Contacts

Administration of kaspersky endpoint security 10. Installation of Kaspersky Security Center. Installing the administration server

Dear Colleagues! Today I want to tell you about the Kaspersky Anti-Virus Administration System. The thing, I'll tell you, is very interesting.

Using it, you can take control of all computers in your organization in terms of allowing/prohibiting the opening of sites, allowing/prohibiting the launch of programs, including in certain categories (for example, you can prohibit the launch of all browsers except certain ones), allowing/prohibiting connections any equipment - flash drives, hard drives and so on (for example, to prevent users from leaking information), also automate the updating of keys for Kaspersky anti-virus, minimize traffic consumption when updating anti-viruses (after installing KSC and configuring anti-viruses installed on workstations on it, they will be updated from this server, and not from the Internet). To install KSC version 10, according to the technical consultant of Kaspersky Lab in the Volga Federal District - Pavel Alexandrov, Windows OS (not necessarily server) with at least 2-4 GB is suitable random access memory. Recently, the Smart Solutions company conducted a Practical Master Class on laptops, where your humble servant was able to personally familiarize himself with this creation of Kaspersky Lab. Kaspersky Security Center 10, as Pavel said, is provided free of charge for those who own a corporate license for KES (Kaspersky Endpoint Security) 10. Fortunately, we, fellow programmers/system administrators of budgetary institutions of the Republic of Tatarstan, do not need to buy anything - everything we need the tools are available from the GIST network at kav.tatar.ru. And also, for your convenience, colleagues, I post video tutorials kindly provided by Igor Aleksandrovich, a company specialist NovaInTech -> Link to video tutorials on Youtube. If after watching the video you still have any questions, I will be happy to help you on Skype (lisischko).

P.S. You can make your Kaspersky Anti-Virus management server subordinate to the TsIT KSC, I won’t say what advantages this gives - I didn’t do this myself, but it is described on the website kav.tatar.ru

Note1: The list of executable files was not replenished on the server, even by the newly created “Inventory” task, until the checkbox was checked in the “ section Extra options” – “Reports and storage” – Inform the administration server “About running programs” in the Anti-Virus policy.

Note4: From time to time, on computers controlled by KSC, everything starts to freeze. The task manager showed that the system was being loaded by the “Kaspersky Security Center Vulnerability Assessment & Patch Management Component” process (executable file vapm.exe). Analysis of the problem showed that when the system was slowing down, the task “Search for vulnerabilities and required updates” was being performed, transferring this task to manual start and stopping solved the problem. Also, there is an option to uncheck the “run missed tasks” checkbox in the task schedule (without switching the launch to manual mode), but I did not try this option, in view of the decision that this function is unnecessary for us. UPD: not even half an hour had passed after stopping the task and switching its launch mode to manual, when some trigger started it again. There's no time to figure it out. I deleted the “Search for vulnerabilities and required updates” task; you can always add it later.

The article examines the Kaspersky Lab product Kaspersky Endpoint Security and its use in a corporate environment, using the example of our clients

Good day, dear visitor. From the title of the article you already understand that today we will talk about protection. In one of the previous articles, I reviewed a product related to this area of ​​IT, which showed itself well. Today I will tell you about an equally interesting product from Kaspersky Lab, of which we are partners, Kaspersky Endpoint Security. It will be considered in virtual environment Hyper-V, on second generation machines. The server part will be implemented on a domain controller running Windows Server 2012 R2, AD mode Windows Server 2012 R2, and the client part on Windows 8.1.

It is worth noting that we constantly use this product in our IT outsourcing practice.

What is Kaspersky Endpoint Security?

Kaspersky Endpoint Security for Windows offers world-class technology to protect against malware combined with Application Control, Web Control and Device Control, as well as data encryption - all within one application. All functionality is managed from a single console, which simplifies the deployment and administration of a wide range of Kaspersky Lab solutions.

Possibilities:

  • Single application
  • Single console
  • Unified policies

Kaspersky Endpoint Security for Windows is a single application that includes a wide range of critical security technologies, such as:

  • Anti-malware protection (including firewall and intrusion prevention system)
  • Workplace control
  • Program control
  • Web Control
  • Device Control
  • Data encryption

Kaspersky Endpoint Security differs in the set of included modules, containing a different number of modules depending on the edition:

  • STARTING,
  • STANDARD
  • ADVANCED
  • Kaspersky Total Security for business

In our case we will use ADVANCED.

The following features are available as part of the Kaspersky Endpoint Security for Business START solution:

The following features are available as part of the Kaspersky Endpoint Security for Business STANDARD solution:

  • Anti-malware, firewall and intrusion prevention system
  • Workplace control
  • Program control
  • Web Control
  • Device Control

...as well as other Kaspersky Lab technologies to ensure IT security

The following features are available as part of the Kaspersky Endpoint Security for Business ADVANCED and Kaspersky Total Security for Business solutions:

  • Anti-malware, firewall and intrusion prevention system
  • Workplace control
  • Program control
  • Web Control
  • Device Control
  • Encryption
    ...as well as other Kaspersky Lab technologies to ensure IT security.

Architecture

Server part:

  • Administration server Kaspersky Security Center
  • Administration console of Kaspersky Security Center
  • Kaspersky Security Center Network Agent

Client part:

  • Kaspersky Endpoint Security

So let's get started

Installing the administration server

In our case, the administration server will be installed on the AD controller in Windows mode Server 2012 R2. Let's start the installation:

I forgot to clarify, we will use Kaspersky Security Center 10. Let's install full distribution , downloaded from the Kaspersky Lab website, which includes the installation package of Kaspersky Endpoint Security 10, respectively, and Network Agent 10

In the next wizard window, select the path to unpack the distribution and click “Install”.

After unpacking the distribution, we are greeted by the Kaspersky Security Center installation wizard; after clicking the “Next” button, the wizard asks “Network size”, because We will have only two clients, one x86 and the other x64, then we indicate “Less than 100 computers on the network.”



We specify the account under which the “Administration Server” will start. In our case Account domain administrator.



Kaspersky Security Center stores all its data in a DBMS. During installation, the wizard prompts you to install Microsoft SQL Server 2008 R2 Express, or, if you have an already installed DBMS, you can select the name of the SQL server and the name of the database.



At the “Administration server address” stage, the wizard asks you to specify the server address, because Since we have AD installed and DNS integrated, it would be wiser to specify the server name.



After selecting the plugins for management, the installation of Kaspersky Security Center will begin.



After successful installation and the first launch of Kaspersky Security Center, we are greeted by the initial setup wizard, in which we can specify a key, accept the agreement for KSN participation, and specify an email address for notifications.




The update parameters are also specified and a policy with tasks is created.



After installation, the following will be installed on our server:

  • Administration server
  • Administration Console
  • Administration Agent

But Kaspersky Endpoint Security will not be installed. We will perform a remote installation, because... the administration agent is already installed, then we can deploy Kaspersky Endpoint Security to the server. If there is no administration agent and all incoming connections are blocked in the Firewall Windows remote installation will not work. Let's expand the node " Remote installation" and select "Run Remote Installation Wizard". Select the installation package and click the “Next” button



In the “Select computers for installation” window, select the installation option for computers located in administration groups. Then select the server and click the “Next” button.



A system reboot will be required after updating important modules of Kaspersky Endpoint Security, because... The package is new enough that a reboot is not needed. When choosing credentials, let's leave everything as default, i.e. empty. After clicking the “Next” button, we will see the installation progress of Kaspersky Endpoint Security.


Creating groups

Because Since the policies and tasks intended for servers differ from the policies and tasks of workstations, we will create groups corresponding to the type of administration for different machines. Expand the “Managed computers” node and select “Groups”, click “Create a subgroup”. Let's create two subgroups, “Workstations” and “Servers”. From the “Managed computers – Computers” menu, using “drag and drop” or “cut & copy”, move “DC” to the “Servers” group and create a policy and tasks for this group different from the tasks and policies in the “Managed computers” node "

Installing Kaspersky Endpoint Security

To install Kaspersky Endpoint Security remotely, you need to disable UAC during installation. The requirement is “inconvenient”, so we will create a policy in the GPO for Windows Firewall in which we will allow incoming connections according to the following predefined rule “File and Printer Sharing”.

After setup and distribution group policy, let's go to the administration console. Expand the “Administration Server” node and select “Install Kaspersky Anti-Virus”, click “Run Remote Installation Wizard”. In the installation package selection wizard window, select the required package and click “Next”. Select clients in the “Unassigned computers” group and click “Next”.

In the next window, leave everything as default and click “Next”. After the window with choosing a key, the wizard prompts you to ask the user to reboot the system after installation of Kaspersky Endpoint Security is completed, leave it as default and click “Next”. At the step “Deleting does not compatible programs“You can make adjustments, of course, if they are needed. Next, the wizard suggests moving client computers to one of the groups; in our case, moving them to the “Workstations” group.







As we can see, the console “speaks” about the successful installation of Kaspersky Endpoint Security on client stations.



As we can see, after installation, the administration server transferred client machines according to the conditions in the remote installation task.



Kaspersky Endpoint Security on the client machine.


Let's create a policy for client stations in which we will enable “Password protection”; this is necessary, for example, if the user wants to turn off the antivirus.

Let's try to disable protection on the client machine.



Rules for moving computers

On the administration server, you can set movement rules for client computers. For example, let's create a situation in which Kaspersky Endpoint Security will be installed on a newly discovered PC. This is useful in a scenario where an organization has installed a new PC.

To automate the deployment of Kaspersky Endpoint Security, we will define movement rules for computers. To do this, select the “Unassigned computers” node and select the “Configure rules for moving computers to administration groups” item and create a new rule.




In the created rule, the newly detected PC will be added to the “Workstations” group from the specified range of IP addresses.

Next, we will create a task to automatically deploy anti-virus protection for machines on which it is not installed. To do this, select the “Workstations” group and go to the “Tasks” tab. Let’s create a task to install anti-virus protection with the “Immediate” schedule.

So, we see that the client computer has been added to the “Workstations” group.

Let's go to the "Tasks" tab and see that the installation task has started.



Let me remind you that the situation was reproduced on a machine without anti-virus protection (although before that I demonstrated a remote installation on one of them, after that the anti-virus was removed to demonstrate this scenario) and, as you can see, the installation takes place on a machine without anti-virus protection, a machine with anti-virus protection was not touched by the defense. After installing anti-virus protection, the KES policy will be applied to this client computer.

Reports

Reports in Kaspersky Endpoint Security are more than informative. For example, let's look at the report “About versions of Kaspersky Lab programs”.

The report, in some detail, displays information about installed programs Kaspersky Lab. You can see how many agents, client solutions and servers are installed. Reports can be deleted and added. You can also view the status of anti-virus protection using the “Selection of computers”, which helps you conveniently sort computers with infected objects or with critical events.

In conclusion, I would like to say that only a small part of the Kaspersky Lab anti-virus complex was reviewed. The controls are indeed convenient and intuitive. But it is worth noting the enormous workload of client systems during the search for viruses and potential threats; this workload is caused mainly due to heuristic analysis, which requires quite a few resources. The product is very easy to administer and is suitable for both AD and working group. This product has been installed by many of our clients and shows only good results.

That's it, people, peace to you!

The connection gateway is used if it is not possible to establish a direct connection with the Administration Server and the client computer. For example, the Administration Server is located in corporate network, and the client computer is not included in it.

How to install

To install Network Agent locally in connection gateway mode:

  1. Run the installation file on the device that will be the connection gateway.

By default, the installation file is located:
\\<Адрес сервера администрирования>\KLSHARE\Packages\NetAgent_10.4.343.

  1. Review the terms of the License Agreement and check the box I accept the terms of the License Agreement.
  1. Select the installation folder.

  1. Set Server Address and uncheck Allow Network Agent to open a UDP port.

  1. Skip a step Proxy configuration.
  2. Select Use as a connection gateway in the demilitarized zone.

  1. Select Receive from Administration Server.

  1. Set tags if you use them. For more information about using tags, see the article How and why to use tags in Kaspersky Security Center 10.

  1. Skip a step Extra options.
  2. Check the box Run the program during installation.

  1. Click Install.

How to setup

  1. Open Kaspersky Security Center 10.
  2. Open context menu node Managed devices and press Creategroup.

  1. Set a name new group and press OK.

  1. Open Properties node Administration server.
  2. Go to section Update Agents and uncheck Assign update agents automatically.Click Add.

  1. In the field drop-down menu, click Add a connection gateway located in the DMZ at.

  1. Enter the connection gateway address and click OK.

  1. Select the set of devices associated with this connection gateway. Click OK.

During the next network scan, the Administration Server will detect the connection gateway added by IP address and place it in Unassigned devices.

  1. Add a connection gateway to a group External devices created in step 3.
  2. Open Properties node Administration server and go to the section Update Agents. Click Add.
  3. In the field dropdown menu A device that will act as an update agent click Add a device from a group. Add a connection gateway from the group Externaldevices and press OK. Repeat step 8.
  4. Select the added connection gateway and open it Properties.

  1. Go to section Gateway. Check the box Connection Gateway And Initiate the creation of a connection to the gateway from the Administration Server side. Set Gateway address for remote devices, for example, abc-lab.kaspersky.com. Click OK.

You can create a Network Agent policy for the connection gateway. When creating at step Net uncheck the box Use UDP port.

Goal of the work.

This lab is devoted to installing the Security Center anti-virus protection management server.

Preliminary information.

Before you begin installation, you need to decide on the general scenario for deploying anti-virus protection. Two main scenarios offered by Security Center developers:

  • - deployment of anti-virus protection within the organization;
  • - deployment of anti-virus protection of the client organization’s network (used by organizations acting as service providers). The same scheme can be used within an organization that has several remote divisions, computer networks which are administered independently of the head office network.

In data laboratory work the first scenario will be implemented. If you plan to use the second one, you will additionally need to install and configure the Web-Console component. And here we need to talk about the architecture of the Security Center. It includes the following components:

  • 1. Administration server, which performs the functions of centralized storage of information about the LC programs installed in the organization’s network and their management.
  • 2. Network Agent carries out interaction between the Administration Server and LC programs installed on the computer. There are versions of the Agent for different operating systems - Windows, Novell and Unix.
  • 3. Administration Console provides a user interface for managing the Server. The administration console is designed as an extension component to Microsoft Management

Console (MMC). It allows you to connect to the Administration Server both locally and remotely, using local network or via the Internet.

4. Kaspersky Security Center Web-Console is designed to monitor the status of anti-virus protection of the client organization's network, which is managed by Kaspersky Security Center. The use of this component will not be studied in this laboratory workshop.

  • 1. Installation and configuration of the Server and Administration Console.
  • 2. Creation of administration groups and distribution of client computers among them.
  • 3. Remote installation of Network Agent and LC anti-virus programs on client computers.
  • 4. Updating signature databases of LC programs on client computers.
  • 5. Configuring notifications about anti-virus protection events.
  • 6. Launch the on-demand scan task and check the operation of event notifications on client computers.
  • 7. Analysis of reports.
  • 8. Setup automatic installation antivirus programs on new computers on the network.

This lab will cover the implementation of the first stage. In Fig. Figure 5.35 shows a diagram of a laboratory bench simulating a protected network (it was also described earlier in Table 5.4). The goal of this lab is to install the Security Center server and administration console on the AVServ server.

Rice. 5.35.

Table 5.5

Differences in Kaspersky Security Center 9.0 distribution versions

Component

Full

version

version

Administration Server distribution package

Kaspersky Endpoint Security distribution package for Windows

Network Agent distribution package

Microsoft SQL 2005 Server Express Edition

Microsoft. NET Framework 2.0 SP1

Microsoft Data Access Component 2.8

Microsoft Windows Installer 3.1

Kaspersky Security Center System Health Validator

The Security Center distribution package can be downloaded from the link http://www.kaspersky.ru/downloads-security-center. In this case, you can choose the version of the downloaded distribution - Lite or full. In table Table 5.5 lists the differences between the distribution versions for version 9.0, which was used to prepare descriptions of laboratory work. To complete the laboratory you will need full version, since along with the installation of the administration server, the MS SQL Server 2005 Express DBMS will be installed, which is used to store data on the state of anti-virus protection.

Description of work.

After completing the preparatory steps, launch the Security Center installation program on the AVServ server. After the welcome window, you will be asked for the path to save the files needed during the installation process, another welcome window will appear and a window with a license agreement that must be accepted to continue the installation process.

When choosing the installation type, select the “Custom” option, which will allow you to familiarize yourself in detail with the list of installed components and applied settings.

If you select the “Standard” option, then as a result of the wizard, Administration Server will be installed along with the server version of Network Agent, Administration Console, application management plugins available in the distribution package, and Microsoft SQL Server 2005 Express Edition (if it has not been installed previously).

The next step is to select the server components to install (Fig. 5.36). We need to install the Administration Server, and leave this checkbox unchecked.

We will not use Cisco NAC technology, which allows us to check the security of a mobile device or computer connecting to the network.

Also, as part of the laboratory workshop, there are no plans to deploy anti-virus protection on mobile devices (such as smartphones), so we are not currently installing these components.


The selected network size affects the setting of the values ​​of a number of parameters that determine the operation of anti-virus protection (they are listed in Table 5.6). These settings can be changed, if necessary, after installing the server.

You will also need to specify the account under which the administration server will be launched, or agree to the creation of a new account (Fig. 5.37).

In previous versions of Windows (for example, when installing on Windows Server 2003), this window may have a System Account option. Anyway, this entry must have administrator rights, which is required both for creating the database and for subsequent operation of the server.

Table 5.6

Settings based on network size

Parameter / number of computers

100-1000

1000-5000

More

Displaying the slave node in the console tree and virtual Servers administration and all parameters related to slave and virtual Servers

absent

absent

present

present

Displaying Sections Safety in the properties windows of the Server and administration groups

absent

absent

present

present

Creating a Network Agent policy using the Initial Configuration Wizard

absent

absent

present

present

Random distribution of update task launch time on client computers

absent

within 5 minutes

within 10 minutes

within 10 minutes

Rice. 5.37.

The next step is to select the database server to use (Fig. 5.38). To store data, Security Center 9.0 can use Microsoft SQL Server (versions 2005, 2008, 2008 R2, including Express 2005, 2008 editions) or MySQL Enterprise. In Fig. 5.38, A the DBMS type selection window is shown. If selected MySQL server, you will need to specify the name and port number for the connection.

If you use an existing instance of MS SQL Server, you will need to specify its name and the name of the database (by default, it is called KAV). In our laboratory work we will use the recommended configuration, which involves installing MS SQL Server 2005 Express along with the installation of Security Center (Fig. 5.38, b).


Rice. 5.38.

After selecting SQL Server as the DBMS to be used, you must specify the authentication mode that will be used when working with it. Here we leave the default setting - Microsoft Windows authentication mode (Fig. 5.39).

To store installation packages and distribute updates, the administration server will use the folder provided in general access. You can specify an existing folder or create a new one. The default share name is KL8NAKE.


Rice. 5.39.

You also have the option to specify the port numbers used to connect to the Security Center server. By default, TCP port 14000 is used, and for protocol-protected SSL connections- TCP port 13000. If after installation you cannot connect to the administration server, you should check whether these ports are blocked by the firewall Windows screen. In addition to those mentioned above, UDP port 13000 is used to transmit information about shutting down computers to the server.

Next, you will need to specify the method for identifying the administration server. This could be an IP address, DNS or NetBIOS names. The virtual network used for the laboratory workshop has a Windows domain and a DNS server, so we will use domain names (Fig. 5.40).


Rice. 5.40.

The next window allows you to select installed plugins to manage antivirus programs OK. Looking ahead, we can say that the Kaspersky Endpoint Security 8 for Windows product will be deployed, the plugin for which we will need (Fig. 5.41).


Rice. 5.41.

After this, the selected programs and components will be installed on the server. Once the installation is complete, the administration console will launch or, if you unchecked the last window of the installation wizard, launch it from the Start menu -> Programs -> Kaspersky Security Center.

Exercise 1.

In accordance with the description, install the administration server on virtual machine AVServ.

When you launch the console, the initial server setup is performed. In the first step, you can specify activation codes or files license keys for LC antivirus products. If you have a “corporate” key for several computers, with default settings the key will be automatically distributed by the server to client computers.


Rice. 5.42.

You can also agree or refuse to use Kaspersky Security Network (KSN), a remote service that provides access to Kaspersky Lab’s knowledge base about the reputation of files, Internet resources and software.

The next step is to configure settings for notifying the anti-virus protection administrator by e-mail. You must specify the mailing address, smtp-ssrvsr and, if necessary, parameters for authorization on the server (Fig. 5.42). If the laboratory does not have a suitable mail server, you can skip this step and make the settings later.

If you access the Internet through a proxy server, you will need to specify its parameters. After passing this stage it will be completed automatic creation standard policies, group tasks and administration tasks. They will be discussed in more detail in the following labs.


Rice. 5.43.

The next step is to automatically start downloading updates. If the download has started successfully, you can, without waiting for the completion, click the “Next” button and after finishing the initial setup wizard, go to the main window of the Administration Console (Fig. 5.43). It should display that there is one managed computer on the network (along with the administration server, an administration agent was installed on the AVScrv computer), on which there is no antivirus protection. This is considered a critical event.

Task 2.

Perform the initial server setup.

The administration console can be installed separately from the Console folder of the distribution disk by running the Setup program. If you are using a distribution package downloaded from the Internet, then you need to open the folder specified at the beginning of the installation to save the distribution files. By default this is the C:KSC9 ussianConsole folder.


Rice. 5.44.

Task 3.

Install the Security Center administration console on the Stationl .labs.local virtual machine. Check connectivity to the AVServ.labs.local server. To do this, you must indicate its address or name in the console window (Fig. 5.44), and also agree to receive a server certificate (Fig. 5.45).


Rice. 5.45.


Rice. 5.46.

If the connection fails, check whether the ports used to connect to the Security Center server are blocked on the AVScrv server (see above). The setting can be checked through Control Panel: System and Security -> Windows Firewall -> Allow a program to run through Windows firewall. The corresponding resolution settings must be present, see fig. 5.46 (the names of the rules remain as in previous version product - Kaspersky Administration Kit).

The larger the network, the more System Administrator(or IT department) is trying to automate the management of software products. Antivirus software is no exception in this regard.

Many antivirus manufacturers have in their arsenal tools remote administration, today we will talk about a similar solution from Kaspersky Lab.

In general, Kaspersky Security Center is a rather serious application, which definitely cannot be described in one article. Therefore, in this article we will analyze only its deployment.

You can download Kaspersky Security Center. The product itself consists of a server that will need to be deployed, an administration console that can be installed on another computer for remote administration of the server, a web console as an alternative to the usual one, and an administration agent that is installed on client computers and is responsible for communicating anti-virus software with the server.

The server itself must be deployed only on operating systems Windows family. Moreover, the presence of a server edition is not necessary. Systems from XP and higher are supported, but only in the Professional/Enterprise/Ultimate editions. WITH full list Supported systems can be found on the website.

In addition, the server requires MS SQL or MySQL (remote is possible) to operate. If you don’t have a ready-made database server at hand, the Kaspersky Security Center installer will install MS SQL Express itself, which is quite sufficient for most organizations.

So, to deploy the server, download and run installation file(I recommend downloading the full distribution). As a test bench, we selected a computer with an operating system Windows system Server 2012 R2.

You will see a convenient menu in which we are now interested in the “Install Kaspersky Security Center 10” item.

After starting the installation, you will be asked to accept the license agreement and select the installation type. For better control over the installation process, we note the custom installation.

If there is a network mobile devices, you can install a separate component to manage their protection.

Enter the size of your network. This point, however, does not carry any important determining force.

Next, the installation program will ask under which user to run the administration server service. You can specify an existing user with admin rights or allow the installer to create a new one.

The next step is to select a database server. As already mentioned, there are two options here - MS SQL or MySQL. If you do not have a ready-made server, Kaspersky Security Center will carefully deploy MS SQL Express.

At this step in the installation process, you may be in for a small surprise if you do not have the .NET Framework 3.5 SP 1 installed on your system.

Windows Server .NET Framework 3.5 SP 1 is built in as a feature and only needs to be enabled. If you do not have a server room operating system, then you need to go to the Microsoft website and download the installer.

Let's consider the option of enabling the component in Windows Server. To do this, open Server Manager and select “Add roles and features.”

A wizard will launch in which we need to indicate that we are going to install roles or components.


Windows Server Add Roles and Features Wizard

We select our server and skip the selection of roles. In the list of components, find .NET Framework 3.5 Functions and check them.


Adding a Feature to Windows Server

After this, we will return to installing Kaspersky Security Center itself.

We need to select the SQL authentication mode. This can be either a separate account or a current one.

The Kaspersky Security Center server requires a shared folder, which client computers could access to receive updates and installation packages. You can create new folder or specify an existing one.

We indicate the ports through which we will connect to the administration server.

Specify the server address on the network. If the server has and will have a static IP address, you can limit yourself to it. But it’s still more convenient to identify the server by name.

The last step before installation is to select the necessary plugins. Plugins allow you to manage various antivirus products Kaspersky Lab. This is useful if you have a whole “zoo” of versions. Plugins can also be installed later.

Now all that remains is to watch the installation process. Sometimes plugins require you to accept a separate license agreement.

The installation of Kaspersky Security Center is complete.

Now let's go over the initial server setup. The administration console installed with the server looks like this:


Administration console of Kaspersky Security Center

The console can also be installed separately. And it’s even necessary so as not to log into the server every time for routine actions.

The left column lists the servers. For now there is only our newly created server. If you administer several servers, then simply click Add Administration Server.

So, click on the newly created server and the Initial Setup Wizard will launch. You will be asked to activate the program using a code or key. However, this can be done later.

In addition, the master will ask your consent to participate in Kaspersky program Security Network. Essentially, this is another spy on your computers that sends Kaspersky Lab data about what resources you access and where you pick up the infection. This is motivated by the creation of a certain knowledge base. In my opinion, for end user The point of participating in such a program is questionable.

You will also be asked to indicate mailboxes for notifications from Kaspersky server Security Center. You can skip this step.

After all these steps the server will start loading latest versions updates from the network. In the future, you can configure not the Kaspersky Lab server on the Internet as an update source, but an upstream server, if there are several of them on your network.

After downloading updates and polling the network, the wizard will display a successful completion message and offer to run the Deploy Protection on Workstations Wizard.

We will talk about deploying protection on workstations in.

Did you like the article? Share it