Kaspersky IoT Secure Gateway 1000

Managing the Intrusion Prevention system

July 25, 2022

ID 196195

Kaspersky IoT Secure Gateway can use the built-in Intrusion Prevention System to analyze and filter traffic. For Intrusion Detection purposes, Kaspersky IoT Secure Gateway uses a signature database that is updated when the device firmware is flashed. When a match is found with a signature from the database, Kaspersky IoT Secure Gateway automatically blocks traffic from the IP address from which the attack originated.

The Intrusion Prevention system is disabled by default.

To enable the Intrusion Prevention System:

  1. In the main window of the Kaspersky Security Center Web Console, select Devices → Managed devices.
  2. Click the name of the computer where Kaspersky IoT Secure Gateway is running. If you do not see the computer name in the list, add it to the Managed devices group as described in the section titled "Configuring how events are displayed in the Kaspersky Security Center Web Console".

    The computer properties window opens.

  3. Select the Applications tab.
  4. Click on Kaspersky IoT Secure Gateway.

    This opens a window containing information about Kaspersky IoT Secure Gateway.

  5. Select the Application settings tab.
  6. Select the Network section.
  7. Select the IPS tab.
  8. Flip the toggle switch in the upper part of the window to Intrusion Prevention System is on.
  9. Click the Save button.

To enable the denylist:

  1. In the main window of the Kaspersky Security Center Web Console, select Devices → Managed devices.
  2. Click the name of the computer where Kaspersky IoT Secure Gateway is running. If you do not see the computer name in the list, add it to the Managed devices group as described in the section titled "Configuring how events are displayed in the Kaspersky Security Center Web Console".

    The computer properties window opens.

  3. Select the Applications tab.
  4. Click on Kaspersky IoT Secure Gateway.

    This opens a window containing information about Kaspersky IoT Secure Gateway.

  5. Select the Application settings tab.
  6. Select the Network section.
  7. Select the IPS tab.
  8. Click the Show list button next to the Blacklist heading.

    The Blacklist page opens.

  9. Set the toggle button to Blacklist is enabled.
  10. Click the Save button.

To add an IP address to the authorized list:

  1. In the main window of the Kaspersky Security Center Web Console, select Devices → Managed devices.
  2. Click the name of the computer where Kaspersky IoT Secure Gateway is running. If you do not see the computer name in the list, add it to the Managed devices group as described in the section titled "Configuring how events are displayed in the Kaspersky Security Center Web Console".

    The computer properties window opens.

  3. Select the Applications tab.
  4. Click on Kaspersky IoT Secure Gateway.

    This opens a window containing information about Kaspersky IoT Secure Gateway.

  5. Select the Application settings tab.
  6. Select the Network section.
  7. Select the IPS tab.
  8. Click the Show list button next to the Whitelist heading.

    The Whitelist page opens.

  9. Click the Add button.

    The Edit page opens.

  10. In the IP address (source) field, specify the IP address from which you want to allow traffic.
  11. Click the Save button.

Did you find this article helpful?
What can we do better?
Thank you for your feedback! You're helping us improve.
Thank you for your feedback! You're helping us improve.