Kaspersky Security Center

Network Agent policy settings

2024年5月6日

ID 219894

Expand all | Collapse all

To configure the Network Agent policy:

  1. In the main menu, go to 资产(设备)策略和配置文件.
  2. Click the name of the Network Agent policy.

    The properties window of the Network Agent policy opens. The properties window contains the tabs and settings described below.

Consider that for Linux and Windows-based devices, various settings are available.

常规

On this tab, you can modify the policy name, policy status and specify the inheritance of policy settings:

  • In the 策略状态 block, you can select one of the following policy modes:
    • 活动策略
    • 非活动策略
  • In the 设置继承 settings group, you can configure the policy inheritance:
    • 从父策略继承设置
    • 在子策略中强制继承设置

事件配置

On this tab, you can configure event logging and event notification. Events are distributed according to importance level in the following sections:

  • 功能失败
  • 警告
  • 信息

In each section, the list shows the types of events and the default event storage period on the Administration Server (in days). After you click the event type, you can specify the settings of event logging and notifications about events selected in the list. By default, common notification settings specified for the entire Administration Server are used for all event types. However, you can change specific settings for the required event types.

For example, in the 警告 section, you can configure the 发生了安全问题 event type. Such events may happen, for instance, when the free disk space of a distribution point is less than 2 GB (at least 4 GB are required to install applications and download updates remotely). To configure the 发生了安全问题 event, click it and specify where to store the occurred events and how to notify about them.

If Network Agent detected a security issue, you can manage this issue by using the settings of a managed device.

应用程序设置

设置

In the Settings section, you can configure the Network Agent policy:

  • 仅通过分发点分发文件
  • 事件队列的最大大小(MB)
  • 应用程序被允许在设备上检索策略扩展数据
  • 保护网络代理服务免遭非授权的卸载或终止,并防止设置更改
  • 使用卸载密码

存储库

In the 存储库 section, you can select the types of objects whose details will be sent from Network Agent to Administration Server. If modification of some settings in this section is prohibited by the Network Agent policy, you cannot modify these settings.

  • 已安装应用程序详情
  • 硬件注册表的详细信息

连接

The 连接 section includes three subsections:

  • 网络
  • 连接配置文件
  • 连接计划

In the 网络 subsection, you can configure the connection to Administration Server, enable the use of a UDP port, and specify the UDP port number.

  • In the 连接到管理服务器 settings group, you can configure connection to the Administration Server and specify the time interval for synchronization between client devices and the Administration Server:
    • 同步间隔(分钟)
    • 压缩网络流量
    • 在 Microsoft Windows 防火墙中打开网络代理端口
    • 使用 SSL 连接
    • 以默认连接设置在分发点(如果可用)上使用连接网关
  • 使用 UDP 端口
  • UDP 端口号

In the 连接配置文件 subsection, you can specify the network location settings and enable out-of-office mode when Administration Server is not available. The settings in the 连接配置文件 section are available only on devices running Windows:

  • 网络位置设置
  • 管理服务器连接配置文件
  • 当管理服务器不可用时启用漫游模式

In the 连接计划 subsection, you can specify the time intervals during which Network Agent sends data to the Administration Server:

  • 必要时连接
  • 在指定时间间隔连接

通过分发点的网络轮询

In the 通过分发点的网络轮询 section, you can configure automatic polling of the network. You can use the following options to enable the polling and set its frequency:

  • Zeroconf
  • IP 范围
  • 域控制器

分发点网络设置

In the 分发点网络设置 section, you can specify the internet access settings:

  • 使用代理服务器
  • 地址
  • 端口号
  • 对本地地址不使用代理服务器
  • 代理服务器身份验证
  • 用户名
  • 密码

KSN 代理(分发点)

In the KSN 代理(分发点) section, you can configure the application to use the distribution point to forward Kaspersky Security Network (KSN) requests from the managed devices:

  • 在分发点端启用 KSN 代理
  • 转发 KSN 请求到管理服务器
  • 通过互联网直接访问 KSN 云/KPSN
  • 端口
  • UDP 端口

更新(分发点)

In the 更新(分发点) section, you can enable the downloading diff files feature, so distribution points take updates in the form of diff files from Kaspersky update servers.

重启管理

In the 重启管理 section, you can specify the action to be performed if the operating system of a managed device has to be restarted for correct use, installation, or uninstallation of an application. The settings in the 重启管理 section are available only on devices running Windows:

  • 不重启操作系统
  • 如果必要,自动重启操作系统
  • 提示用户操作
    • 重复提示间隔(分钟)
    • 在该时间后强制重启(分钟)
    • 强行关闭锁定会话中的应用程序

See also:

Scenario: Regular updating Kaspersky databases and applications

Comparison of Network Agent settings by operating systems

Did you find this article helpful?
What can we do better?
Thank you for your feedback! You're helping us improve.
Thank you for your feedback! You're helping us improve.