Kaspersky Security Center

Adjustment of distribution points and connection gateways

July 8, 2024

ID 92429

A structure of administration groups in Kaspersky Security Center performs the following functions:

  • Sets the scope of policies

    There is an alternate way of applying relevant settings on devices, by using policy profiles. In this case, you set the scope of policies with tags, device locations in Active Directory organizational units, or membership in Active Directory security groups.

  • Sets the scope of group tasks

    There is an approach to defining the scope of group tasks that is not based on a hierarchy of administration groups: use of tasks for device selections and tasks for specific devices.

  • Sets access rights to devices, virtual Administration Servers, and secondary Administration Servers
  • Assigns distribution points

When building the structure of administration groups, you must take into account the topology of the organization's network for the optimum assignment of distribution points. The optimum distribution of distribution points allows you to save traffic on the organization's network.

Depending on the organizational schema and network topology, the following standard configurations can be applied to the structure of administration groups:

  • Single office
  • Multiple small remote offices

Devices functioning as distribution points must be protected, including physical protection, against any unauthorized access.

In this section

Standard configuration of distribution points: Single office

Standard configuration of distribution points: Multiple small remote offices

Assigning a managed device to act as a distribution point

Connecting a Linux device as a gateway in the demilitarized zone

Connecting a Linux device to the Administration Server via a connection gateway

Adding a connection gateway in the DMZ as a distribution point

Assigning distribution points automatically

About local installation of Network Agent on a device selected as distribution point

About using a distribution point as connection gateway

Adding IP ranges to the scanned ranges list of a distribution point

Using a distribution point as a push server

See also:

Scenario: Regular updating Kaspersky databases and applications

Main installation scenario

Did you find this article helpful?
What can we do better?
Thank you for your feedback! You're helping us improve.
Thank you for your feedback! You're helping us improve.