nerdexam
Check_Point

156-215.80 · Question #178

You are running the Security Gateway on SecurePlatform and configure SNX with default settings. The client fails to connect to the Security Gateway. What is wrong?

The correct answer is D. The SecurePlatform Web User Interface is listening on port 44(3). SNX requires port 443 for its SSL VPN connection, but SecurePlatform's Web UI also listens on port 443 by default, causing a conflict that prevents client connections.

VPN Solutions

Question

You are running the Security Gateway on SecurePlatform and configure SNX with default settings. The client fails to connect to the Security Gateway. What is wrong?

Options

  • AThe routing table on the client does not get modified.
  • BThe client has Active-X blocked.
  • CThe client is configured incorrectly.
  • DThe SecurePlatform Web User Interface is listening on port 44(3)

How the community answered

(28 responses)
  • A
    4% (1)
  • B
    7% (2)
  • C
    4% (1)
  • D
    86% (24)

Why each option

SNX requires port 443 for its SSL VPN connection, but SecurePlatform's Web UI also listens on port 443 by default, causing a conflict that prevents client connections.

AThe routing table on the client does not get modified.

SNX modifies the client routing table automatically upon a successful connection; routing table modification failure is a post-connection symptom, not a cause of initial connection failure.

BThe client has Active-X blocked.

SNX uses Java or a native client for VPN functionality and does not depend on ActiveX, so blocking ActiveX would not prevent SNX from connecting.

CThe client is configured incorrectly.

The question specifies default settings are used, so client misconfiguration is ruled out as the cause - the issue is a server-side port conflict.

DThe SecurePlatform Web User Interface is listening on port 44(3)Correct

SecurePlatform's built-in Web User Interface listens on TCP port 443 by default, which is the same port that SNX requires for its HTTPS-based SSL VPN tunnel. This port conflict prevents the SNX client from establishing a connection to the Security Gateway. To resolve this, the WebUI port must be changed or disabled so that SNX can exclusively use port 443.

Concept tested: SNX SSL VPN port conflict with SecurePlatform WebUI

Source: https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk65210

Topics

#SNX#SSL Network Extender#port 443 conflict#SecurePlatform WebUI

Community Discussion

No community discussion yet for this question.

Full 156-215.80 Practice