A connection gateway is Network Agent operating in a special mode. Network Agent is a Kaspersky Security Center component that enables interaction between the Administration Server and Kaspersky applications. A connection gateway receives connections from other Network Agents and tunnels them to the Administration Server through its own connection with the Server. Unlike an ordinary Network Agent, a connection gateway may be configured to wait for connections from the Administration Server rather than establishing connections to it.
A connection gateway lets you more efficiently use the security features to protect network infrastructure against potential vulnerabilities.
This topic describes how to configure a connection gateway to connect mobile devices to Kaspersky Security Center Administration Server. The configuration proceeds in the following steps:
This article contains an overview of the scenario. For detailed instructions, refer to the Kaspersky Security Center Help.
Requirements
For a connection gateway to work correctly with mobile devices, the following requirements must be met:
These ports are designed to connect and synchronize mobile devices.
Install Network Agent in the connection gateway role on a host
First, you need to install Network Agent on the selected host device acting in the gateway connection role. You can download a full installation package of Kaspersky Security Center or use a local installation of Kaspersky Security Center.
By default, the installation file is located at: \\<server name>\KLSHARE\PkgInst\NetAgent_<version number>
To install Network Agent in the connection gateway role:
We recommend that you do not clear this check box so your connection remains secured.
This mode simultaneously activates the connection gateway role and tells Network Agent to wait for connections from Administration Server, rather than establish connections to Administration Server.
Network Agent is now installed and configured in the connection gateway role.
Configure the connection gateway on Kaspersky Security Center Administration Server
Once you have installed Network Agent in the connection gateway role, you need to connect it to Administration Server. Administration Server does not yet list the device with the connection gateway among the managed devices because the connection gateway has not tried to connect to Administration Server. Therefore, you need to add the connection gateway as a distribution point to ensure that Administration Server initiates a connection to the connection gateway.
To configure the connection gateway on Administration Server:
The Add distribution point window opens.
Enter the IP address of the connection gateway or enter the name if the connection gateway is accessible by name.
The connection gateway will be saved as a new entry named Temporary entry for connection gateway.
Administration Server almost immediately attempts to connect to the connection gateway at the address that you specified. If it succeeds, the entry name changes to the name of the connection gateway device. This process takes up to five minutes.
While the temporary entry for the connection gateway is being converted to a named entry, the connection gateway also appears in the Unassigned devices group.
For detailed information on configuring the distribution point properties, refer to the Kaspersky Security Center Help.
If the 'CA: true' basic constraint is not set for a custom mobile Administration Server certificate, the same certificate will be used for the connection gateway as for the Administration Server.
The connection gateway is now configured. You can now add new mobile devices by specifying the connection gateway address. New devices will appear on the Administration Server.
To change the mobile device connection address, reissue the mobile certificate with a new connection address specified when configuring the connection gateway (in the Administration Server properties window, select Administration server connection settings → Certificates). For detailed information on reissuing mobile certificates, refer to the Reissuing the mobile Administration Server certificate section.
To make sure mobile devices are synchronized with Kaspersky Security Center on the connection gateway, the connection address you have set when configuring the connection gateway must be specified in the properties of Kaspersky Endpoint Security for Android installation packages.