Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
andreew
Participant

Disable SNX in Spark appliances

Hello, mates!

I'm facing a odd situation with centrally managed SMB appliances. I would like to stop the redirect to SSL Network Extender when trying to access https://<gateway-external-ip>:10443, where 10443 is the port for my vpn remote clients (mobile and endpoint security).  Im using Smart1 Cloud and R82.0.10 software.

I already unhecked SNX under VPN Clients, but Im still being redirectioned to its page.

Once i had the same problem with enterprise appliances and it turned to be that "Allow older clients to connect to this gateway" under VPN Clients>Authentication was checked. This time, I didn't checked it from the start.

 

Does anyone faced the same issue with spark appliances before?

0 Kudos
10 Replies
Lesley
MVP Platinum
MVP Platinum

Page shows I think because you have Check Point Mobile feature enabled. Can you try to disable this one and try again?

-------
Please press "Accept as Solution" if my post solved it 🙂
andreew
Participant

Hello Lesley!

Do you mean the mobile access checkbox in the General Properties tab of the gateway?

0 Kudos
Lesley
MVP Platinum
MVP Platinum

Under vpn clients on the first screenshot you shared

-------
Please press "Accept as Solution" if my post solved it 🙂
0 Kudos
andreew
Participant

I disabled it, but the portal stiils there
I think that this one refers to the client installed with the second option presented when running the MSI installer, isnt it?

0 Kudos
Lesley
MVP Platinum
MVP Platinum

You have screenshot to make sure it is really snx? Policy push really works on this unit? cpstat fw

-------
Please press "Accept as Solution" if my post solved it 🙂
0 Kudos
andreew
Participant

Im attaching some screenshots. After running delete ssl-network-extender, the portal goes away until the firewall download the binaries again

I pushed policy successfully 9 minutes ago

0 Kudos
PhoneBoy
Admin
Admin

The command "delete ssl-network-extender" doesn't actually disable the SNX portal, so that's not a shock.
In any case, you might have to consult TAC on this one.

0 Kudos
andreew
Participant

Hello!
Yeah, that makes sense. Its kinda odd, maybe deactivating it is not supported. Tac may helps

0 Kudos
Tom_Hinoue
Advisor
Advisor

I don't have this issue with combination of Centrally Managed Spark (R81.10.17 B4901) and Smart-1 (R81.20).
The SNX portal is inaccessible with similar settings to what I see in your screenshot. So maybe it's an issue with R82.

Btw, did you check sk184344 - SSL Network Extender Portal is accessible externally although it was disabled ?
I'm not sure about SM1C, but if the SM1C is above JHF Take 19, then this issue should be resolved at least for Management side.

If not, maybe we also need a fix in R82.00.XX firmware (Gateway side), which I recommend you to open a TAC case.

andreew
Participant

Hello!
I think Smart-1 is always updated with the last recommended jhf. I didnt find this information for 82.10, but we already have take 24 so take 19 should the last recommended
In any case, it seems to be a tac case in the end

Thank you for the SK, i didnt see it before

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events