(MDM) Installing the agent for Web Security

This section outlines the steps to install the macOS Forcepoint Agent using Jamf for Web Security Proxy Connect (PCEP) or Direct Connect (DCEP).

Steps

  1. Obtain the Forcepoint Cloud CA certificate:
    1. Go to the Forcepoint Cloud Security Gateway portal.
    2. Select the policy from Account > Policies, and then click Web Categories.
    3. Click Forcepoint LLC root certificate(s), and save the certificate.

  2. Obtain the generate_root_ca tool from here and run in the terminal.
    The _ca.cer certificate and the fpnpd.dat file generates in the installer folder.
  3. Obtain the downloaded agent, unzip and then create a installer package for Jamf MDM deployment with the following files:
    • fpnpd.dat
    • manifest.json
    • WebsenseEndpoint.pkg
  4. Open Jamf Pro and in Computers > Configuration Profiles, deploy the following files through Jamf:
  5. To enroll the machine to the profiles, select the configuration profile file, review the profile in System Settings.
    A message appears for your confirmation to install the profile.
  6. Click Install, and then click Enroll.

    The enrolled profiles will display under the Device (Managed) section in System Settings > General > Device Management in your system, and the Full Disk Access will be enabled for the following applications configured by the profiles.
    Application Path
    EndpointClassifier Library/Application Support/Websense Endpoint/EPClassifier/EndPointClassifier
    ESDaemonBundle Library/Application Support/Websense Endpoint/DLP/ESDaemonBundle.app
    AEserver System/Library/Frameworks/CoreServices.framework/Versions/A/Frameworks/AE.framework/Versions/A/Support/AEServer
    FPEPAgent Library/Application Support/Websense Endpoint/Cloud/FPEPAgent
    Websense Endpoint Helper Library/Application Support/Websense Endpoint/DLP/Websense Endpoint Helper.app
    F1EHelper Library/Application Support/Websense Endpoint/F1E/F1E Helper.app
    wsdlpd Library/Application Support/Websense Endpoint/DLP/wsdlpd
    fpprotectiond Library/Application Support/Websense Endpoint/Cloud/fpprotectiond
    fpbrokerd Library/Application Support/Websense Endpoint/Cloud/fpbrokerd
  7. Deploy the package in Jamf.