Install the Okta Privileged Access gateway

Before you begin

Verify that the gateway machine meets these requirements.

  • The gateway machine can download packages from scaleft.com. This applies to both gateway roles.
  • The gateway machine is running the Network Time Protocol (NTP) service and is correctly synchronized to external NTP pool servers. This applies to both gateway roles, because time synchronization matters for each.

The gateway machine needs outbound access to Okta Privileged Access, whichever role it runs. A gateway configured for infrastructure orchestration also picks up its work from Okta Privileged Access, so it can't service database integrations without that access. For the domains and ports, see Okta Privileged Access port requirements.

Also, verify that the gateway machine can reach the resources that you plan to manage through Okta Privileged Access.

  • For server access: Connect directly to your destination servers (also known as SSH target hosts), listen for incoming connections from clients, and provide adequate storage space for your session logs.

  • For database access: Connect to your database instances, on the port that each instance listens on. See Supported database types, versions, and deployment options.

Installation guides

The following installation guides walk you through the steps to install the Okta Privileged Access gateway on various operating systems.

You can install preview releases to test new features or install a production-ready stable release. Preview deployments begin on the release date and are gradually rolled out to all users over the course of one week before the stable release.

Related topics