Kaspersky Embedded Systems Security for Linux

Installing Kaspersky Embedded Systems Security using the Web Console

Kaspersky Security Center Web Console supports the following main deployment methods:

Installation process consists of the following steps:

  1. Creating an . The Protection Deployment Wizard creates the package automatically if it has not already been created. The installation package is located in the list of installation packages downloaded into the Kaspersky Security Center Web Console: Device discovery and deploymentDeployment and assignmentInstallation packages. You can also create an installation package and configure its settings manually.
  2. Creating a remote installation task. The Protection Deployment Wizard creates and runs the remote installation task automatically. You can also create and run the task manually.

In this section

Creating an installation package

Installation using the Protection Deployment Wizard

Creating a remote installation task

Page top
[Topic 202117]

Creating an installation package

To create an installation package:

  1. In Web Console main window, select Device discovery and deploymentDeployment and assignmentInstallation packages.

    This opens a list of installation packages downloaded to Web Console.

  2. Click Add.

    The wizard for creating an installation package will start. Follow the instructions of the Wizard.

  3. At the first page of the Wizard, select Create installation package for Kaspersky application.

    The Wizard will create an installation package from the distribution kit residing on Kaspersky servers. The list is updated automatically as new versions of applications are released. It is recommended to select this option to install Kaspersky Embedded Systems Security.

    You can also create an installation package from a file.

    Kaspersky Security Center Cloud Console does not allow creation of installation packages from a file.

  4. Select Kaspersky Embedded Systems Security distribution package. Information about the distribution kit will be displayed on the right.
  5. Read the information and click the Download and create installation package button. The installation package creation process starts.
  6. During creation of the installation package, accept the terms of the End User License Agreement and Privacy Policy. When prompted by the Wizard, read the License Agreement between you and Kaspersky and the Privacy Policy that describes the processing and transmission of data. To continue creating the installation package, you must confirm that you have read and accept the full terms of the End User License Agreement and the Privacy Policy.

The installation package will be created and added to the Web Console. Using the installation package, you can install the application on devices in the corporate network or update the application version.

In the installation package properties, you can also configure the application installation settings (see the table below) on the Settings tab.

An installation package for Kaspersky Embedded Systems Security cannot be configured in Kaspersky Security Center Web Console versions lower than 14.2. Use the autoinstall.ini configuration file to configure settings.

Installation package settings

Section

Description

Specify the locale.

Select this check box to specify the locale used during the application operation. Locale in the format specified by RFC 3066. If this setting is not specified, the default locale is used.

Activate the application

Select this check box to specify the activation code.

Update source

Specify the update source:

  • Kaspersky update servers.
  • Kaspersky Security Center Administration Server.
  • Other source in the local or global network.

Run update task after installation.

Select this check box to run the Update task after the application is installed.

Specify proxy server settings

Select this check box to specify the address of the proxy server used to connect to the Internet.

Install kernel source

Select this check box to automatically start of kernel module compilation.

Use GUI

Select this check box to enable the use of the graphical user interface.

Page top

[Topic 247278]

Installation using the Protection Deployment Wizard

The TCP ports 139 and 445, and the UDP ports 137 and 138 must be opened on a client device.

To deploy Kaspersky Embedded Systems Security:

  1. In Web Console main window, select Device discovery and deploymentDeployment and assignmentProtection Deployment Wizard.

    The Protection Deployment Wizard starts.

  2. Follow the instructions of the Protection Deployment Wizard.

Step 1. Selecting an installation package

At this step, select the Kaspersky Embedded Systems Security installation package from the list of installation packages. If the package is not available in the list, click Add and select the Kaspersky Embedded Systems Security distribution kit from the list. The installation package is created automatically.

You can configure the installation package settings using the Web Console.

Step 2. Application activation

At this step, you can add a license key to the installation package to activate the application. This step is optional. If the Administration Server contains a license key with automatic distribution functionality, the key will be automatically added later. You can also activate the application later using the Add Key task.

Step 3. Selecting a Network Agent

At this step, select the version of the Network Agent that will be installed together with Kaspersky Embedded Systems Security. The Network Agent facilitates interaction between the Administration Server and client devices. If the Network Agent is already installed on the device, it is not installed again.

Step 4. Selecting devices to install the application

At this step, select the devices to install the application. The following options are available:

  • Specify an administration group. The task is assigned to the devices included in a previously created administration group.
  • Specify a device selection. The task is assigned to devices included in the device selection. You can specify one of the existing device selections.

Step 5. Configuring advanced installation settings

At this step, configure the following advanced application installation settings:

  • Force installation package download. Selecting the application installation method:
    • Using the Network Agent. If the Network Agent is not installed on the device, first the Network Agent is installed using the operating system tools. Then, Kaspersky Embedded Systems Security is installed by means of the Network Agent.
    • Using operating system resources through distribution points. The installation package is delivered to the client devices using the operating system tools via the distribution points. You can select this option if there is at least one distribution point in the network. A distribution point is a device with Network Agent installed that is used for update distribution, remote installation of applications, and retrieval of information about devices in the network. For more details about distribution points, refer to Kaspersky Security Center documentation.
    • Using operating system resources through Administration Server. Files are delivered to the client devices by means of the operating system tools using the Administration Server. You can select this option if the Network Agent is not installed on the client device, but this device belongs to the same network as the Administration Server.
  • Do not re-install the application if it is already installed. Clear this check box if you want to install an earlier version of the application, for example.
  • Assign package installation in the Active Directory group policies. Kaspersky Embedded Systems Security is installed by means of the Network Agent or manually by means of Active Directory. To install Network Agent, the remote installation task must be run with domain administrator privileges.

Step 6. Device restart management

At this step, you can select an action to be performed if the device restart is required. When installing the application, device restart is not required. Restart is required only if you have to remove incompatible applications before installation. Restart may also be required when updating the application version.

Step 7. Removing incompatible applications

This step is displayed if applications incompatible with Kaspersky Embedded Systems Security are installed on the client device.

At this step, carefully review the list of incompatible applications and allow the removal of these applications. If incompatible applications are installed on the client device, Kaspersky Embedded Systems Security installation finishes with an error.

Step 8. Assigning to an administration group

At this step, select an administration group where to move the client devices after the Network Agent installation. Moving devices to the administration group is necessary for applying policies and group tasks. If a device is already assigned to an administration group, it will not be re-assigned. If you do not select an administration group, the devices are added to the Unassigned devices group.

Step 9. Selecting an account for accessing the client devices

At this step, select the account used for installing Network Agent using the tools of the operating system. In this case, administrator rights are required for accessing the client device. You can add multiple accounts. If an account does not have sufficient rights, the Installation Wizard uses the next account. If you install Kaspersky Embedded Systems Security by means of the Network Agent, you do not have to select an account.

Step 10. Starting installation

Exiting the Wizard. The remote application installation task is started automatically. You can monitor the task execution progress in the task properties in the Results section.

Page top
[Topic 202118]

Creating a remote installation task

To create a remote installation task:

  1. In the main window of Web Console, select DevicesTasks.

    The list of tasks opens.

  2. Click Add.

    The Task Wizard starts.

  3. Follow the Task wizard instructions.

Step 1. Configuring general task settings

At this step, configure the general settings of the task:

  1. In the Application drop-down list, select Kaspersky Security Center.
  2. In the Task type drop-down list, select Install application remotely.
  3. In the Task name field, enter a short description.
  4. In the Select devices to which the task will be assigned section, select the task scope.

Step 2. Selecting devices to install the application

At this step, select the devices where to install Kaspersky Embedded Systems Security according to the selected task scope.

Step 3. Configuring an installation package

At this step, configure the settings of the installation package:

  1. Select Kaspersky Embedded Systems Security 3.3 for Linux installation package.
  2. Select the Network Agent installation package.

    The selected version of the Network Agent will be installed together with Kaspersky Embedded Systems Security. The Network Agent facilitates interaction between the Administration Server and client devices. If the Network Agent is already installed on the device, it is not installed again.

  3. In the Force installation package download section, select the application installation method:
    • Using the Network Agent. If the Network Agent is not installed on the device, first the Network Agent is installed using the operating system tools. Then Kaspersky Embedded Systems Security is installed by means of the Network Agent.
    • Using operating system resources through distribution points. The installation package is delivered to the client devices using the operating system tools via the distribution points. You can select this option if there is at least one distribution point in the network. For more details about distribution points, refer to Kaspersky Security Center documentation.
    • Using operating system resources through Administration Server. Files are delivered to the client devices by means of the operating system tools using the Administration Server. You can select this option if the Network Agent is not installed on the client device, but the client device belongs to the same network as the Administration Server.
  4. In the Maximum number of concurrent downloads field, set a limit on the number of installation package download requests sent to the Administration Server. The limit on the number of requests allows avoiding network overload.
  5. In the Maximum number of installation attempts field, specify the limit on the number of attempts to install the application. If the application installation finishes with an error, the task will automatically start installation again.
  6. If necessary, clear the Do not install application if it is already installed check box. It allows, for example, to install one of the previous versions of the application.
  7. If necessary, select the Assign package installation in Active Directory group policies check box. The application is installed by means of the Network Agent or manually by means of Active Directory. To install Network Agent, the remote installation task must be run with domain administrator privileges.
  8. If necessary, select the Prompt users to close running applications check box. Application installation requires device resources. For the convenience of the user, the Installation Wizard prompts you to close running applications before starting the installation. This helps prevent disruptions in the operation of other applications and prevents possible malfunctions of the device.
  9. In the Behavior of devices managed by other Administration Servers section, select Kaspersky Embedded Systems Security installation method. If the network has more than one Administration Server installed, these Administration Servers may see the same client devices. This may cause, for example, an application to be installed remotely on the same client device several times through different Administration Servers, or other conflicts.
  10. If necessary, in the Device moving mode section, specify a group for moving unassigned devices.

Step 4. Device restart management

At this step, you can select an action to be performed if the device restart is required.

Step 5. Selecting an account to access the device

At this step, select the account used for installing Network Agent using the tools of the operating system. In this case, administrator rights are required for accessing the device. You can add multiple accounts. If an account does not have sufficient rights, the Installation Wizard uses the next account. If you install Kaspersky Embedded Systems Security by means of the Network Agent, you do not have to select an account.

Step 6. Completing task creation

Complete wizard operations by clicking the Create button. A new task will be displayed in the list of tasks. To run a task, select the check box next to the task and click the Start button. The application will be installed in silent mode.

Page top
[Topic 202124]