Mobile Access for Smartphones and Tablets
Mobile Access for Smartphones and Tablets
Overview of Mobile Access for Smartphones and Tablets
To manage your users and their access to resources, do these actions:
For email, calendar, and contact access, configure Mobile Mail or ActiveSync applications.
This can be done automatically in the Mobile Access Wizard.Configure Web applications, if necessary.
Make sure users have the information and credentials required to authenticate to the Security Gateway.
For client certificates, use the Certificate Creation and Distribution Wizard (see the "Creating Client Certificates" section).
Make sure users' Mobile Settings meet your organization's needs (see the "Managing Mobile Settings" section).
Tell users which App to install.
Make sure smartphone and tablet users are included in your Mobile Access Policy.
Certificate Authentication for Handheld Devices
For handheld devices to connect to the Security Gateway, these certificates must be properly configured:
If you configure Personal Certificate as the authentication method, make sure to generate client certificates for users (see the "Managing Client Certificates" section).
A server certificate signed by a trusted third-party Certification Authority (for example, Entrust) is strongly recommended. If you have a third-party certificate, make sure the CA is trusted by the device. If you do not have a third-party certificate, a self-signed certificate is already configured on the server.
Managing Client Certificates
Check Point Mobile Apps for mobile devices can use certificate-only authentication or two-factor authentication with client certificates and username/password. The certificate is signed by the internal CA of the Security Management Server.
Manage client certificates in Security Policies > Access Control > Access Tools > Client Certificates.
The page has two panes.
- In the Client Certificates pane:
- Create, edit, and revoke client certificates.
- See all certificates, their status, expiration date and enrollment key. By default, only the first 50 results show in the certificate list. Click Show more to see more results.
- Search for specified certificates.
- Send certificate information to users.
- In the Email Templates for Certificate Distribution pane:
- Create and edit email templates for client certificate distribution.
- Preview email templates.
Creating Client Certificates
Note - If you use LDAP or AD, creation of client certificates does not change the LDAP or AD server. If you get an error message regarding LDAP/AD write access, ignore it and close the window to continue.
To create and distribute certificates with the client certificate wizard:
In SmartConsole, select Security Policies > Access Control > Access Tools > Client Certificates.
In the Client Certificates pane, click New.
The Certificate Creation and Distribution wizard opens.In the Certificate Distribution page, select how to distribute the enrollment keys to users. You can select one or both options.
- Send an email containing the enrollment keys using the selected email template - Each user gets an email, based on the template you choose, that contains an enrollment key.
- Generate a file that contains all of the enrollment keys - Generate a file for your records that contains a list of all users and their enrollment keys.
Optional: To change the expiration date of the enrollment key, edit the number of days in Users must enroll within x days.
Optional: Add a comment that will show next to the certificate in the certificate list on the Client Certificates page.
Click Next.
The Users page opens.Click Add to add the users or groups that require certificates.
When all included users or groups show in the list, click Generate to create the certificates and send the emails.
Click Finish.
Click Save.
In SmartConsole, install the Policy.
Revoking Certificates
If the status of a certificate is Pending Enrollment, after you revoke it, the certificate does not show in the Client Certificate list.
To revoke one or more certificates
- Select the certificate or certificates from the Client Certificate list.
- Click Revoke.
- Click OK.
After you revoke a certificate, it does not show in the Client Certificate list.
Creating Templates for Certificate Distribution
To create or edit an email template 01. In SmartConsole, select Security Policies > Access Control > Access Tools > Client Certificates. 02. To create a new template: In the Email Templates for Certificate Distribution pane, select New. To edit a template: In the Email Templates for Certificate Distribution pane, double-click a template.
- Enter a Name for the template.
- Optional: Enter a Comment. Comments show in the Mail Template list on the Client Certificates page.
- Optional: Click Languages to change the language of the email.
- Enter a Subject for the email. Click Insert Field to add a predefined field, such as a Username.
- In the message body add and format text. Click Insert Field to add a predefined field, such as Username, Registration Key, or Expiration Date.
- Click inside the E-mail Template body.
- Click Insert Link and select the type of link to add (link or QR code).
- Click OK.
- Optional: Click Preview in Browser to see a preview of how the email will look.
- Click OK.
- Publish the changes.
Cloning a Template
Clone an email template to create a template that is similar to one that already exists.
To create a clone of an email template
- Select a template from the template list in the Client Certificates page.
- Click Clone.
- A new copy of the selected template opens for you to edit.
Remote Wipe
Remote Wipe removes the offline data cached on the user's mobile device.
When the administrator revokes the internal CA certificate, a Remote Wipe push notification is sent, if the Remote Wipe configuration for the client enables Remote Wipe by Push Notification. Remote Wipe is triggered when the device gets the push notification.
| Note - Remote Wipe by Push Notification works by best effort. There is no guarantee that the Security Gateway will send the notification, or that the client will get it successfully. |
If the device does not get the Remote Wipe push notification, Remote Wipe is triggered when the client does an activity that requires connection to the Security Gateway while using a revoked internal CA certificate.
Remote Wipe send logs:
- If a Remote Wipe Push Notification is sent.
- When a Remote Wipe process ends successfully.
To configure Remote Wipe:
- Run the applicable command on the Security Gateway in the Expert mode.
Syntax:
| `cvpnd_settings |
- To enable or disable Remote Wipe:
Remote Wipe is enabled by default.`cvpnd_settings $CVPNDIR/conf/cvpnd.C set RemoteWipeEnabled {true - To enable or disable Remote Wipe by Push Notification (wipe is done if client gets notification):
The Remote Wipe Push Notifications feature is enabled by default. For supported clients, see sk95587.`cvpnd_settings $CVPNDIR/conf/cvpnd.C set RemoteWipePushEnabled {true - To set supported devices for Remote Wipe Push Notifications, based on operating system:
`cvpnd_settings $CVPNDIR/conf/cvpnd.C listAdd RemoteWipePushSupportedClientOS {iOS
- Restart the CVPN service to apply the changes:
cvpnrestart |
To see that your changes are applied, open the $CVPNDIR/conf/cvpnd.C file in Read-Only mode.
To trigger Remote Wipe on a device:
- Make sure that the
$CVPNDIR/conf/cvpnd.Cfile is configured for Remote Wipe and, if you want, for Push Notifications. - Revoke the client certificate:
- Open Mobile Access tab > Client Certificates.
- Select certificates.
- Click Revoke.
- Click OK.
To see Remote Wipe logs:
- Open SmartConsole.
- From the left navigation panel, click Logs & Events > Logs.
- Query for:
"Remote Wipe" AND blade:"Mobile Access" action:"Failed Log In"
You can filter these results for user DN, device ID, or certificate serial number.
Mobile Device Profiles
For Capsule Workspace, many settings that affect the user experience on mobile devices come from the Mobile Profile.
Each Mobile Access user group has an assigned Mobile Profile. By default, all users get the Default Profile.
The settings in the Mobile Profile include:
- Passcode Settings
- Mail, Calendar, and Contacts availability
- Settings for offline content
- Where contacts come from
Manage the Mobile Profiles in Mobile Access tab > Capsule Workspace Settings.
- In the Mobile Profiles pane:
- See all Mobile Profiles.
- Create, edit, delete, clone, and rename Mobile Profiles.
- In the Mobile Profile Policy pane:
- Create rules to assign Mobile Profiles to user groups.
- Search for a user or group within the policy rules.
Creating and Editing Mobile Profiles
To create or edit a Mobile Profile
In SmartConsole, from the left taskbar, click Manage & Settings.
Click Blades.
In the Mobile Access section, click the Capsule Workspace Settings button.
Open the Profiles tab.
Do one of these:
- To create a new Mobile Profile, right click inside the table > click New.
- To edit an existing Mobile Profile, right click on the table row that contains the profile > click Edit...
Change settings. See the Capsule Workspace Settings in the Mobile Profile section below.
Click OK.
Install policy.
Capsule Workspace Settings in the Mobile Profile
- In the Security tab, configure Access Settings:
- Session timeout - After users authenticate with the authentication method configured in Gateways & Servers > Security Gateway object > Mobile Access > Authentication, configure how long they stay authenticated to the Security Gateway.
- Activate Passcode lock - Select to protect the Business Secure Container area of the mobile device with a passcode.
- Passcode profile - Select a passcode profile to use. The profile includes the passcode complexity, length, expiration, and number of failed attempts allowed.
- Allow storing user credentials on the device for single-sign on - If username and password authentication is used, store the authentication credentials on the device. Then users are only prompted for their passcode not also for their username and password.
- Report jail-broken devices - Create a log if a jail-broken device connects to the Security Gateway.
- Block access from jail-broken devices - Block devices that are jail-broken from connecting to the Security Gateway.
- Block third-party keyboard - Block keyboards that are not the native keyboard for the operating system of the endpoint device.
- Hide 'connect anyway' on SSL trust screen - If the endpoint device does not trust the certificate of the Security Gateway, users do not have the option to connect.
- In the Applications tab, select which application features are available on devices:
- Allow printing mail - allows users of the endpoint device to print email.
- Max attachment size (MB) - select the maximum attachment size to allow.
- Offline Content - configure what data is saved and for how long when the Check Point App cannot reach the Security Gateway.
- Push Notifications - allow push notifications on devices.
- Calendar
- Contacts
- Web Applications
- Check Point Capsule Documents
- In the Data Loss Prevention tab, configure settings for Outbound and Inbound traffic.
- In the Harmony Mobile section, configure settings for Harmony Mobile integration with the Harmony Mobile application or with Harmony App Protect.
- In the Client Customization tab, configure what end users see in the client.
- In the Advanced tab, configure custom fields for new Capsule Workspace features that do not exist in your version of SmartConsole.
Managing Passcode Profiles
A passcode lock protects Capsule Workspace in mobile devices. In each Mobile Profile, configure which Passcode Profile it uses. The profile includes the passcode requirements, expiration, and number of failed attempts allowed. The default passcode profiles are Normal, Permissive, and Restrictive. You can edit the default profiles and create new profiles.
To manage Passcode Profiles:
In SmartConsole, from the left taskbar, click Security Policies.
Click Blades.
In the Mobile Access section, click the Capsule Workspace Settings button.
Open the Passcodes tab.
Do one of these:
- To create a new Passcode Profile, right-click inside the table > click New.
- To edit an existing Mobile Profile, right-click on the table row that contains the profile > click Edit...
Change settings. See the Passcode Profile Settings section below.
Click OK.
Install policy.
Configuring Push Notifications
Enable push notifications from the Mobile Access Wizard or from the Security Gateway Properties of each Security Gateway.
- From the Mobile Access Wizard:
- If you enable Mobile Mail in the Mobile Access Wizard, push notifications are automatically enabled for the Security Gateway.
- If you enable Mobile Mail from the Mobile Access tab, push notifications are NOT enabled.
- From the Security Gateway Properties:
- Open a Security Gateway object that has Mobile Access enabled.
- Select Mobile Access > Capsule Workspace from the tree.
- Select Enable Push Notifications.
- Click OK.
Exchange Server and Security Gateway Communication
Make sure that the Exchange server can access the Mobile Access Portal.
All confidential information between the Exchange server and the Security Gateway uses encrypted SSL tunnels. Non-confidential information can use unencrypted HTTP connections.
You can configure all push notification communication to use SSL tunnels.
To force all push notification communication to go through SSL tunnels:
- Install a trusted server certificate on the Mobile Access Security Gateway.
- Close all SmartConsole windows connected to the Management Server.
- Connect with Database Tool (GuiDBEdit Tool) to the Management Server.
- Search for the field main_url (Ctrl +F).
- Press F3 to see next main_url until you find main_url that contains the value ExchangeRegistration.
- Double-click the ExchangeRegistration main_url field and edit the value to be https:// and not http://.
- Save the changes and close Database Tool (GuiDBEdit Tool).
- Connect with SmartConsole to the Management Server.
- Open the Mobile Access Security Gateway object.
- Click OK.
- Install policy.
Instructions for End Users
Give these instructions to end users to configure their mobile devices to work with Mobile Access.
iPhone/iPad End User Configuration
To connect to the corporate site:
- Get Check Point Capsule Workspace from the App Store.
- When prompted, enter the Site Name and Registration key.
Android End User Configuration
To connect to the corporate site:
- Get the Check Point Mobile app from the Android Market.
- When prompted, enter the Site Name and Registration key.