PortGuard deployment checklist

Console installers by platform · Linux Agent installation · License operator guide

Use the current Stable Console installer in the matching platform tab. Prepare a dedicated license for each Console instance. Agent and Console versions are independent.

StepActionExpected result
1. LicenseLicensing admin signs in, issues the organization license and seat count, copies the one-time code.License is issued; code is privately available to the Console administrator.
2. ConsoleInstall the matching platform package. Create the local admin account and activate in Settings → License.Organization and seat capacity appear; License Server shows the bound Console instance.
3. DeploymentAccess Console by its reachable LAN URL. Endpoints → Enroll agents → select allowed operating systems (include Linux for a Linux deployment) → download deployment file.One reusable private rollout file; no per-device code.
4. AgentInstall Linux Agent with that file; inspect both service statuses.Authenticated heartbeat, endpoint online, one seat allocated.
5. USBConnect a USB drive, check status, safely unmount, Block, then Allow.Command results report verified native evidence. Mounted/in-use devices are refused; with no device, the saved block policy is Protected and Allow is Unprotected.
6. PersistenceRestart Agent and verify heartbeat.Same identity and seat; no duplicate registration.
7. CapacityWith a dedicated small license, try enrolling beyond capacity.Enrollment rejects the extra identity. Offline identities still occupy seats.

Additional checks

Replace a license in Console Settings → License with a larger total capacity and confirm the same Agent IDs remain. Change a Linux Agent URL using the address-change workflow and verify the same seat is retained. Save Block/Allow without a USB drive and verify Protected/Unprotected, then attach a safe test device.

Troubleshooting

Record the Console build, Agent version, operating system, command ID and sanitized error. Keep activation codes, deployment files and tokens private. License revocation does not remotely invalidate an already-issued entitlement; revoke an Agent in Console separately to release its seat.

Use a trusted network for the default HTTP connection. HTTP traffic is not encrypted.