Downloading and Installing the Agent and Certificates

Prev Next

Prerequisites

  • Network connectivity to required  SASE Agent service URLs.
  • Firewall access for required inbound and outbound traffic.
  • Open ports based on the configured VPN protocol and tenant region.

For the complete list of required URLs, ports, and protocol details, see sk182251.

In the Downloads page, you can download the Check Point SASE Agent and Certificate. 

To view the Downloads page, access the Check Point SASE Administrator Portal and click Devices > Downloads.

Note - The version available here may be newer than the default version for some customers, while a gradual rollout is underway.
Notes -
  • For the latest SASE Agent versions, see sk182466.
  • The SASE Agent is supported on devices with ARM processor in Private Access mode only.


Downloading the Check Point SASE Agent

  1. Access the Check Point SASE Administrator Portal and click Devices > Downloads.
  2. Click the Agents tab.
  3. Do one of these:
  4. To verify that the downloaded file is authentic, use the Checksum.
  5. Deploying the Agent Using an MDM Application.

Downloading the Certificate

  1. Access the Check Point SASE Administrator Portal and click Devices > Downloads.
  2. Click the Certificates tab.
  3. Click Activate to activate the SWG root certificate.
  4. When the certificate is active, click Download.
    The system downloads a PEM file.
MDM Deployment
If the devices in your organization are managed through a central desktop management tool you may prefer remote installation instead of having team members download and install the agent on their own.
Web Security (SWG) - Agents with the Web Security feature enabled requires additional steps to ensure the feature's full functionality. For detailed steps, see MDM App Deployment.