Configuring the Client Package
Due to security considerations, users must approve the fingerprint and certificate DN for all primary Security Gateways in the site. Therefore, clients must connect interactively at least once for each gateway that becomes primary. With this release, a secondary gateway can become primary automatically.
To configure the package for ATMs:
-
Install non-ATM Endpoint Security VPN on a client machine.
-
Create a site.
For each Security Gateway on the site, users have to connect and approve the fingerprint.
Note - The last connected Security Gateway will be defined as the primary gateway in the generated package deployment.
-
Go to
c:\program files\checkpoint\endpoint
and runAdminMode.bat
. -
Go to VPN Options > Administration tab.
-
In the Input MSI Package path field, enter the path name of CheckPointEndpointSecurityForATM.msi.
-
Select Replace user's configuration when upgrading.
-
In Select a product, select Endpoint Security VPN.
-
Click Generate.
-
Save the MSI to the local disk.
-
Enable No Office Mode on the MSI:
-
At the Windows command prompt,
go to c:\program files\checkpoint\endpoint
. -
Run this command:
cpmsi_tool.exe CheckPointEndpointSecurityForATM.msi
-NO_OFFICE_MODE
1
-