Install an Access Tier

Installs and configure the Cloud Secure Edge (CSE) Access Tier in your environment
Updated On: Oct 02, 2026

{% include_relative install/incl/netagent-v2.md %}

Overview

The Access Tier is an identity-aware proxy that mediates access between entities on the internet and your internal services. Each Access Tier has a public IP address that is reachable from the internet, and each accepts inbound connections on the following ports:

  • TCP 80 and TCP 443 (Hosted Web Services),
  • TCP 8443 (Infrastructure Services),
  • and UDP 51820 (Service Tunnels).

The core of the Access Tier component is the netagent binary - a light-weight, identity-aware proxy, written in Golang. Netagent runs on Linux servers and is designed to be similar in deployment to open-source proxies such as Nginx.

Download

Download the latest Netagent version here.

Supported OSs

The Access Tier supports the following operating systems (see Choose an Installation Method below for the install options):

{% include supported-os.html component="access-tier" %}

Choose an Installation Method