Identity Agent for a User Endpoint Computer - Downloading
It is recommended for end users to download the latest Identity Agents. Here are download links:
-
Identity Agent for Windows (contains all flavors for Windows OS in a single package (Full, Light, v1 and v2 for Terminal Server)
An administrator of an Identity Awareness
Software Blade on a Check Point Firewall that enforces network access and audits data based on network location, the identity of the user, and the identity of the computer. Acronym: IDA. Gateway can make Identity Agent
Check Point dedicated client agent installed on Windows-based user endpoint computers. This Identity Agent acquires and reports identities to the Check Point Firewall with Identity Awareness enabled. The administrator configures the Identity Agents (not the end users). There are two types of Identity Agents - Full and Light. You can download the Full and Light Identity Agent package from the Captive Portal - 'https://<Gateway_IP_Address>/connect' or from Support Center. available for end users to download from the Identity Awareness Captive Portal
A Check Point Identity Awareness web portal, to which users connect with their web browser to log in and authenticate, when using Browser-Based Authentication.. This table shows relevant differences between Identity Awareness Gateway versions:
|
Version of Identity Awareness Gateway |
Is the Identity Agent download file pre-installed on the Identity Awareness Gateway? |
Details |
|---|---|---|
|
R82 and lower |
Yes |
The version of the Identity Agent that end users download from the Identity Awareness Captive Portal is current to the General Availability release date of the Identity Awareness Gateway. This version is not updated automatically. To update the version of Identity Agent that users download, see To upload Identity Agent to the Identity Awareness Gateway so that end users can download it from the Identity Awareness Captive Portal:. |
|
R82.10 and higher |
No |
To install the download file on the Identity Awareness Gateway, or to update the version of Identity Agent that users download, see To upload Identity Agent to the Identity Awareness Gateway so that end users can download it from the Identity Awareness Captive Portal:. |
To upload Identity Agent to the Identity Awareness Gateway so that end users can download it from the Identity Awareness Captive Portal:
-
Download the new version of Identity Agent to your computer:
-
Identity Agent for Windows (contains all flavors for Windows OS in a single package (Full, Light, v1 and v2 for Terminal Server)
-
-
On the CLI of the Identity Awareness Gateway, make sure that this directory exists (if it does not exist, then create it):
/opt/CPNacPortal/htdocs/nac/nacclients -
Copy the downloaded Identity Agent from your computer to the Identity Awareness Gateway to the directory:
/opt/CPNacPortal/htdocs/nac/nacclients -
Connect to the command line of the Identity Awareness Gateway.
-
Log in to the Expert mode.
-
To make sure the file has permissions configured to allow end users to download it, run one of these commands on the Identity Awareness Gateway:
-
For Identity Agent Full:
chmod -v 644 /opt/CPNacPortal/htdocs/nac/nacclients/fullAgent.exe -
For Identity Agent Light:
chmod -v 644 /opt/CPNacPortal/htdocs/nac/nacclients/lightAgent.exe
-
-
Make sure that users are required to download the same type of Identity Agent that you downloaded to the Security Gateway.
For example, if you downloaded the Full Identity Agent package, then:
-
Connect with SmartConsole
Check Point GUI application used to manage a Check Point environment - configure Security Policies, configure devices, monitor products and events, install updates, and so on. to the Security Management Server
Dedicated Check Point server that runs Check Point software to manage the objects and policies in a Check Point environment within a single management Domain. Synonym: Single-Domain Security Management Server. / Domain Management Server
Check Point Single-Domain Security Management Server or a Multi-Domain Security Management Server. that manages the Identity Awareness Gateway. -
From the left navigation panel, click Gateways & Servers.
-
Double-click the Identity Awareness Gateway object.
-
From the left tree, click the Identity Awareness page.
-
Select Browser-Based Authentication and click Settings.
The Portal Settings window opens.
-
In the Captive Portal Settings window, below Identity Agent Deployment from the Portal, select Require users to download to make users install the Identity Agent.
Make sure the selected type of Identity Agent matches the type of Identity Agent you downloaded to the Security Gateway:
-
Identity Agent - Full
-
Identity Agent - Custom
-
Identity Agent - Light
-
-
Optional: To give users flexibility to choose when they install the Identity Client, select Users may defer installation until and select the latest date before users must install the Identity Client to continue to connect to the Identity Awareness Gateway. Until the selected date, the user sees a Skip Identity Client installation option in the Captive Portal.
-
If you selected a new kind of Identity Agent or made changes to Users may defer installation until:
-
Click OK to close the Security Gateway object.
-
Install the Access Control Policy.
-
-
To require end users to download Identity Agent from the Identity Awareness Captive Portal:
-
Connect with SmartConsole to the Management Server that manages the Identity Awareness Gateway.
-
From the left navigation panel, click Gateways & Servers.
-
Double-click the Identity Awareness Gateway object.
-
From the left, click the Identity Awareness page.
-
Enable the Browser-Based Authentication and click Settings.
-
In the section Identity Agent Deployment from the Portal:
-
Select Require users to download.
-
Select the required Identity Agent type.
-
Identity Agent - Light
-
Identity Agent - Full
-
Identity Agent - Custom
This is a custom configuration created in the Identity Agent Configuration Utility
Check Point utility that creates custom Identity Agent installation packages. This utility is installed as a part of the Identity Agent: go to the Windows Start menu > All Programs > Check Point > Identity Agent > open the 'Identity Agent' shortcut > select 'Properties' > click 'Open File Location' ('Find Target' in some Windows versions > double-click 'IAConfigTool.exe')..For more information, see Creating Custom Identity Clients
-
-
-
Click OK to close the Security Gateway object.
-
Install the Access Control Policy on the Identity Awareness Gateway.