New Trusted Partner Client-Based Access for Windows XP and Windows 7 Includes Juniper Netconnect VPN client and CyberGatekeeper client Copyright 2011 FMR Corp. February 2011
Trusted Partner Access Pre-InstallationWorksheet This document contains instructions for downloading and installing the software required for Trusted Partner Client-based access. This software is NOT required for Trusted Partner Web-based access (commonly known as TPA WEB). If you have trouble with the pre-installation tasks, contact Techline at 800-525-3274. You must be using Windows XP or Windows 7 If you are not on Windows XP or Windows 7 please contact your Fidelity Business Unit sponsor to research options for getting the appropriate Operating System. Vista is not supported If ha Locate your Local Administrator Password The installation of the Juniper client package requires local administrator privileges. If you are using a Fidelity asset, you can download the software from the SSI link when you are in the office working onsite. If installed in that manner, administrator privileges are not required. Order a Hard Token (RSA SecurID) If you are an existing Trusted Partner and already have a Hard Token, please skip this step. If you do not have a Hard Token or no one has not requested a Hard Token for you please have your Business Unit Sponsor go to the site below and follow the necessary procedures: http://trustedpartner.fmr.com Obtain/Install Anti-virus Software (non-fidelity devices only) Important note: Anti-virus software is no longer provided to Trusted Partners using personally owned or other non-fidelity devices. Symantec AntiVirus Corporate Edition (SAV) 10.x., Symantec Endpoint Protection v.11 Corporate Edition, or McAfee Total Protection 2010 or 2011 are approved versions of anti-virus software for accessing Fidelity s network. Anti-virus software is required for client-based access and must be obtained/installed separately for non-fidelity devices.
Table of Contents Table of Contents... iii About Trusted Partner Access... 1 What is Trusted Partner Access?...1 What software is included in Trusted Partner Access?...1 Do I have to uninstall any existing software on my Computer?...1 Do I need a Firewall if I am using a Cable or DSL connection?...1 Install Trusted Partner Access Software... 3 Run the Trusted Partner Access Auto-Installation Program...3 Log In to Fidelity and Test the Installation... 5 Overview of the Log-In Process...5 Connect to the Trusted Partner Portal...6 Identify Yourself as a Valid Fidelity User...7 Access applications on Fidelity s Network...10 Terms Used in this Guide...11 If you have trouble with the installation tasks, contact the Help Desk at 800-525-3274 iii
About Trusted Partner Access About Trusted Partner Access What is Trusted Partner Access? Trusted Partner Access is a Fidelity (Internet Based) remote access product, which gives Trusted Partners (non-full-time employees) access to applications and devices on Fidelity s Network. This product must be installed on a Windows XP or Windows 7 build. The software can be downloaded from https://remote.fidelity.com. What software is included in Trusted Partner Access? Based on your selections during the install, you will have two software applications (or clients ) loaded onto your system. These clients include the Juniper Netconnect client and the CyberGatekeeper agent for Windows XP and Windows 7 users only. For non-fidelity assets only, anti-virus software is required and it NOT included in the package. The software would need to be obtained separately by the Trusted Partner or BU Sponsor. Symantec AntiVirus Corporate Edition (SAV) 10.x., Symantec Endpoint Protection v.11 Corporate Edition, or McAfee Total Protection 2010 or 2011 are approved versions of anti-virus software for accessing Fidelity s network. Do I have to uninstall any existing software on my Computer? If you are an existing Trusted Partner, you do not need to uninstall the existing Nortel TPA client software. It is recommended to keep the old client until access has been validated successfully to the new Juniper Trusted Partner environment. Do I need a Firewall if I am using a Cable or DSL connection? No firewall is required at this time. You will be notified in the future when a Software Firewall will be required. If you have trouble with the installation tasks, contact the Help Desk at 800-525-3274 1
Log-in to Fidelity and Test the Installation Install Trusted Partner Access Software Before You Begin Before you get started installing Trusted Partner Access, make sure that you have the following: You ll need approximately 20 minutes to completely install & set up Trusted Partner Access. Your Desktop or Laptop MUST be running a build of Windows XP/SP3 or Windows 7. Run the Trusted Partner Access Auto-Installation Program To install the new Trusted Partner Access 1. Close any open applications. 2. Login to your workstation as Administrator. (You must have administrative privileges to install Trusted Partner Access components unless you are onsite and can utilize the SSI links). 3. There is one package which will auto-detect your OS and install the correct version for you. The package can be downloaded from https://remote.fidelity.com Download the file and save it locally. 4. Please disconnect from any existing VPN connections to Fidelity before running the new package. 5. - XP users: Locate the downloaded file, Fid-TPA.EXE, and double-click on it to begin the installation process - Windows 7 users: Right-click on the downloaded file, Fid-TPA.EXE, and select the option to run as administrator.to begin the installation process. You must do this even if you are logged in as an administrator. NOTE: During the installation process, you may receive one or more pop-ups as shown on the following page. Please take the recommended action specified for each. If you have trouble with the installation tasks, contact the Help Desk at 800-525-3274 3
Trusted Partner Access Installation Guide Select the option to allow it to run Select the option to Run this ActiveX control Select Always 4
Log-in to Fidelity and Test the Installation Log In to Fidelity and Test the Installation Test that the software is working correctly Follow this process each time you connect remotely to the Fidelity network. Overview of the Log-In Process Steps to test the software that you have installed and configured. Connect to the Fidelity Access Trusted Partner Portal http://trustedpartner.fidelity.com or click on the desktop icon for Trusted Partner Access Select the option for Full Client Access Identify Yourself as a Valid Fidelity User Login with your Hard Token credentials Access the Applications on Fidelity s Network Login to applications on Fidelity s Network which are permitted for your profile If you have trouble with the installation tasks, contact the Help Desk at 800-525-3274 5
Trusted Partner Access Installation Guide Connect to the Trusted Partner Portal NOTE: There is one URL: http://trustedpartner.fidelity.com To access Fidelity s Trusted Partner Portal, click on the Trusted Partner desktop icon or enter the URL in your browser. At the login screen, select Full Client Access by clicking on the associated token icon 6
Log-in to Fidelity and Test the Installation Identify Yourself as a Valid Fidelity User To authenticate as a valid user Enter your Username (PPID or Corpid) and Password (token pin plus 6 digits from your hard token) At the landing page, click on the button labeled Start to launch NetConnect If you have trouble with the installation tasks, contact the Help Desk at 800-525-3274 7
Trusted Partner Access Installation Guide Netconnect will launch To confirm you, you should see the Juniper NetConnect icon in your systray 8
Log-in to Fidelity and Test the Installation Session Status and Disconnecting: Double-click the icon to open a window to provide information about your NetConnect session. This will also allow you to disconnect. In the event of issues, you may be asked to open this window to provide the assigned IP address. To disconnect gracefully, select Sign Out from this screen or right-click on the icon in your systray and select Sign Out. If you have trouble with the installation tasks, contact the Help Desk at 800-525-3274 9
Trusted Partner Access Installation Guide Access applications on Fidelity s Network You will have access to only the applications provided to you by your Fidelity Business Unit Sponsor Accessing applications Application access to servers or logins to servers MUST be obtained by the Fidelity Business Unit sponsor. The Fidelity Remote Access Team is NOT responsible for getting username and passwords for applications/devices on the network. 10
Appendix Log-in to Fidelity and Test the Installation Terms Used in this Guide Trusted Partner Access is a Fidelity (Internet Based) remote access product, which gives Trusted Partners (non-full-time employees) access to applications and devices on Fidelity s Network. These applications must be specifically requested through the Trusted Partner website http://trustedpartner.fmr.com. This product must be installed on a Windows XP or Windows 7 build. VPN, or Virtual Private Networking, is the common term for software used to ensure secure communications over the Internet. VPN is sometimes referred to as a tunnel. Juniper NetConnect is the Fidelity-chosen VPN software used for this purpose. SSL VPN This is the new software package that will allow Trusted Partners to access Fidelity from behind a Corporate Firewall. ISP is a common abbreviation for Internet Service Provider, which provides connectivity to the Internet. AT&T Global Dialer maybe the ISP provided by Fidelity; however you may choose to use another ISP like a broadband provider who provides Cable Internet Access or DSL. A Hard Token is a small, separate device which generates a unique code which is combined with the user s secret PIN to allow secure access onto the Fidelity network. CGK, or CyberGateKeeper, increases our security by requiring all Trusted Partner Access users to follow a new procedure to access the network. This process will install the InfoExpress CyberGatekeeper product providing a method to enforce policy management for our remote access users who access Fidelity's enterprise network using Virtual Private Networking (VPN). CyberGatekeeper will provide a mechanism to determine whether remote access system configurations are in compliance with Corporate Security standards, and if not will stop potentially harmful systems from accessing Fidelity s network If you have trouble with the installation tasks, contact the Help Desk at 800-525-3274 11