You are welcome to subscribe to "New articles in Knowledge base" mailing list:

You are visiting our Support Website and we thank you in advance for your participation in this poll and your feedbacks.

Please vote honestly, we will analyze the results and will do our best to improve our service as soon as possible.

 Corporate Support Website Usability Survey:
Navigation quality*
Technical articles efficiency*
Relevance of the article(s) turned out by your query*
Ease of access to relevant information*
Comments

Read the same in:    English  Francais  Deutsch  日本語  Polski  Русский  
Home / Business products /  Administration Kit /  Kaspersky Administration Kit 6.0 MP1/MP2 /  Implementing in network

 
Search :  
Search tips Article ID # :   
 

Kaspersky Administration Kit 6.0 MP1/MP2

 
How to connect the Clients to the Administration Server via Internet and not using VPN?
 ID Article: 1032    Other languages:  Francais  Deutsch  日本語  Polski  Русский      Views for 7 days 24    Last modified on 2007 Nov 15 16:10 Printable version

Useful links
 



 

Concerning to Kaspersky Administration Kit 6.0 MP1

If VPN is not configured between the head and the local (remote) offices, then to manage remotely Kaspersky Lab's anti-virus applications installed on the computers of the remote office, the following requirements must be met:

1. Administration Server in the head office should have an external IP-address and 13000 and 14000 incoming ports should be opened on it.

WarningIn order to increase the security it is recommended to enable Port forwarding on the server which helped to realize NAT (Network Address Translation).

2. An external IP-address of the master Administration Server should be specified when a Network Agent is being installed on client computers of the remote office. If the installation package is used to install a Network Agent, then an external IP-address is defined manually in the package properties on the Settings tab.

3. Network Agent should be installed on the computers in the remote office.

The Agent can be installed one of the following ways: 

    • 1 method:

1. install in a remote office an Administration Server and connect it to the Administration Server in the head office as slave one – i.e. create the server hierarchy.

2. on the slave Server create an installation package for the Network Agent.

3. create the remote install task based on the package and run this task on all computers of the remote office.

Information Once the Network Agent is installed on client computers, one product deployment task can be created on the master Server and in the task settings check Send to slave Administration Servers – and the task will be performed automatically on all computers of the head and remote offices.

    • 2 method

1. temporarily install an Administration Server in the local office

2. on a slave Server create an installation package for the Network Agent and change in it connection settings of the Administration Server – define parameters of the Server in the head office.

3. create the remote install task based on the package and run this task on all computers of the remote office. Client computers will be connected to the Server in the head office.

4. After the installation process is complete, the slave Administration Server can be deleted.

    • 3 method: install the Network Agent locally on each computer, as an address specify the address of the Administration Server of the head office. Client computers will be connected to the Server in the head office.

 

    • 4 method: install the Network Agent remotely on the computers in the local office, using the Administration Server in the head office. Client computers will be connected to the Server in the head office. 

You can use the following methods for it: 

      • Install Network Agent using the remote push install task – this task allows specifying the range of the IP-addresses of the computers in the local office.

WarningIn this case check if Server is running on the computer and the Simple File Sharing is disabled. 

 

      • Install Network Agent remotely using login-script 

 

      • Install Network Agent remotely using MSI – installer. 

 

      • Create a self-extracting archive for the Network Agent installation package. Users should run it themselves from the Web-server. 

 

      • Suggest users to run the installer from the shared folder on the Administration Server (Program Files\Kaspersky Lab\Kaspersky Administration Kit\Share\Packages).

If you manage client computers remotely via Internet and without VPN:

1. you do not need access to any shared folders on the Administration Server or a client computer.

2. access to the admin$ shared folder on a client computer is needed to install a Network Agent remotely

WarningOnce Network Agent is installed:

 

  • to install the Anti-Virus applications remotely there is no need to open an incoming port 1500 on a client computer. The application is installed by means of Network Agent. 

 

  • to manage the Anti-virus in real-time mode remotely, check the Keep connection checkbox in the properties of the client computer.

 Did the provided info help you?

                       

 Give your detailed feedback.

 

Kaspersky Lab

Copyright © 1997 - 2009 Kaspersky Lab
Site map  |   Contact us  |   International Support Service  |  Send us a suspected virus
Login Your Personal Cabinet  |   Register  |   FAQ for Personal Cabinet