156-215.80 · Question #178
You are running the Security Gateway on SecurePlatform and configure SNX with default settings. The client fails to connect to the Security Gateway. What is wrong?
The correct answer is D. The SecurePlatform Web User Interface is listening on port 44(3). SNX requires port 443 for its SSL VPN connection, but SecurePlatform's Web UI also listens on port 443 by default, causing a conflict that prevents client connections.
Question
You are running the Security Gateway on SecurePlatform and configure SNX with default settings. The client fails to connect to the Security Gateway. What is wrong?
Options
- AThe routing table on the client does not get modified.
- BThe client has Active-X blocked.
- CThe client is configured incorrectly.
- DThe SecurePlatform Web User Interface is listening on port 44(3)
How the community answered
(28 responses)- A4% (1)
- B7% (2)
- C4% (1)
- D86% (24)
Why each option
SNX requires port 443 for its SSL VPN connection, but SecurePlatform's Web UI also listens on port 443 by default, causing a conflict that prevents client connections.
SNX modifies the client routing table automatically upon a successful connection; routing table modification failure is a post-connection symptom, not a cause of initial connection failure.
SNX uses Java or a native client for VPN functionality and does not depend on ActiveX, so blocking ActiveX would not prevent SNX from connecting.
The question specifies default settings are used, so client misconfiguration is ruled out as the cause - the issue is a server-side port conflict.
SecurePlatform's built-in Web User Interface listens on TCP port 443 by default, which is the same port that SNX requires for its HTTPS-based SSL VPN tunnel. This port conflict prevents the SNX client from establishing a connection to the Security Gateway. To resolve this, the WebUI port must be changed or disabled so that SNX can exclusively use port 443.
Concept tested: SNX SSL VPN port conflict with SecurePlatform WebUI
Source: https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk65210
Topics
Community Discussion
No community discussion yet for this question.