UserCheck Objects and Clients for DLP
Creating UserCheck Interaction Objects
Create a UserCheck Interaction object from the Rule Base or from the page of the DLP tab. The procedure below shows how to create the object from the Rule Base in SmartDashboard.
Note - You can only edit DLP UserCheck objects in SmartDashboard. You cannot create or edit them in R80 SmartConsole.
To create a UserCheck object that includes a message:
- In R80 SmartConsole, select > and click .
SmartDashboard opens and shows the tab.
- From the navigation tree, click .
The column uses these interaction modes:
- - Show an informative message users. Users can continue to the application or cancel the request.
- - Show a message to users that asks them if they want to continue with the request or not. To continue with the request, the user is expected to supply a reason.
- - Show a message to users and block the application request.
- Right-click the cell for the rule and select the interaction mode > .
You can also double-click an existing interaction mode to edit it.
The window opens on the page.
- Enter a name for the UserCheck object and, optionally, a comment.
- Select a language (English is the default) from the Languages tabs.
- Click to add a graphic, such as company logo.
Note - The graphic must have a height and width of 176 x 52 pixels.
- Click the text box adjacent to the picture and enter title text for the message.
- In the page title, message subject, and message body text boxes, enter the message content. You can:
- Use the formatting toolbar to change text color, alignment, add or remove bullets.
- variables for:
- Username
- Original URL
- Source IP
- Incident ID
- Violation protocol
- Email subject / File name
- Matched Rules Notifications
Variables are replaced with applicable values when the (Prevent, Ask, Inform) action occurs and the message shows. The Username can only be displayed if the Identity Awareness blade is enabled.
- Use the variable to add a:
- - Users select a checkbox to continue
- - Users can enter an explanation for their activity or other text according to the instructions. Edit the default text in the Textual Input box based on your business needs.
- - Users can click a link to report that an incorrect category was included in the message. Use this field with the variable.
- Optional: Click to see the results in your default browser.
- Click .
- Click and then close SmartDashboard.
- From R80 SmartConsole, install the policy.
Configuring the Security Gateway for UserCheck
Enable or disable UserCheck directly on the Security Gateway. If users connect to the gateway remotely, set the internal interface of the gateway (on the page) to be the same as the for the UserCheck portal.
Note - The field must be manually updated if:
- The field uses an IP address and not a DNS name
- You change the IPv4 address of the gateway to IPv6 or the opposite
To configure a Security Gateway for UserCheck:
- In R80 SmartConsole, click and double-click the Security Gateway.
The gateway window opens and shows the page.
- From the navigation tree, click .
- Click .
- In the field, select the primary URL for the web portal that shows the UserCheck notifications.
- If the points to an external interface:
- In the section, click .
- In the window, click the applicable setting:
- Click .
- If necessary, click to add URL aliases that redirect different hostnames to the .
For example: Usercheck.mycompany.com The aliases must resolve to the portal's IP address on the corporate DNS server.
- In the area, click to import a certificate that the portal uses to authenticate to the server.
- In the area, click to configure interfaces on the gateway through which the portal can be accessed. These options are based on the topology configured for the gateway. Users are sent to the UserCheck portal if they connect:
- . Select this option if there is a rule that states who can access the portal.
- (default)
Note - If is selected, add a Firewall rule that looks like this:
Source
|
Destination
|
VPN
|
Service
|
Action
|
Any
|
Gateway on which UserCheck client is enabled
|
Any Traffic
|
UserCheck
|
Accept
|
- In the area, select .
- Click .
- Publish the changes and install policy.
Configuring R80 SmartConsole for DLP SSO
Configure the object in R80 SmartConsole for an LDAP Account Unit to support SSO.
To create a host object for the AD server:
- In R80 SmartConsole, click > (Ctrl+E).
- Click >.
- Configure the settings for the host.
- Click and publish the changes.
To configure the LDAP account unit:
- From the Object Explorer, click > > .
- In the tab of the window, enter these settings:
- Enter the .
- In , select .
- In the Domain field, enter the domain name.
We recommended that you configure this field for existing account units that you want to use for Identity Awareness. This setting does not affect other LDAP Account Units.
- Select and .
- Click .
- In the window, configure these settings:
- Select .
- Enter the .
- Enter the and for the AD account.
- Do not change the default settings for .
- Click .
- Configure these settings in the tab:
- Click .
- In , select the host object for the AD server.
- Enter the of the user (added in the AD) for LDAP operations.
- Enter the and confirm it.
- In the section, make sure that is selected.
- Click the tab, and configure these settings:
- Click .
- Click .
- Click .
Note - LDAP over SSL is not supported by default. If you have not configured your domain controller to support LDAP over SSL, either skip step 6 or configure your domain controller to support LDAP over SSL.
- Click the tab, and configure these settings:
- In the , select the host object for the AD server
- Click to configure the branches in use.
- Set the number of entries supported.
- Click the tab, and configure these settings:
- In the section, click .
- Select .
- Click and publish the changes.
Localizing and Customizing the UserCheck Portal
After you set the UserCheck interaction object language, you can translate the Portal OK and Cancel buttons to the applicable language. For more information, see: sk83700.
The DLP UserCheck predefined notifications are in only English by default. If necessary, you can add more languages manually.
To support more languages for UserCheck:
- In R80 SmartConsole, select >> and click .
SmartDashboard opens and shows the tab.
- From the navigation tree, click .
- Select a UserCheck interaction object and click .
- In the pane, click .
- From the list, select the applicable language.
- Click .
A tab for the language is added.
- Enter the necessary text and click .
UserCheck Client Overview
The UserCheck client is installed on endpoint computers to communicate with the gateway and show UserCheck interaction notifications to users. It works with these Software Blades:
- Notifications of DLP incidents can be sent by email (for SMTP traffic) or shown in a popup from the UserCheck client in the system tray (for SMTP, HTTP and FTP).
- UserCheck client adds the option to send notifications for applications that are not in a web browser, such as Skype, iTunes, or browser add-ons (such as radio toolbars). The UserCheck client can also work together with the UserCheck portal to show notifications on the computer itself when:
- The notification cannot be displayed in a browser, or
- The UserCheck engine determines that the notification will not be shown correctly in the browser.
Users select an option in the notification message to respond in real-time.
For DLP, administrators with full permissions or the View/Release/Discard DLP messages permission can also send or discard incidents from the R80 SmartConsole view tab.
Workflow for installing and configuring UserCheck clients:
- Configure how the clients communicate with the gateway and create trust with it.
- Enable UserCheck and the UserCheck client on the gateway.
- Download the UserCheck client MSI file.
- Install the UserCheck client on the endpoint computers.
- Make sure that the UserCheck clients can connect to the gateway and receive notifications.
Enabling UserCheck Client
Enable UserCheck and the UserCheck client on the gateway in the Properties window of the gateway object in R80 SmartConsole. This is necessary to let clients communicate with the gateway.
To enable UserCheck and the UserCheck client on the gateway:
- In R80 SmartConsole, click and double-click the Security Gateway.
The gateway window opens and shows the page.
- From the navigation tree, click .
- Select .
This enables UserCheck notifications from the gateway.
- In the UserCheck Client section, select .
This enables UserCheck notifications from the client.
- Click and publish the changes.
- Install the policy on the gateway.
Getting the MSI File
To get the MSI file:
- In R80 SmartConsole, in the view, open the window of the gateway object.
- From the navigation tree, select
- In the t section, click .

|
Important - Before you can download the client msi file, the UserCheck portal must be up. The portal is up only after a Policy installation.
|
UserCheck and Check Point Password Authentication
You can see and edit Check Point users from Users and Administrators in the navigation tree.
To enable Check Point password authentication:
R80 SmartConsole Configuration
- Open R80 SmartConsole and open the view.
- Click > , and select an existing user or create a new user.
- In the page of the user, make sure that an email address is defined.
- In the page of the user, set to and enter the password and password confirmation.
- Click .
UserCheck Client Configuration
Ask your users to configure their UserCheck client:
- On the UserCheck client computer, right click the UserCheck icon in the Notification Area (next to the system clock).
- Select .
- Click .
- Select .