How to connect Clients to the Administration Server using the VPN-network?



Kaspersky Administration Kit 6.0


How to connect Clients to the Administration Server using the VPN-network?

Back to "Installation"
2012 Jan 23 ID: 1033

Concerning to Kaspersky Administration Kit 6.0 MP1

Configuration: Administration Server is in the head office, and the Clients are in several local offices. 

You can rectify the problem by: 

  • Creating the Administration Servers hierarchy. In this case in each local office install an Administration Server (locally), connect Clients to this Server and then connect these Servers as slave to the master Server. 

To install the Network Agent: 

1. install in a remote office an Administration Server and connect it to the Administration Server in the head office as slave one – i.e. create the server hierarchy

2. on the slave Server create an installation package for the Network Agent. 

3. create the remote install task based on the package and run this task on all computers of the remote office. 

InformationOnce the Network Agent is installed on client computers, one product deployment task can be created on the master Server and in the task settings check Send to slave Administration Servers – and the task will be performed automatically on all computers of the head and remote offices. 

  • Without the Administration Servers hierarchy. Let's view this variant in details: 

1. Scanning ports 

    • Make sure the UDP-port 15000 is open on the client computers 
    • Make sure the TCP-ports 13000 and 14000 are open on the Administration Server 

These ports are necessary for the normal work of the Network Agent and for force synchronization of the Administration Server and the Client. You can check if the necessary ports are open with the help of netstat

netstat -a 

2. Testing connection of the Client in the local office and the Administration Server in the head office. 

1. Install a Network Agent on a client computer in the local office manually. As connection parameters specify the data of the Administration Server in the head office. 

2. In the Network group on the Administration Server find this client computer and drag it by the mouse to the Groups group. 

3. In the Client's properties on the Applications tab Kaspersky Network Agent must be added to the applications list. It means the Network Agent has successfully connected to the Administration Server and synchronized. 

If it did not occur during approximately 15 minutes, then check if the TCP-ports 14000 and 13000 (SSL-connection) are open on the Server. 

4. To check the feedback (connection is initiated by the Server) force synchronization manually (the Synchronize command from the Client context menu in the console tree). 

You can synchronize manually if the 15000 UDP-port is open on the client computer. 

3. Installing Network Agent on all computers of the local office 

There are three methods to perform this operation: 

1 method: install Network Agent locally on each computer. As an address define the address of the Administration Server in the head office: 

2 method: 

1. temporarily install an Administration Server in the local office 

2. on the slave Server create an installation package for the Network Agent and as Agent connection parameters define the Server parameters in the head office

3. create a product deployment task based on this package and run it on all computers of a remote office. 

4. after the installation process is complete, the slave Administration Server can be deleted. 

InformationClient computers will be connected to the Server in the head office. 

3 method: install the Network Agent remotely on the computers in the local office, using the Administration Server in the head office. You can use the following methods for it: 

      • Install Network Agent using the remote push install task – this tasks allows specifying the range of the IP-addresses of the computers in the local office. 

In this case check if Server is running on the computer and the Simple File Sharing is disabled. 

      • Install Network Agent remotely using login-script 


      • Install Network Agent remotely using MSI – installator


      • Create a self-extracting archive for the Network Agent installation package. Users should run it themselves from the Web-server 


      • Suggest users to run the installer from the shared folder on the Administration Server (Program Files\Kaspersky Lab\Kaspersky Administration Kit\Share\Packages). 

After the Network Agent has been installed, the administrator can fully manage client computers and can install necessary antivirus applications. Files are delivered on remote computers by the Network Agent.

Was this information helpful?
Yes No


Feedback on Technical Support Site

Please let us know what you think about the site design, improvements we could add and any errors we need to eliminate

Send My Website Feedback Send My Website Feedback

Thank you!

Thank you for submitting your feedback.
We will review your feedback shortly.