You are welcome to subscribe to "New articles in Knowledge base" mailing list:

You are visiting our Support Website and we thank you in advance for your participation in this poll and your feedbacks.

Please vote honestly, we will analyze the results and will do our best to improve our service as soon as possible.

 Corporate Support Website Usability Survey:
Navigation quality*
Technical articles efficiency*
Relevance of the article(s) turned out by your query*
Ease of access to relevant information*
Comments

Read the same in:    English  Francais  Deutsch  日本語  Polski  Русский  
Home / Business products /  Administration Kit /  Kaspersky Administration Kit 6.0 MP1/MP2 /  Implementing in network

 
Search :  
Search tips Article ID # :   
 

Kaspersky Administration Kit 6.0 MP1/MP2

 
How to connect Clients to the Administration Server using the VPN-network?
 ID Article: 1033    Other languages:  Francais  Deutsch  日本語  Polski  Русский      Views for 7 days 20    Last modified on 2007 Nov 15 16:10 Printable version

Useful links
 



 

Concerning to Kaspersky Administration Kit 6.0 MP1

Configuration: Administration Server is in the head office, and the Clients are in several local offices.

You can rectify the problem by: 

  • Creating the Administration Servers hierarchy. In this case in each local office install an Administration Server (locally), connect Clients to this Server and then connect these Servers as slave to the master Server.

To install the Network Agent:

1. install in a remote office an Administration Server and connect it to the Administration Server in the head office as slave one – i.e. create the server hierarchy.

2. on the slave Server create an installation package for the Network Agent.

3. create the remote install task based on the package and run this task on all computers of the remote office.

InformationOnce the Network Agent is installed on client computers, one product deployment task can be created on the master Server and in the task settings check Send to slave Administration Servers – and the task will be performed automatically on all computers of the head and remote offices. 

  • Without the Administration Servers hierarchy. Let's view this variant in details:

1. Scanning ports 

    • Make sure the UDP-port 15000 is open on the client computers 
    • Make sure the TCP-ports 13000 and 14000 are open on the Administration Server

These ports are necessary for the normal work of the Network Agent and for force synchronization of the Administration Server and the Client. You can check if the necessary ports are open with the help of netstat:

netstat -a

2. Testing connection of the Client in the local office and the Administration Server in the head office.

1. Install a Network Agent on a client computer in the local office manually. As connection parameters specify the data of the Administration Server in the head office.

2. In the Network group on the Administration Server find this client computer and drag it by the mouse to the Groups group.

3. In the Client's properties on the Applications tab Kaspersky Network Agent must be added to the applications list. It means the Network Agent has successfully connected to the Administration Server and synchronized.

If it did not occur during approximately 15 minutes, then check if the TCP-ports 14000 and 13000 (SSL-connection) are open on the Server.

4. To check the feedback (connection is initiated by the Server) force synchronization manually (the Synchronize command from the Client context menu in the console tree).

You can synchronize manually if the 15000 UDP-port is open on the client computer. 

3. Installing Network Agent on all computers of the local office

There are three methods to perform this operation: 

1 method: install Network Agent locally on each computer. As an address define the address of the Administration Server in the head office: 

2 method:

1. temporarily install an Administration Server in the local office 

2. on the slave Server create an installation package for the Network Agent and as Agent connection parameters define the Server parameters in the head office

3. create a product deployment task based on this package and run it on all computers of a remote office. 

4. after the installation process is complete, the slave Administration Server can be deleted.

InformationClient computers will be connected to the Server in the head office. 

3 method: install the Network Agent remotely on the computers in the local office, using the Administration Server in the head office. You can use the following methods for it:

      • Install Network Agent using the remote push install task – this tasks allows specifying the range of the IP-addresses of the computers in the local office.

In this case check if Server is running on the computer and the Simple File Sharing is disabled. 

      • Install Network Agent remotely using login-script 

 

      • Install Network Agent remotely using MSI – installator

 

      • Create a self-extracting archive for the Network Agent installation package. Users should run it themselves from the Web-server 

 

      • Suggest users to run the installer from the shared folder on the Administration Server (Program Files\Kaspersky Lab\Kaspersky Administration Kit\Share\Packages).

After the Network Agent has been installed, the administrator can fully manage client computers and can install necessary antivirus applications. Files are delivered on remote computers by the Network Agent.


 Did the provided info help you?

                       

 Give your detailed feedback.

 

Kaspersky Lab

Copyright © 1997 - 2009 Kaspersky Lab
Site map  |   Contact us  |   International Support Service  |  Send us a suspected virus
Login Your Personal Cabinet  |   Register  |   FAQ for Personal Cabinet