Linux

checkpoint ssl/vpn connection in linux operating system

A short technical note summarizing the basic approach and applicable steps for Checkpoint SSL/VPN connection in Linux operating system.

Step 1: Installation of the following packages and additionally installation of updated Oracle JRE (Source)

Step 2: Let’s install the SNX file shared from the checkpoint web panel.

Linux Supported Platforms

Latest
Linux
Distribution
32-bit Prerequisites64-bit PrerequisitesInstallation command
Ubuntu
 14.04
 16.04
 16.10
 17.04
libpam0g:i386
libx11-6:i386
libst dc++6:i386
libstdc++5:i386
libpam0g:i386
libx11-6:i386
libstdc++6:i386
libstdc++5:i386
libnss3-tools (certutil) 
Apt-get
openSUSE 11.4libstdc++33
  1. pam-32bit
  2. libstdc++33 32bit
  3. Install all dependencies required by pam and libstdc++33 packages.
openSuSE 12.2compat-libstdc++
  1. pam-32bit
  2. pam-modules-32bit
  3. compat-libstdc++.i586
Fedora 15
  1. xterm.i686
  2. libXaw.so.7
  3. libstdc++.so.5
  1. Xterm.86_64 (with libXaw.86_64 dependency)
  2. libX11.i686
  3. pam-devel.i686 (which contains: libaudit.so.1, libcrack.so.2, lindb-4.8.so, libselinux.so.1, libpam.so.0)
  4. libstdc++.so.5
Fedora 16/18</span>
  1. xterm.i686
  2. libstdc++.so.5
  1. xterm.x86_64 (with libXaw.86_64 dependency)</span>
  2. elf_utils-libelf.i686</span>
  3. libX11.i686
  4. libaudit.so.1
  5. libc rack.so.2
  6. libdb-5.3.so
  7. libselinux.so.1
  8. libpam.so.0
  9. libstdc++.so.5
For Mobile Access Portal Agent: (also)
  1. 10. libXext.i686
  2. libXrender.i686
  3. libXtst.i686
  4. libXi.i686
dnf install <lib_name> 
RHEL 7.3 / 7.4NoneSame as Fedora 16 64-bityum-config-manager --enable rhel-7-server-optional-rpms
yum install
RHEL 6.1Same as 
Fedora 
(16 32-bit)
Same as Fedora 16 64-bit

Step 3: Connection can be made via Linux terminal as follows. (Source)

Note: If you get an authentication error, you can try different versions of snx as described here (Source 2)

CheckPointVPN_SNX_Linux_800007075.sh

SSL Network Extender Command Attributes

<tdForce a specific encryption algorithm. Valid values - RC4 and 3DES.</td>
AttributesDescription
snx -f <configuration file>Run SSL Network Extender using parameters defined in a configuration file other than the default name or location.
snx -dDisconnect from Mobile Access
snx -s <server>Specify server IP or hostname
snx -u <username>Specify a valid user
snx -c <certificate file>Specify which certificate is used to authenticate.
snx -l <CA directory>Define the directory where CA's certificates are stored.
snx -p <port>Change the HTTPS port. (default port is TCP 443).
snx -gEnable debugging. snx.elg log file is created.
snx -e <cipher>