed in $FWDIR/conf/extender/CSHELL
So if you want to have newest clien on your portal you shoul replace file snx_install.sh in $FWDIR/conf/extender/CSHELL by file from $CVPNDIR/htdocs/SNX/INSTALL/
Are you talking about the legacy SNX portal here?
Not sure that's even officially supported anymore.
The functionality of auto-launching SNX hasn't worked for years since it relies on Internet Explorer, which isn't even supported any longer.
Are you talking about the legacy SNX portal here?
Not sure that's even officially supported anymore.
The functionality of auto-launching SNX hasn't worked for years since it relies on Internet Explorer, which isn't even supported any longer.
Yes, I am talking about SNX portal. We have just tried to find the way how to deliver newer version of SNX client to our users without involving our support. Users can download actual version by themself.
Yes, I am talking about SNX portal. We have just tried to find the way how to deliver newer version of SNX client to our users without involving our support. Users can download actual version by themself.
How are users launching SNX on Linux without the MAB portal?
Last I heard, launching SNX from CLI wasn’t supported, but perhaps this changed?
How are users launching SNX on Linux without the MAB portal?
Last I heard, launching SNX from CLI wasn’t supported, but perhaps this changed?
Maybe this indeed works with the legacy SNX portal and not the MAB portal, where there's an SK that says it is not: https://support.checkpoint.com/results/sk/sk180750
In any case, I'll clarify the situation with R&D.
Maybe this indeed works with the legacy SNX portal and not the MAB portal, where there's an SK that says it is not: https://support.checkpoint.com/results/sk/sk180750
In any case, I'll clarify the situation with R&D.
We definitely don't use Mobile Access blade, only Remote Access VPN.
We definitely don't use Mobile Access blade, only Remote Access VPN.
I did check with R&D and it appears this is all expected behavior.
Officially we don’t support the legacy SNX portal any longer, thus why the updated SNX client is not placed there.
You can copy it to the correct location as you did and it should still work.
Further, using the legacy SNX portal appears to be the only way you can launch SNX via the CLI.
(As a parenthetical, SMB appliances use the legacy SNX portal only, which means launching SNX via CLI against an SMB gateway should work)
If Mobile Access Blade is used instead of the legacy SNX portal, then SNX must be launched from there.
Launching SNX via CLI is not supported in this case.
I did check with R&D and it appears this is all expected behavior.
Officially we don’t support the legacy SNX portal any longer, thus why the updated SNX client is not placed there.
You can copy it to the correct location as you did and it should still work.
Further, using the legacy SNX portal appears to be the only way you can launch SNX via the CLI.
(As a parenthetical, SMB appliances use the legacy SNX portal only, which means launching SNX via CLI against an SMB gateway should work)
If Mobile Access Blade is used instead of the legacy SNX portal, then SNX must be launched from there.
Launching SNX via CLI is not supported in this case.