Kaspersky Anti Targeted Attack Platform

Distributed solution and multitenancy mode

You can configure settings of each Central Node component individually or manage several components in a centralized way in distributed solution mode.

The distributed solution is a two-tier hierarchy of servers with Central Node components installed. This structure sets apart a master control server known as the Primary Central Node (PCN) and slave servers known as Secondary Central Nodes (SCN). Interaction of servers requires connecting SCN to PCN.

PCN and SCN scan files and objects using the same technology as the individually managed Central Node component.

The distributed solution allows centralized management of the following functional areas of the program:

  • Users.
  • Alerts.
  • Threat Hunting.
  • Tasks.
  • Prevention.
  • User rules.
  • Storage.
  • Endpoint Agents, including network isolation of hosts.
  • Reports.

If you support multiple organization, you can use the program in the

mode. You can install Kaspersky Anti Targeted Attack Platform on one or more Central Node for each organization. Each organization has its own PCN server and SCN servers connected to it. Each organization can manage the program independently from other organizations. The provider can manage data of several organizations.

For each user account, the number of simultaneous program management sessions is limited to one IP address. If the same user name is used to sign in to the program from a different IP address, the earlier session is terminated.

If you are using the distributed solution and multitenancy mode, the limit is enforced for each PCN and SCN server separately.

kata_distributed

Operation of the program in distributed solution mode

You can use distributed solution and multitenancy mode in the following cases:

  • To protect more than 10,000 hosts in an organization.
  • For centralized management of the program in different departments of the organization;
  • For centralized management of the program on servers of multiple organizations.

After you switch the program to distributed solution and multitenancy mode, license key management is only available on the PCN. All keys added to the SCN before are deleted. Each connected SCN receives a key from the PCN.

You can deploy the program in distributed solution and multitenancy mode in the following scenarios:

  • Install the Central Node component on new servers and assign PCN and SCN roles to those servers.
  • Assign PCN and SCN roles to servers that already have the Central Node component installed.

    In this case you must upgrade the Central Node component to version 3.7.

    Before you switch servers with Central Node components installed to distributed solution mode, review the changes that will be applied to the system after the operating mode is changed. Assigning the PCN role to a server is irreversible.

In this Help section

Distributed mode and multitenancy transition scenario

Modifications of program settings for distributed solution mode and multitenancy

Assigning the PCN role to a server

Assigning the SCN role to a server

Processing SCN to PCN connection requests

Viewing information about organizations, PCN and SCN servers

Adding an organization to the PCN server

Removing an organization from the PCN server

Renaming an organization on the PCN server

Disconnecting an SCN from PCN

Modifications of program settings for disconnecting an SCN from PCN

Decommissioning an SCN server