Hardware and software requirements
Hardware requirements
Kaspersky Industrial CyberSecurity for Networks has the following minimum hardware requirements for computers on which application components will be installed:
- Computer that will perform Server functions:
- CPU: Intel Core i7 or equivalent (highest single-core frequency configurations are recommended)
- RAM: 32 GB
- Free space on the hard drive: 500 GB (SSD is recommended)
- Computer that will perform sensor functions:
- CPU: Intel Core i5 / i7 or equivalent (maximum core configurations are recommended)
- RAM: 8 GB, and an additional 2 GB for each monitoring point on this computer
- Free space on the hard drive: 250 GB (SSD is recommended)
When using sensors, the bandwidth of the dedicated Kaspersky Industrial CyberSecurity network between the Server and each sensor must be at least 50% of the cumulative incoming traffic at the sensor (for all monitoring points of the sensor).
Example: A sensor has two monitoring points. One monitoring point receives 100 Mbit/s of traffic, while the other receives 200 Mbit/s. In this case, the bandwidth of the channel between the sensor and the Server must be at least 150 Mbit/s ((200+100)/2=150). |
Software requirements for Kaspersky Industrial CyberSecurity for Networks 4.0
Kaspersky Industrial CyberSecurity for Networks 4.0 has the following software requirements for computers on which application components will be installed:
- CentOS Stream 8 operating system.
When installing the operating system, it is recommended to allocate the entire hard drive (minus the minimum space required for the boot and swap partitions) to the system (root) partition. To improve the performance of software, you can also mount the /var/ folder to a high-speed hard drive (if you have an additional drive, such as an SSD drive). If you choose to do so, the /var/ folder must be completely mounted to the other drive. Subfolders within the /var/ folder (such as /var/opt/) cannot be mounted to different drives.
- The same version of operating system must be installed on all computers where application components are installed.
- To install application components in the CentOS operating system, the following conditions must be fulfilled:
- Chrony time synchronization package version 3.1 or later is installed.
- The SELinux access control enforcement system is disabled.
- The dnf-utils package is installed.
- Python interpreter version 2.7 is installed.
- A symbolic link to the installed version of the python2 package is configured.
- The python2-pyyaml package is installed.
- To ensure proper functioning of application components on the computer that will perform Server functions, the following conditions must also be fulfilled in the CentOS operating system:
- Python interpreter version 3.6 or later is installed, along with packages supporting the operation of connectors and data conversion scripts (if connectors will also operate on other computers, the packages must also be installed on those computers)
- Mail server is installed (Mail Transfer Agent, MTA) to send emails through the email connector and to send reports by email (for example, Postfix).
- Perl interpreter version 5.10 or later is installed (if Kaspersky Security Center Network Agent is being installed).
For installation of application components, it is recommended to use separate computers on which only software from the operating system is installed. If third-party applications are installed on computers, the performance of components of Kaspersky Industrial CyberSecurity for Networks may be reduced.
You can use the following browsers to connect through the web interface:
- Google Chrome version 105 or later.
- Mozilla Firefox version 104 or later.
- Microsoft Edge version 105 or later.
Kaspersky Industrial CyberSecurity for Networks 4.0 is compatible with Kaspersky Security Center 13.2 and Kaspersky Security Center 14. The Kaspersky Industrial CyberSecurity for Networks administration web plug-in becomes available to use in Kaspersky Security Center 13.2 after you install Kaspersky Security Center Web Console version 13.2.571 and a patch for this application, which enables interaction with the Kaspersky Industrial CyberSecurity for Networks administration web plug-in (patch version: 13.2.571.1). The Kaspersky Industrial CyberSecurity for Networks web plug-in becomes available to use after installing Kaspersky Security Center Web Console.version 14.0.3286. You can request the indicated versions of these programs from your Technical Account Manager (TAM).
Kaspersky Industrial CyberSecurity for Networks supports joint operation with Kaspersky Industrial CyberSecurity for Nodes version 2.6 or later. Integration with Kaspersky Industrial CyberSecurity for Nodes 3.0 and 3.1 is supported (in this mode, Kaspersky Industrial CyberSecurity for Networks receives data from Kaspersky Industrial CyberSecurity for Nodes).
Software requirements for Kaspersky Industrial CyberSecurity for Networks 4.0.1
Kaspersky Industrial CyberSecurity for Networks 4.0.1 has the following software requirements for computers where application components will be installed:
- Astra Linux Special Edition 1.7 operating system: RUSB.10015-01 (operational update 1.7), RUSB.10015-17 or RUSB.10015-37.
When installing the operating system, it is recommended to allocate the entire hard drive (minus the minimum space required for the boot and swap partitions) to the system (root) partition. To improve the performance of software, you can also mount the /var/ folder to a high-speed hard drive (if you have an additional drive, such as an SSD drive). If you choose to do so, the /var/ folder must be completely mounted to the other drive. Subfolders within the /var/ folder (such as /var/opt/) cannot be mounted to different drives.
- The same version of operating system must be installed on all computers where application components are installed.
- To install application components in the Astra Linux Special Edition operating system, the following conditions must be fulfilled:
- The standard operating system components "Internet tools" and "Network services" are installed (in addition to the standard components that are installed by default in the operating system).
- The operating system has an active firewall implemented by the UFW network security configuration application (for automatic configuration of network filtering).
- Repositories containing up-to-date stable versions of installation packages are connected in the operating system (for example, connected repositories on discs containing an update of the installation disc for the operating system and an update of the disc containing development tools).
- The rsync package is installed.
- The libcap2-bin package is installed.
- A symbolic link to the installed version of the python2 package is configured.
- The python-apt package is installed.
- The SSH server package is installed (for centralized installation of application components).
- The en_US.utf8 locale is enabled (on the computer from which the centralized installation of application components will be performed).
- To ensure proper functioning of application components on all computers that will perform Server and sensor functions, the following conditions must be fulfilled in the Astra Linux Special Edition operating system:
- Information streams are allowed without limitations from the capability-based access restriction mechanism (a null capability marker is set for all access objects).
- The closed software environment mechanism is disabled in the operating system.
- To ensure proper functioning of application components on the computer that will perform Server functions, the following conditions must also be fulfilled in the Astra Linux Special Edition operating system:
- Python interpreter version 3.6 or later is installed, along with packages supporting the operation of connectors and data conversion scripts (if connectors will also operate on other computers, the packages must also be installed on those computers)
- The Postgres Pro version 14 DBMS is installed (if the Server uses this DBMS instead of the DBMS from the application distribution kit).
- A mail server is installed (Mail Transfer Agent, MTA) to send emails through the email connector and to send reports by email (for example, Exim 4).
- Perl interpreter version 5.10 or later is installed (if Kaspersky Security Center Network Agent is being installed).
For installation of application components, it is recommended to use separate computers on which only software from the operating system is installed. If third-party applications are installed on computers, the performance of components of Kaspersky Industrial CyberSecurity for Networks may be reduced.
You can use the following browsers to connect through the web interface:
- Google Chrome version 101.
- Mozilla Firefox version 102.
- Microsoft Edge version 101.
- Chromium for Astra Linux version 101.
Kaspersky Industrial CyberSecurity for Networks 4.0.1 is compatible with Kaspersky Security Center 13.2 and Kaspersky Security Center 14. The Kaspersky Industrial CyberSecurity for Networks administration web plug-in becomes available to use in Kaspersky Security Center 13.2 after you install Kaspersky Security Center Web Console version 13.2.571 and a patch for this application, which enables interaction with the Kaspersky Industrial CyberSecurity for Networks administration web plug-in (patch version: 13.2.571.1). The Kaspersky Industrial CyberSecurity for Networks web plug-in becomes available to use after installing Kaspersky Security Center Web Console.version 14.0.3286. You can request the indicated versions of these programs from your Technical Account Manager (TAM).
Kaspersky Industrial CyberSecurity for Networks 4.0.1 supports joint operation with Kaspersky Industrial CyberSecurity for Nodes version 2.6 or later. Integration with Kaspersky Industrial CyberSecurity for Nodes 3.0 and 3.1 is supported (in this mode, Kaspersky Industrial CyberSecurity for Networks receives data from Kaspersky Industrial CyberSecurity for Nodes).