Assigning distribution points manually

Expand all | Collapse all

Kaspersky Security Center Cloud Console enables you to manually assign devices to act as distribution points. We recommend that you Calculating the number and configuration of distribution points of distribution points required for your network.

Distribution point devices running macOS cannot download updates from Kaspersky update servers.

If one or more devices running macOS are within the scope of the Download updates to the repositories of distribution points task, the task completes with the Failed status, even if it has successfully completed on all Windows devices.

Devices functioning as distribution points must be protected, including physical protection, against any unauthorized access.

To manually assign a device to act as distribution point:

  1. In the main menu, click the Administration Server name.

    The Administration Server properties window opens.

  2. On the General tab, select the Distribution points section.
  3. Click the Assign button.
  4. Select the device that you want to make a distribution point.

    When selecting a device, keep in mind the operation features of distribution points and the requirements set for the device that acts as distribution point.

  5. Select the administration group that you want to include in the scope of the selected distribution point.
  6. Click the Add button.

    The distribution point that you have added will be displayed in the list of distribution points, in the Distribution points section.

  7. Select the newly added distribution point in the list to open its properties window.
  8. Configure the distribution point in the properties window:
    • The General section contains the settings of interaction between the distribution point and client devices:
      • SSL port
      • Use multicast
      • IP multicast address
      • IP multicast port number
      • Distribution point address for remote devices
      • Deploy updates
      • Deploy installation packages
      • Run push server
      • Push server port
    • In the Scope section, specify the scope to which the distribution point will distribute updates (administration groups and / or network location).

      If you want to specify an administration group, click the Add group button. In the right pane that opens, select the administration group from the drop-down list, and then click the Add button.

      If you want to specify a subnet, click the Add subnet button. In the right pane that opens, click the Add button, and then specify the subnet name.

      For devices running Windows operating system, the Automatically assign distribution points within this network location description toggle switch is displayed. Network location cannot be determined for devices running other operating systems.

    • In the Source of updates section, you can select a source of updates for the distribution point.
    • If your distribution points use proxy server when connecting to the internet, in the Internet connection settings section, you can specify the following settings:
      • Use proxy server
      • Proxy server address
      • Port number
      • Bypass proxy server for local addresses
      • Proxy server authentication
      • User name
      • Password
    • In the KSN Proxy section, you can configure the application to use the distribution point to forward KSN requests from the managed devices:
      • Enable KSN Proxy on the distribution point side
      • Port
      • Use UDP port
      • UDP port
      • Use HTTPS
      • HTTPS port
    • In the Connection gateway section, you can configure the distribution point to act as a gateway for connection between Network Agent instances and Administration Server if a direct connection cannot be established due to organization of your network. To do this, enable the Connection gateway toggle switch.

      By default, this option is disabled.

      When connecting mobile devices to Administration Server via the distribution point that acts as a connection gateway, you can enable the following options:

      • Open port for mobile devices (SSL authentication of the Administration Server only)
      • Open port for mobile devices (two-way SSL authentication)

      In both cases, the certificates are checked during the TLS session establishment on distribution point only. The certificates are not forwarded to be checked by the Administration Server. After a TLS session with the mobile device is established, the distribution point uses the Administration Server certificate to create a tunnel for synchronization between the mobile device and Administration Server. If you open the port for two-way SSL authentication, the only way to distribute the mobile device certificate is via an installation package.

    • Configure the polling of Windows domains, domain controller, and IP ranges by the distribution point:
      • Windows domains polling

        The section is only displayed for the distribution points running Windows.

      • Domain controller polling
      • IP range polling
    • In the Advanced section, specify the folder that the distribution point must use to store distributed data:
      • Use default folder
      • Use specified folder
    • In the Statistics section you can view statistics on downloading anti-virus databases to the device or statistics on installing packages to the device.
  9. Click the OK button.

The selected devices act as distribution points.

See also:

Ports used by Kaspersky Security Center Cloud Console

Scenario: Discovering networked devices

Page top