Check Point Endpoint Security Vpn For Macos 10.13
Open ' CheckPoint Endpoint Security VPN '. At the lower right of your screen, click on the arrow to expand your system tray. Double-click on CheckPoint which looks like a yellow padlock. If it's not currently in your 'System Tray', proceed to the next step. ENDPOINT SECURITY WITHOUT COMPROMISE. KEY PRODUCT BENEFITS. Mature endpoint. Endpoint-threat-prevention/ Check Point SandBlast Agent Solution Brief. MacOS Sierra 10.12.6, MacOS High Sierra 10.13.4 (Threat Emulation, Threat Extraction, Anti- Ransomware, Chrome for Mac Browser Extension). In macOS 10.13 and later, the gatekeeper requests consent from the end user before allowing to load a third party kernel extension for the first time. It is possible to avoid this by preparing the installation of Endpoint Security on each machine by deploying a Device Management Kernel Extension Policy Payload containing the Check Point team. According to sk117536, E80.89 client supports macOS Mojave (10.14) and macOS High Sierra (10.13) only. See sk117536 Endpoint Security Homepage for details - here we also can read: We are committed to offer early availability clients within 3 weeks of OS GA and to announce GA within 2 months of OS GA, however in practice we are delivering much.
R80.30 Management Servers can manage Security Gateways of these versions:
Gateway Type | Release Version |
---|---|
Security Gateway | R75.20, R75.30, R75.40, R75.45, R75.46, R75.47, |
VSX | R76, |
Maestro Security Groups | R80.20SP |
R80.30 Management Servers can manage appliance Security Gateways that run these versions:
Appliance | Release Version |
---|---|
Security Gateway 80 | R75.20.x |
1100 Appliances | R75.20.x, R77.20.x |
1200R Appliances | R77.20.x |
1400 Appliances | R77.20.x |
60000/40000 Scalable Platforms | R76SP, R76SP.10, R76SP.20, R76SP.30, R76SP.40, R76SP.50, R80.20SP |
The maximum number of interfaces supported (physical and virtual) is shown in this table.
Check Point Endpoint Security Vpn For Mac Os X 10.13
Mode | Max # of Interfaces | Notes |
---|---|---|
Security Gateway | 1024 | Non-VSX |
VSX Gateway | 4096 | Includes VLANs and Warp Interfaces |
Note - This table applies to Check Point Appliances and Open Servers.
Cluster Type | Maximum Supported Number |
---|---|
ClusterXL | 5 |
Virtual System Load Sharing | 13 |
- A minimum of 2.3G free RAM must be available, regardless of the number of cores or connection used by the Security Gateway.
- Supported with 5000 and higher appliances series.
The Threat Emulation requirements are different based on the emulation location:
- ThreatCloud - Gaia operating system (64 or 32-bit)
- Local or Remote emulation - Threat Emulation Private Cloud Appliance on the Gaia operating system (64-bit only)
Storing Logs
Logs can be stored on:
- A Security Management Server that collects logs from the Security Gateways. This is the default.
- A Log Server on a dedicated machine. This is recommended for organizations that generate many logs.
A dedicated Log Server has greater capacity and performance than a Security Management Server with an activated logging service. On dedicated Log Servers, the Log Server must be the same version as the Management Server.
SmartEvent Requirements
You can enable the SmartEvent Blade on a Security Management Server, or install a dedicated SmartEvent Server. SmartEvent R80.30 can connect to a different version of Log Server - R77.xx or lower.
SmartEvent and a SmartEvent Correlation Unit are usually installed on the same server. You can also install them on separate servers, for example, to balance the load in large logging environments. The SmartEvent Correlation Unit must be the same version as SmartEvent Server.
To deploy SmartEvent and to generate reports, a valid license or contract is required.
Hardware Requirements
This table shows the minimum hardware requirements for SmartConsole applications:
Component | Minimal Requirement |
---|---|
CPU | Intel Pentium Processor E2140, or 2 GHz equivalent processor |
Memory | 4 GB |
Available Disk Space | 2 GB |
Video Adapter | Minimum resolution: 1024 x 768 |
Software Requirements
SmartConsole is supported on:
- Windows 10 (all editions), Windows 8.1 (Pro), and Windows 7 (SP1, Ultimate, Professional, and Enterprise)
- Windows Server 2016, 2012, 2008 (SP2), and 2008 R2 (SP1)
The Gaia Portal supports these web browsers:
Browser | Supported Versions |
---|---|
Google Chrome | 14 and higher |
Microsoft Internet Explorer | 8 and higher |
Microsoft Edge | Any |
Mozilla Firefox | 6 and higher |
Apple Safari | 5 and higher |
OS Compatibility
Endpoint OS Compatibility | Windows | Linux | Mac | iOS | Android |
---|---|---|---|---|---|
Mobile Access Portal | ü | ü | ü | ü | ü |
Clientless access to web applications (Link Translation) | ü | ü | ü | ü | ü |
Compliance Scanner | ü | ü | ü | ||
Secure Workspace | ü | ||||
SSL Network Extender - Network Mode | ü | ü | ü | ||
SSL Network Extender - Application Mode | ü | ||||
Downloaded from Mobile Access applications | ü | ü | ü | ||
Citrix | ü | ü | ü | ||
File Shares - Web-based file viewer (HTML) | ü | ü | ü | ü | ü |
Web mail | ü | ü | ü | ü | ü |
Browser Compatibility
Endpoint | Microsoft | Microsoft | Google | Mozilla | Apple | Opera |
---|---|---|---|---|---|---|
Mobile Access Portal | ü | ü | ü | ü | ü | ü |
Clientless access to web applications (Link Translation) | ü | ü | ü | ü | ü | |
Compliance Scanner(2) | ü | ü | ü | ü | ||
Secure Workspace(3) | ü | ü | ü | |||
SSL Network Extender - Network Mode | ü | ü | ü | ü | ||
SSL Network Extender - Application Mode(3) | ü | ü | ü | ü | ||
Downloaded from Mobile Access applications | ü | ü | ü | ü | ||
Citrix | ü | ü | ü | |||
File Shares - Web-based file viewer (HTML) | ü | ü | ü | ü | ü | Limited |
Web mail | ü | ü | ü | ü | ü |
- Google Chrome support for Mobile Access Portal on-demand clients, such as SSL Network Extender Network Mode, SSL Network Extender Application Mode, Secure Workspace, and Endpoint Security on Demand, requires Java JRE 32-bit installed on the end-user's computer.
- Running Compliance Scanner on Windows platforms requires Java Runtime Environment (JRE or JDK) 32-bit installed on the end-user's computer.
- Secure Workspace and SSL Network Extender Application Mode are available for Windows platforms only.
- Identity Agents
See Clients and Agents Support by Windows Platform and Clients and Agents Support by Mac Platform for:
- Identity Agent (Light and Full)
- Identity Agent for Terminal Servers
- Identity Collector
- AD Query
Active Directory for AD Query is supported on:
Microsoft Windows Server 2008 R2, 2012, 2012 R2, and 2016.
- Endpoint Security Management Servers are supported on Management-only appliances or open servers. Endpoint Security Management Servers do not support Standalone (Security Gateway + Management Server) and Multi-Domain Security Management deployments.
- Endpoint Security Management Servers do not support on Red Hat Enterprise Linux releases.
- R80.30 Endpoint Security Management Server can manage:
- E80.64 and higher versions of Endpoint Security Clients for Windows
- E80.64 and higher Client for macOS
Anti-Malware signature updates:
- To allow Endpoint clients to get Anti-Malware signature updates from a cleanly installed R80.30 Primary Endpoint Security Management Server or cleanly installed R80.30 Endpoint Policy Server, you must follow sk127074. No additional steps are required, if you upgraded the Primary Endpoint Security Management Server to R80.30.
- Endpoint Security Clients can still acquire their Anti-Malware signature updates directly from an external Check Point signature server or other external Anti-Malware signature resources, if your organization's Endpoint Anti-Malware policy allows it.
For more information, see the R80.30 Endpoint Security Management Server Administration Guide.
These are the minimum requirements to enable Endpoint Security management on a Security Management Server:
Component | All Supported Operating Systems |
---|---|
Number of cores | 4 |
Memory | 16 GB |
Disk Space | 500 GB |
The requirements for External Endpoint Policy Servers are similar.
Resource consumption is based on the size of your environment. For larger environments, more disk space, memory, and CPU are required.
Multiple Login Option Support
Version R80.10 introduced multiple login options per gateway with multi-factor authentication schemes, for users of different clients and the Mobile Access portal. For example, configure an option to authenticate with Personal Certificate and Password, or Password and DynamicID for SMS or email.
These features are supported when connected to an R80.30 gateway that has IPsec VPN or Mobile Access enabled.
Supported Client or Portal | Lowest Supported Version |
---|---|
Mobile Access Portal | R80.10 |
Capsule Workspace for iOS | 1002.2 |
Capsule Workspace for Android | 7.1 |
Remote Access clients for Windows - Standalone clients | E80.65 |
Remote Access VPN Blade of the Endpoint Security Suite for Windows | E80.65 |
See the R80.30 Mobile Access Administration Guide or the R80.10 and Higher Remote Access VPN Administration Guide for details.
Clients and Agents Support by Windows Platform
Microsoft Windows
In this table, Windows 7 support is true for Ultimate, Professional, and Enterprise editions. Windows 8 support is true for Pro and Enterprise editions. All the marked consoles and clients support Windows 32-bit and 64-bit.
Check Point Product | Windows 7 (+SP1) | Windows 8.1 | Windows 10 * |
---|---|---|---|
Remote Access clients E80.x | ü | ü | ü |
Capsule VPN Plug-in | ü | ü | |
SSL Network Extender | ü | ü | ü |
UserCheck Client | ü | ü | ü |
Identity Agent (Light and Full) | ü | ü | ü |
Identity Agent for Terminal Servers | ü |
* Supported Windows 10 versions: 1703, 1709, 1803 for more information see the Detailed Client Releases Information section in sk117536.
Microsoft Windows Server
Check Point Product | Server | Server | Server | Server |
---|---|---|---|---|
UserCheck Client | ü | ü | ü | |
Identity Agent for Terminal Servers | ü | ü | ü | ü |
Identity Collector | ü | ü | ü | ü |
Note - Identity Agent for Terminal Servers is also supported on XenApp 6.
Clients and Agents Support by Mac Platform
All support is for Macintosh OS 64-bit.
Check Point Product | OS X 10.11 | macOS 10.12 | OS X 10.13 |
Identity Agent | ü | ü | ü |
SSL Network Extender | ü | ü | ü |
Endpoint Security VPN E80.x or higher | ü | ü | ü |
DLP Exchange Agent Support
Security Vpn Download
The R80.30 DLP Exchange Agent is supported on:
Windows Server | Exchange Server |
---|---|
2012 R2 64-bit | 2010, 2013 |
2016 64-bit | 2016 |
Security Vpn Free
For earlier server versions, use the R77.30 DLP Exchange Agent.