Upgrade steps for Windows

Note: If you are installing Forcepoint F1E v23.11 agents with the new Neo endpoint agent, install Forcepoint F1E before you install Neo.

Create a new endpoint installation package using the Forcepoint Endpoint package builder

  1. Download the latest package builder from the Forcepoint Support site:
    1. Log on to the Forcepoint Downloads page.
    2. Do one of the following:
      • In Products select Data Loss Prevention (DLP), and in Product Options select Endpoint (DLP).
      • In Products select Web Security, and in Product Options select Endpoint (Web).
      • In Products select Next Generation Firewall (NGFW), and in Product Options select Endpoint (NGFW).
    3. Select the desired package builder.

      The Product Installer view opens.

    4. Click Download.

      A ZIP file named ForcepointOneEndpointPackage.zip downloads.

  2. Before you create an installation package, complete the following agent-specific tasks:
    • Forcepoint DLP Endpoint:
      • You must be logged on to the Forcepoint DLP server with a Service Account before you run the package builder. Otherwise, incorrect communication keys are created and Forcepoint DLP Endpoint cannot connect to the Forcepoint DLP server.
      • You must copy the Endpoint Classifier files from ForcepointOneEndpointPackage.zip to the C:\Program Files (x86)\Websense\Data Security\client folder. For more information about this step, see Forcepoint DLP Endpoint Windows and Mac deployments.
      Important:

      Due to a compatibility issue with older Windows Endpoint Classifier files, you must use the Windows Endpoint Classifier files provided in this ZIP file when you build a Windows Forcepoint DLP Endpoint installation package using this package builder.

      If you use older Windows Endpoint Classifier files, the package builder shows an error message and does not build an installation package.

    • Forcepoint ECA:
      • Verify that you have the configuration file you used when you created the previous Forcepoint ECA package.
  3. Open ForcepointOneEndpointPackage.zip and run WebsenseEndpointPackageBuilder.exe.
  4. On the Select Endpoint Components screen, select two or more of the following:
    • Forcepoint Web Security Endpoint
    • Forcepoint DLP Endpoint
    • Forcepoint Endpoint Context Agent
    • CASB Endpoint (available under Forcepoint Web Security Endpoint)
  5. If you selected Forcepoint Web Security Endpoint above, select one of the options below:
    • Direct Connect Endpoint (not available with Forcepoint ECA)
    • Proxy Connect Endpoint
  6. Choose Windows 32-bit or Windows 64-bit when prompted.
  7. Complete the configuration for each selected component in the installation wizard to create the installation package.

    For more information about configuring the components, see the Installation and Deployment Guide for Forcepoint F1E.

    Important: If the conventional Forcepoint ECA (v1.4 or earlier) is installed, uninstall it before deploying the new Forcepoint F1E installation package. If you do not uninstall the conventional Forcepoint ECA software, the new Forcepoint F1E software may not open correctly.
  8. Deploy the installation package to each endpoint machine manually, or using GPO, SMS, or a similar deployment method, as described in the Installation and Deployment Guide for Forcepoint F1E.

    For information about how to upgrade Remote Filtering Client, see the Upgrading the Remote Filtering Client section of Deploying the Remote Filtering Module.

    Note:
    • Forcepoint Web Security Direct Connect Endpoint end users must join your organization’s domain on the endpoint machine. If the end user has not joined and connected to your domain, the disposition server test fails.
    • If you deploy Forcepoint F1E using GPO, do not restrict access to the command prompt.
  9. After you finish the upgrade, you may need to restart the endpoint machine:
Upgrade from Restart Required?

Forcepoint DLP Endpoint

v8.3 and earlier

Yes

You must uninstall Forcepoint DLP Endpoint v8.3 and earlier, then restart the endpoint machine before installing v23.11.

v8.4 and later Yes

Forcepoint Proxy Connect Endpoint

v8.3 and earlier

Yes

You must uninstall Forcepoint Proxy Connect Endpoint v8.3 and earlier, then restart the endpoint machine before installing v23.11.

v8.4 and later Yes

Forcepoint Direct Connect Endpoint

v8.3 and earlier

Yes

You must uninstall Forcepoint Direct Connect Endpoint v8.3 and earlier, then restart the endpoint machine before installing v23.11.

v8.4 and later Yes

Forcepoint ECA

v1.4 and earlier

Yes

You must uninstall Forcepoint ECA v1.4 and earlier, then restart the endpoint machine before installing v23.11.

v19.04 and later Yes

Automatic software updates

To automate software updates for Forcepoint DLP Endpoint or combined Forcepoint DLP Endpoint/Forcepoint Web Security Endpoint through the package builder, see Automatic Updates for Forcepoint DLP Endpoint for details.