Firmware Version: 4.5 and above
Note: Before configuring Enterprise Cloud on GajShield, make sure you have a cloud license.
Note: If you find that CA certificate has been created beforehand, it is the same certificate created under Browsing >> Setup >> SSL Certificate used for scanning https browsing traffic. You have to now configure additional information fields specified below
Go to Enterprise Cloud tab >> Go to Organization Information and fill in the details to configure cloud service information.
If not, you'll have to add all the CA certificate information under Enterprise Cloud -> Organization Information
Note: Certificate should have key length value set to 1024
#FQDN: The Fully Qualified Domain Name (FQDN), FQDN must be in ASCII format. For example, myhost.test.com.
#X.509 DN: An X.509 certificate binds a name to a public key value. The role of the certificate is to associate a public key with the identity contained in the X.509 certificate.
#IP Address: IP address the certificate is associated with. It can be any IP address. For example, 125.11.12.13
#Email: Email address the certificate is associated with. For example, support@gajshield.com
1. Important: If your current certificate expires and you need to create a new certificate, under Browsing >> Setup >> SSL Certificate after creating the certificate, go to
Enterprise Cloud >>Organization.
Information & click on, without doing any changes in the configuration click on save. After recreating the certificate, you will need to delete the old cloud exe under Configuration Users and create new cloud exe.
2. Select Cloud configuration as required, under Cloud Service Information.
Note: UDP ports / services will not work when selecting cloud failover option
3. Final Cloud configuration will look like the below image.
4. Now you need to create a user from Browsing >> User Setting >> Users >> +
After adding fields click on Add button.
5. Go to Enterprise Cloud >> Configure Users >> +
![]() |
Note: To add new users or group in clouds Available Users or Available Groups list, add them from Browsing >> Users setting.
6. After adding the user to cloud services, sign the exe by clicking on Click here to sign
Note: This password can be used to disconnect or uninstall the cloud client.
Important: Restart Cloud Service, if you make any changes in Organization Information tab.
7. Now you can download the cloud client exe by clicking on . If you want to download only the user certificate click on save the zip folder containing 3 files. For example (ca.crt, guest-client.crt, guest-client.key)
Important: Install cloud client on normal user login, & use "Run as Administrator" to install cloud client.
8. To change password of the cloud client on users PC, where the cloud client is installed. Right click on cloud icon shown on the right side of your taskbar. Select Change Password, a pop-up will open insert old password and the new password.
9. If you have forgotten the password of the cloud client exe, you will have to re- create the user exe (repeat step 4 & 5) and download the new user certificate from the firewall (see step 6) and not the cloud client exe. Import the 3 files downloaded from the firewall in the respective boxes as shown below.
Certificate downloaded from the firewall for example is guest-client.zip, contains 3 files as show below
Note: Import the above three files in their respective sections.
10. After configuring enterprise cloud, you will need to add firewall policy to allow mobile users to connect to the firewall.
Go to Firewall >> Policies >> Rules and add policies according to your organizations requirements. Show below is an example of firewall policy for cloud client.
You have successfully configured Enterprise Cloud on your firewall.
Attached Files:
How_to_configure_Enterprise_cloud.pdf