Kaspersky Thin Client

Scenario: Migrating management of Kaspersky Thin Client to a new Kaspersky Security Center Server

October 23, 2023

ID 227035

This section describes the sequence of steps that must be performed by the administrator when connecting a group of devices running Kaspersky Thin Client to a new Kaspersky Security Center Administration Server if this group was previously managed by a different instance of Kaspersky Security Center.

The scenario for configuring Kaspersky Thin Client management when migrating to a new instance of Kaspersky Security Center consists of the following steps:

  1. Installing a new Kaspersky Security Center Administration Server

    Download the Kaspersky Security Center distribution package and install the full version of Kaspersky Security Center on the server. The distribution package for the full version of Kaspersky Security Center includes the Kaspersky Security Center Web Console. We recommend selecting the standard installation. For details on installing Kaspersky Security Center, please refer to the Installation of Kaspersky Security Center section of the Kaspersky Security Center Online Help Guide.

  2. Configuring firewall rules

    If you plan to use the default port to connect the thin client to Kaspersky Security Center, set the rules allowing TCP connections through port 13292 for the operating system firewall of the server on which Kaspersky Security Center is installed. If you plan to use a port other than 13292, set the permissions accordingly. For detailed information on configuring firewall rules, please refer to the relevant documentation on the operating system you are using.

  3. Installing the Kaspersky Security Management Suite web plug-in

    In the Web Console, install the Kaspersky Security Management Suite web plug-in for the new Kaspersky Security Center Administration Server. A ZIP archive containing the web plug-in distribution package is included in the distribution kit.

  4. Preparing ports

    Kaspersky Thin Client uses a mobile protocol to connect to Kaspersky Security Center. On the Kaspersky Security Center Administration Server, enable use of the TCP port that you set up access to in step 2. For details on TCP port enabling on the Kaspersky Security Center Administration Server, see the Modifying the Mobile Device Management settings section of the Kaspersky Security Center Online Help Guide.

  5. Turning on Kaspersky Thin Client

    Turn on Kaspersky Thin Client and wait for the system to load.

  6. Creating an active Kaspersky Security Center policy for Kaspersky Thin Client

    In the previously used Web Console, create an active policy for the group of devices that will be managed through the new instance of Kaspersky Security Center.

  7. Saving the mobile certificate of the new Kaspersky Security Center Administration Server

    Locally save the mobile certificate of the new Kaspersky Security Center Administration Server.

  8. Uploading a reserve certificate in the utilized Kaspersky Security Center Web Console

    Upload the mobile certificate of the new Kaspersky Security Center Administration Server as the reserve certificate in the previously used Kaspersky Security Center Web Console. If necessary, a user certificate for connecting Kaspersky Thin Client to Kaspersky Security Center can be uploaded as a reserve certificate. To do so, you must first create a user certificate and upload it in the Kaspersky Security Center Web Console.

    Wait for Kaspersky Thin Client to fully synchronize with Kaspersky Security Center. The synchronization period (heartbeat) is defined when configuring Kaspersky Thin Client through the Kaspersky Security Center Web Console. After synchronization, devices in the administration group will receive the mobile certificates of the new Kaspersky Security Center Administration Server.

  9. Configuring a connection between Kaspersky Thin Client and the new Kaspersky Security Center

    If a DHCP server is deployed in your enterprise infrastructure and the settings for connecting Kaspersky Thin Client to Kaspersky Security Center are received automatically, use option 224 to define the IP address or domain name of the new Kaspersky Security Center Administration Server and wait for all devices running Kaspersky Thin Client to finish synchronizing with Kaspersky Security Center.

    Devices in the administration group will be connected to the new Kaspersky Security Center Administration Server and you will be able to manage them through the Web Console interface.

    If a DHCP server is not deployed in your enterprise infrastructure, manually configure the connection to the new Kaspersky Security Center in the Kaspersky Thin Client interface.

Did you find this article helpful?
What can we do better?
Thank you for your feedback! You're helping us improve.
Thank you for your feedback! You're helping us improve.