EndDefend Shield Global Gateway

Shield Deployment & Certificates

Deploy the EndDefend Shield connector on your endpoints and install the latest trusted CA Certificates for secure SSL inspection.

You must be a registered user of EndDefend before deploying these tools. The connectors require an active tenant to route traffic correctly.

1

Download Shield Connectors

Install the lightweight endpoint connector for your operating system.

macOS Connector

Compatible with macOS Ventura (13.0) and later. Apple Silicon (M1/M2/M3) natively supported.

v2.1.4 (Universal Binary) - 45MB

Windows Connector

Compatible with Windows 10 and Windows 11. Requires Administrator privileges for install.

v2.1.4 (64-bit Installer) - 38MB

2

Install CA Certificates

Required to prevent SSL warnings and enable deep packet inspection.

EndDefend Root CA

Updated: September 2026. Valid until 2036.

Installation Instructions:

macOS

  • Double click the downloaded .pem file.
  • Keychain Access will open. Select the System keychain.
  • Double click the imported certificate.
  • Expand Trust, and change "When using this certificate" to Always Trust.

Windows

  • Double click the downloaded .crt file.
  • Click Install Certificate...
  • Select Local Machine and click Next.
  • Place all certificates in the following store: Trusted Root Certification Authorities.
3

Network Configuration

Configure your system or router to forward traffic to the Shield Gateway.

Gateway Settings

Proxy Hostname

gateway.enddefend.com

Port

8081

Once the Shield Connector is installed and the CA certificates are trusted, configure your OS-level proxy settings to route HTTP and HTTPS traffic through the gateway above.

Traffic mapped to this gateway will be deep-inspected according to your tenant's active DLP policies and SaaS blocking rules.

Ensure port 8081 is open in your local firewall outbound rules.