Initial configuration settings in the Administration Console

In the Kaspersky Security Center Administration Console, you can specify the initial configuration settings for Kaspersky Endpoint Security when creating an installation package or in the installation package properties, in the Settings section. The created installation packages are available in the tree of the Administration Console in the Additional → Remote installation → Installation packages folder.

You can also specify initial configuration settings of the application in the configuration file that is included in the installation package.

Initial configuration settings

Setting

Description

Language of events in KSC

Select the localization language for application events sent to Kaspersky Security Center:

  • System (default) to use the operating system locale.

    If the application cannot detect the locale of the operating system or this locale is not supported, English is used by default.

  • An explicitly specified language.

The application uses the UTF-8 encoding.

The locale of the graphical interface and the application command line is taken from the LANG environment variable. If the application does not support this localization, it defaults to the English localization.

Activation code

If you want to activate the application during installation, enter the activation code.

You can also activate the application after installation.

This setting applies only if the application is used in Standard mode.

Selecting an update source

Clicking the Configure button opens a window in which you can select the databases and application modules update source:

  • Kaspersky update servers (default).
  • Kaspersky Security Center.
  • Other source in the local or global network. If you select this option, enter the address of the update source in the Address field.

This setting applies only if the application is used in Standard mode.

Run database update task after installation

If this check box is selected, after the application is installed, the databases and application modules update task starts. The check box is selected by default.

This setting applies only if the application is used in Standard mode.

Proxy server address

If you use a proxy server to access the internet, enter the address of your proxy server in one of the following formats:

  • <connection protocol>://<IP address of the proxy server>:<port number> if the proxy server connection does not require authentication
  • <connection protocol>://<user name>:<password>@<IP address of the proxy server>:<port number> if the proxy server connection requires authentication

Connecting to a proxy server over HTTPS is not supported.

 

This setting applies only if the application is used in Standard mode.

Install kernel source

If this check box is selected, starting File Threat Protection automatically starts the compilation of the kernel module on operating systems that do not support fanotify. The check box is selected by default.

Use the graphical user interface

Select this check box if you plan to install and use the application graphical interface. Files for installing the graphical interface must be added to the installation package. This check box is cleared by default.

This setting applies only if the application is used in Standard mode.

User with admin role

Enter the user to which you want to assign the admin role. The Administrator role allows managing application settings and task settings in the graphical interface of the application and on the command line without using the sudo command.

Configure SELinux automatically

If this check box is selected SELinux is automatically configured to work with Kaspersky Endpoint Security. The check box is selected by default.

Remove users from privileged groups

Select this check box to automatically remove users from the 'kesladmin' and 'keslaudit' privileged groups before installing the application. This check box is cleared by default.

If the check box is selected and the 'nogroup' group does not exist, the installation fails and you are prompted to manually remove users from privileged groups.

Disable protection components and scan tasks when the application is started for the first time after installation

Select this check box if, after completing the installation process, you want to run the application with protection components and scan tasks disabled.

An installation with protection components disabled can be convenient, for example, in order to reproduce a problem in the operation of the application and create a trace file.

If you enable the necessary components and tasks, the enabled components and tasks will continue to work after the application is restarted.

Use the application in Light Agent mode

Select the check box if you want to use the application in Light Agent mode to protect virtual environments (as part of Kaspersky Security for Virtualization Light Agent).

If this check box is cleared, the application is used in Standard mode. This check box is cleared by default.

The protected virtual machine is used as a server

The role of the virtual machine on which the application will be installed: server or workstation. By default, this check box is selected (the virtual machine is used in the virtual infrastructure as a server).

The setting is applied only if the application is used in Light Agent mode.

Enable VDI protection mode

Select this check box to enable VDI protection mode. This is recommended if you are installing the application on a virtual machine template that will be used to create temporary virtual machines. This check box is cleared by default.

The setting is applied only if the application is used in Light Agent mode.

System event interception

The group of settings contains the Configure button. Clicking this button opens the System event interception settings window. In this window, you can configure the system event interception mechanisms used by the application.

The Interception mechanism line displays the name of the system event interception mechanism used by the application.

This setting is applied only on devices where the operating system supports fanotify and the application is used in standard mode.

Interception mechanism

(System event interception settings window).

Select the system event interception mechanism to be used by the application:

  • Fanotify technology (default). If this option is selected, the application uses fanotify to intercept system events.
  • Updatable kernel module. If this option is selected, an updatable kernel module is installed during application installation. The application uses this module to intercept system events.

This setting is applied only on devices where the operating system supports fanotify and the application is used in standard mode.

If the updatable kernel module fails to start

(System event interception settings window).

Select the action the application performs if the updatable kernel module fails to start:

  • Use fanotify (default). If this option is selected, the application switches to fanotify for system event interception.
  • Disable system event interception If the application does not use system event interception, real-time file scanning is not performed, and the protection level of the device is reduced.

This option is available if the Updatable kernel module interception mechanism is selected.

This setting is applied only on devices where the operating system supports fanotify and the application is used in standard mode.

Page top