Identity Agent for a User Endpoint Computer - Downloading

It is recommended for end users to download the latest Identity Agents. Here are download links:

An administrator of an Identity AwarenessClosed Software Blade on a Check Point Firewall that enforces network access and audits data based on network location, the identity of the user, and the identity of the computer. Acronym: IDA. Gateway can make Identity AgentClosed Check Point dedicated client agent installed on Windows-based user endpoint computers. This Identity Agent acquires and reports identities to the Check Point Firewall with Identity Awareness enabled. The administrator configures the Identity Agents (not the end users). There are two types of Identity Agents - Full and Light. You can download the Full and Light Identity Agent package from the Captive Portal - 'https://<Gateway_IP_Address>/connect' or from Support Center. available for end users to download from the Identity Awareness Captive PortalClosed A Check Point Identity Awareness web portal, to which users connect with their web browser to log in and authenticate, when using Browser-Based Authentication.. This table shows relevant differences between Identity Awareness Gateway versions:

Version of Identity Awareness Gateway

Is the Identity Agent download file pre-installed on the Identity Awareness Gateway?

Details

R82 and lower

Yes

The version of the Identity Agent that end users download from the Identity Awareness Captive Portal is current to the General Availability release date of the Identity Awareness Gateway. This version is not updated automatically. To update the version of Identity Agent that users download, see To upload Identity Agent to the Identity Awareness Gateway so that end users can download it from the Identity Awareness Captive Portal:.

R82.10 and higher

No

To install the download file on the Identity Awareness Gateway, or to update the version of Identity Agent that users download, see To upload Identity Agent to the Identity Awareness Gateway so that end users can download it from the Identity Awareness Captive Portal:.

To upload Identity Agent to the Identity Awareness Gateway so that end users can download it from the Identity Awareness Captive Portal:

  1. Download the new version of Identity Agent to your computer:

  2. On the CLI of the Identity Awareness Gateway, make sure that this directory exists (if it does not exist, then create it):

    /opt/CPNacPortal/htdocs/nac/nacclients

  3. Copy the downloaded Identity Agent from your computer to the Identity Awareness Gateway to the directory:

    /opt/CPNacPortal/htdocs/nac/nacclients

  4. Connect to the command line of the Identity Awareness Gateway.

  5. Log in to the Expert mode.

  6. To make sure the file has permissions configured to allow end users to download it, run one of these commands on the Identity Awareness Gateway:

    • For Identity Agent Full:

      chmod -v 644 /opt/CPNacPortal/htdocs/nac/nacclients/fullAgent.exe

    • For Identity Agent Light:

      chmod -v 644 /opt/CPNacPortal/htdocs/nac/nacclients/lightAgent.exe

  7. Make sure that users are required to download the same type of Identity Agent that you downloaded to the Security Gateway.

    For example, if you downloaded the Full Identity Agent package, then:

    1. Connect with SmartConsoleClosed Check Point GUI application used to manage a Check Point environment - configure Security Policies, configure devices, monitor products and events, install updates, and so on. to the Security Management ServerClosed Dedicated Check Point server that runs Check Point software to manage the objects and policies in a Check Point environment within a single management Domain. Synonym: Single-Domain Security Management Server. / Domain Management ServerClosed Check Point Single-Domain Security Management Server or a Multi-Domain Security Management Server. that manages the Identity Awareness Gateway.

    2. From the left navigation panel, click Gateways & Servers.

    3. Double-click the Identity Awareness Gateway object.

    4. From the left tree, click the Identity Awareness page.

    5. Select Browser-Based Authentication and click Settings.

      The Portal Settings window opens.

    6. In the Captive Portal Settings window, below Identity Agent Deployment from the Portal, select Require users to download to make users install the Identity Agent.

      Make sure the selected type of Identity Agent matches the type of Identity Agent you downloaded to the Security Gateway:

      • Identity Agent - Full

      • Identity Agent - Custom

      • Identity Agent - Light

    7. Optional: To give users flexibility to choose when they install the Identity Client, select Users may defer installation until and select the latest date before users must install the Identity Client to continue to connect to the Identity Awareness Gateway. Until the selected date, the user sees a Skip Identity Client installation option in the Captive Portal.

    8. If you selected a new kind of Identity Agent or made changes to Users may defer installation until:

      1. Click OK to close the Security Gateway object.

      2. Install the Access Control Policy.

To require end users to download Identity Agent from the Identity Awareness Captive Portal:

  1. Connect with SmartConsole to the Management Server that manages the Identity Awareness Gateway.

  2. From the left navigation panel, click Gateways & Servers.

  3. Double-click the Identity Awareness Gateway object.

  4. From the left, click the Identity Awareness page.

  5. Enable the Browser-Based Authentication and click Settings.

  6. In the section Identity Agent Deployment from the Portal:

    1. Select Require users to download.

    2. Select the required Identity Agent type.

  7. Click OK to close the Security Gateway object.

  8. Install the Access Control Policy on the Identity Awareness Gateway.