Is there a Linux client for Checkpoint VPN? Preferably for Ubuntu?
7 Answers
I've heard good things about Shrew, but I've only ever seen it used on Windows.
I'm using SNX (by checkpoint) and it works perfect. It can be downloaded from here.
I used this guide in order to install snx on my client, check it out and see if you got all the required packages installed.
In addition, you can create a .snxrc file in your /home/user/ directory and include there the server's IP and username like so:
server 1.1.1.1 username itaig Then just run snx, you'll be asked to input your password and that's it.
- 2I just get "SNX: Authentication failed" after I supply the certificate's password. Do I have to authenticate with the Windows client once before it will work, or something?Robin Green– Robin Green2014-08-11 17:58:19 +00:00Commented Aug 11, 2014 at 17:58
- @RobinGreen, I've updated my answer, check it out.Itai Ganot– Itai Ganot2014-08-11 18:06:30 +00:00Commented Aug 11, 2014 at 18:06
- Any idea how SNX would handle 2 factor authentication? I can't seem to get it to work.Rob Audenaerde– Rob Audenaerde2016-08-23 07:36:37 +00:00Commented Aug 23, 2016 at 7:36
- It's complicated to configure and I haven't done it myself but I know it's doableItai Ganot– Itai Ganot2016-08-23 09:20:55 +00:00Commented Aug 23, 2016 at 9:20
- It is no longer supported on linux if ou disable RC4 and 3DES on the firewall :(Rob Audenaerde– Rob Audenaerde2017-07-12 13:03:24 +00:00Commented Jul 12, 2017 at 13:03
The existing client is ancient, and as for now AFAIK, there are no plans to write a newer one. There are Linux native VPN clients that should work with checkpoint - check out vpnc and raccoon especially.
http://www.vpnc.org/InteropProfiles/checkpoint-profile.pdf
http://www.fw-1.de/aerasec/ng/vpn-racoon/CP-VPN1-NG-Linux-racoon.html
I have successfully connected to Checkpoint (NGX R75) using Shrew Soft, more info here: https://serverfault.com/a/386021/73387
I'm assuming your looking for an IPSEC client, but if you are looking for SSL VPN, I have had good luck with the Checkpoint SNX client in Ubuntu.
- 1Unfortunately this now redirects to their mobile blade site.frankster– frankster2012-11-14 16:19:11 +00:00Commented Nov 14, 2012 at 16:19
- And no longer works with modern ciphersRob Audenaerde– Rob Audenaerde2017-07-12 13:05:09 +00:00Commented Jul 12, 2017 at 13:05
I also was looking for it AND I've found a checkpoint client VPN on the Checkpoint Users Forums, I'll link it to you tomorrow.
OK Here is the link to the Documentation under RedHat:
BUT, the Linux client VPN seems to be deprecated and no longer supported, as my own experience, it should be better to use the OpenSwan VPN to connect throught an Checkpoint VPN gateway under linux.
- Link is broken by now as well...Maarten Bodewes– Maarten Bodewes2021-05-31 14:31:02 +00:00Commented May 31, 2021 at 14:31
IPSEC pure clients only work if the firewall admin has configured the functionality. In a corporate setting, usually they dont, as Windows and Macs have specific client software.
From 2021 onwards, SNX on the command line is unfortunately not supported anymore.
You can connect via the mobile web portal upon installing SNX and the Java agent.
Or use my automatic setup script https://github.com/ruyrybeyro/chrootvpn
See https://unix.stackexchange.com/questions/450131/vpn-ssl-network-extender-in-firefox/709258 too, for more details.