Mobile Access for Smartphones and Tablets

Mobile Access for Smartphones and Tablets

Overview of Mobile Access for Smartphones and Tablets

To manage your users and their access to resources, do these actions:

For client certificates, use the Certificate Creation and Distribution Wizard (see the "Creating Client Certificates" section).

Certificate Authentication for Handheld Devices

For handheld devices to connect to the Security Gateway, these certificates must be properly configured:

Managing Client Certificates

Check Point Mobile Apps for mobile devices can use certificate-only authentication or two-factor authentication with client certificates and username/password. The certificate is signed by the internal CA of the Security Management Server.

Manage client certificates in Security Policies > Access Control > Access Tools > Client Certificates.

The page has two panes.

Creating Client Certificates

Note - If you use LDAP or AD, creation of client certificates does not change the LDAP or AD server. If you get an error message regarding LDAP/AD write access, ignore it and close the window to continue.

To create and distribute certificates with the client certificate wizard:

  1. In SmartConsole, select Security Policies > Access Control > Access Tools > Client Certificates.

  2. In the Client Certificates pane, click New.
    The Certificate Creation and Distribution wizard opens.

  3. In the Certificate Distribution page, select how to distribute the enrollment keys to users. You can select one or both options.

    1. Send an email containing the enrollment keys using the selected email template - Each user gets an email, based on the template you choose, that contains an enrollment key.
    2. Generate a file that contains all of the enrollment keys - Generate a file for your records that contains a list of all users and their enrollment keys.
  4. Optional: To change the expiration date of the enrollment key, edit the number of days in Users must enroll within x days.

  5. Optional: Add a comment that will show next to the certificate in the certificate list on the Client Certificates page.

  6. Click Next.
    The Users page opens.

  7. Click Add to add the users or groups that require certificates.

  8. When all included users or groups show in the list, click Generate to create the certificates and send the emails.

  9. Click Finish.

  10. Click Save.

  11. In SmartConsole, install the Policy.

Revoking Certificates

If the status of a certificate is Pending Enrollment, after you revoke it, the certificate does not show in the Client Certificate list.

To revoke one or more certificates

  1. Select the certificate or certificates from the Client Certificate list.
  2. Click Revoke.
  3. Click OK.

After you revoke a certificate, it does not show in the Client Certificate list.

Creating Templates for Certificate Distribution

To create or edit an email template 01. In SmartConsole, select Security Policies > Access Control > Access Tools > Client Certificates. 02. To create a new template: In the Email Templates for Certificate Distribution pane, select New. To edit a template: In the Email Templates for Certificate Distribution pane, double-click a template.

  1. Enter a Name for the template.
  2. Optional: Enter a Comment. Comments show in the Mail Template list on the Client Certificates page.
  3. Optional: Click Languages to change the language of the email.
  4. Enter a Subject for the email. Click Insert Field to add a predefined field, such as a Username.
  5. In the message body add and format text. Click Insert Field to add a predefined field, such as Username, Registration Key, or Expiration Date.
  6. Click inside the E-mail Template body.
  7. Click Insert Link and select the type of link to add (link or QR code).
  8. Click OK.
  9. Optional: Click Preview in Browser to see a preview of how the email will look.
  10. Click OK.
  11. Publish the changes.

Cloning a Template

Clone an email template to create a template that is similar to one that already exists.

To create a clone of an email template

  1. Select a template from the template list in the Client Certificates page.
  2. Click Clone.
  3. A new copy of the selected template opens for you to edit.

Remote Wipe

Remote Wipe removes the offline data cached on the user's mobile device.

When the administrator revokes the internal CA certificate, a Remote Wipe push notification is sent, if the Remote Wipe configuration for the client enables Remote Wipe by Push Notification. Remote Wipe is triggered when the device gets the push notification.

Note - Remote Wipe by Push Notification works by best effort. There is no guarantee that the Security Gateway will send the notification, or that the client will get it successfully.

If the device does not get the Remote Wipe push notification, Remote Wipe is triggered when the client does an activity that requires connection to the Security Gateway while using a revoked internal CA certificate.

Remote Wipe send logs:

To configure Remote Wipe:

  1. Run the applicable command on the Security Gateway in the Expert mode.

Syntax:

`cvpnd_settings {set
  1. Restart the CVPN service to apply the changes:
cvpnrestart

To see that your changes are applied, open the $CVPNDIR/conf/cvpnd.C file in Read-Only mode.

To trigger Remote Wipe on a device:

  1. Make sure that the $CVPNDIR/conf/cvpnd.C file is configured for Remote Wipe and, if you want, for Push Notifications.
  2. Revoke the client certificate:
    1. Open Mobile Access tab > Client Certificates.
    2. Select certificates.
    3. Click Revoke.
    4. Click OK.

To see Remote Wipe logs:

  1. Open SmartConsole.
  2. From the left navigation panel, click Logs & Events > Logs.
  3. Query for:
    "Remote Wipe" AND blade:"Mobile Access" action:"Failed Log In"

You can filter these results for user DN, device ID, or certificate serial number.

Mobile Device Profiles

For Capsule Workspace, many settings that affect the user experience on mobile devices come from the Mobile Profile.

Each Mobile Access user group has an assigned Mobile Profile. By default, all users get the Default Profile.

The settings in the Mobile Profile include:

Manage the Mobile Profiles in Mobile Access tab > Capsule Workspace Settings.

Creating and Editing Mobile Profiles

To create or edit a Mobile Profile

  1. In SmartConsole, from the left taskbar, click Manage & Settings.

  2. Click Blades.

  3. In the Mobile Access section, click the Capsule Workspace Settings button.

  4. Open the Profiles tab.

  5. Do one of these:

    • To create a new Mobile Profile, right click inside the table > click New.
    • To edit an existing Mobile Profile, right click on the table row that contains the profile > click Edit...
  6. Change settings. See the Capsule Workspace Settings in the Mobile Profile section below.

  7. Click OK.

  8. Install policy.

Capsule Workspace Settings in the Mobile Profile

  1. In the Security tab, configure Access Settings:
    • Session timeout - After users authenticate with the authentication method configured in Gateways & Servers > Security Gateway object > Mobile Access > Authentication, configure how long they stay authenticated to the Security Gateway.
    • Activate Passcode lock - Select to protect the Business Secure Container area of the mobile device with a passcode.
      • Passcode profile - Select a passcode profile to use. The profile includes the passcode complexity, length, expiration, and number of failed attempts allowed.
      • Allow storing user credentials on the device for single-sign on - If username and password authentication is used, store the authentication credentials on the device. Then users are only prompted for their passcode not also for their username and password.
    • Report jail-broken devices - Create a log if a jail-broken device connects to the Security Gateway.
      • Block access from jail-broken devices - Block devices that are jail-broken from connecting to the Security Gateway.
    • Block third-party keyboard - Block keyboards that are not the native keyboard for the operating system of the endpoint device.
    • Hide 'connect anyway' on SSL trust screen - If the endpoint device does not trust the certificate of the Security Gateway, users do not have the option to connect.
  2. In the Applications tab, select which application features are available on devices:
    • Mail
    • Allow printing mail - allows users of the endpoint device to print email.
    • Max attachment size (MB) - select the maximum attachment size to allow.
    • Offline Content - configure what data is saved and for how long when the Check Point App cannot reach the Security Gateway.
    • Push Notifications - allow push notifications on devices.
    • Calendar
    • Contacts
    • Web Applications
    • Check Point Capsule Documents
  3. In the Data Loss Prevention tab, configure settings for Outbound and Inbound traffic.
  4. In the Harmony Mobile section, configure settings for Harmony Mobile integration with the Harmony Mobile application or with Harmony App Protect.
  5. In the Client Customization tab, configure what end users see in the client.
  6. In the Advanced tab, configure custom fields for new Capsule Workspace features that do not exist in your version of SmartConsole.

Managing Passcode Profiles

A passcode lock protects Capsule Workspace in mobile devices. In each Mobile Profile, configure which Passcode Profile it uses. The profile includes the passcode requirements, expiration, and number of failed attempts allowed. The default passcode profiles are Normal, Permissive, and Restrictive. You can edit the default profiles and create new profiles.

To manage Passcode Profiles:

  1. In SmartConsole, from the left taskbar, click Security Policies.

  2. Click Blades.

  3. In the Mobile Access section, click the Capsule Workspace Settings button.

  4. Open the Passcodes tab.

  5. Do one of these:

    • To create a new Passcode Profile, right-click inside the table > click New.
    • To edit an existing Mobile Profile, right-click on the table row that contains the profile > click Edit...
  6. Change settings. See the Passcode Profile Settings section below.

  7. Click OK.

  8. Install policy.

Configuring Push Notifications

Enable push notifications from the Mobile Access Wizard or from the Security Gateway Properties of each Security Gateway.

  1. Open a Security Gateway object that has Mobile Access enabled.
  2. Select Mobile Access > Capsule Workspace from the tree.
  3. Select Enable Push Notifications.
  4. Click OK.

Exchange Server and Security Gateway Communication

Make sure that the Exchange server can access the Mobile Access Portal.

All confidential information between the Exchange server and the Security Gateway uses encrypted SSL tunnels. Non-confidential information can use unencrypted HTTP connections.

You can configure all push notification communication to use SSL tunnels.

To force all push notification communication to go through SSL tunnels:

  1. Install a trusted server certificate on the Mobile Access Security Gateway.
  2. Close all SmartConsole windows connected to the Management Server.
  3. Connect with Database Tool (GuiDBEdit Tool) to the Management Server.
  4. Search for the field main_url (Ctrl +F).
  5. Press F3 to see next main_url until you find main_url that contains the value ExchangeRegistration.
  6. Double-click the ExchangeRegistration main_url field and edit the value to be https:// and not http://.
  7. Save the changes and close Database Tool (GuiDBEdit Tool).
  8. Connect with SmartConsole to the Management Server.
  9. Open the Mobile Access Security Gateway object.
  10. Click OK.
  11. Install policy.

Instructions for End Users

Give these instructions to end users to configure their mobile devices to work with Mobile Access.

iPhone/iPad End User Configuration

To connect to the corporate site:

  1. Get Check Point Capsule Workspace from the App Store.
  2. When prompted, enter the Site Name and Registration key.

Android End User Configuration

To connect to the corporate site:

  1. Get the Check Point Mobile app from the Android Market.
  2. When prompted, enter the Site Name and Registration key.