Kaspersky Anti Targeted Attack Platform

Managing policies of Kaspersky Endpoint Agent for Linux

This section provides instructions for creating a policy for Kaspersky Endpoint Agent for Linux and enabling options in the policy using Kaspersky Security Center Administration Console.

Instructions in this section apply only to Kaspersky Endpoint Agent for Linux.

In this section

Creating a policy for Kaspersky Endpoint Agent for Linux

Enabling options in the policy of Kaspersky Endpoint Agent for Linux

Page top
[Topic 257340]

Creating a policy for Kaspersky Endpoint Agent for Linux

To create a policy for Kaspersky Endpoint Agent in Kaspersky Security Center:

  1. Open the Kaspersky Security Center Administration Console.
  2. In the console tree, open the Policies folder.
  3. Click Create policy.

    The New Policy Wizard starts.

  4. In the Enter group policy name, window, enter the name that will be used to display the new policy in the list of policies.
  5. In the Select policy type, select a Kaspersky Endpoint Agent deployment mode by selecting the Endpoint Detection and Response Expert (KATA EDR) check box.
  6. Click Next.
  7. Do one of the following in all settings windows that are displayed in sequence:
    • To configure application settings from the displayed sections when creating the policy:
      1. Click Configure next to the name of the section.
      2. This opens a window; in that window, modify the relevant settings and click OK.
      3. Click Next.
    • To edit application settings in the displayed sections later, click Next.

    Application configuration involves the following steps:

    • Configuring general proxy server settings.
    • Configuring the integration of Kaspersky Endpoint Agent with KATA Central Node.
  8. In the Target group window, select the Kaspersky Security Center administration group that the new policy must affect:
    1. Click Browse.

      This opens the administration group selection window.

    2. Select an administration group from the list.

      For example, you can select the Managed devices group.

    3. If you want to create a device subgroup in the Managed devices group:
      1. Click New group.
      2. This opens a window; in that window, enter the name of the device subgroup.
      3. Click OK.
    4. Click Next.
  9. In the Create group policy for the program select one of the following policy states:
    • Active policy to activate the policy immediately after creation.
    • Inactive policy to activate the policy later.
  10. Select the Open policy properties immediately after creation if you need to perform additional configuration of the policy right after it is created.
  11. Click Finish.

The policy that you created appears in the list of politics.

Page top

[Topic 257329]

Enabling options in the policy of Kaspersky Endpoint Agent for Linux

When configuring default settings of a Kaspersky Endpoint Agent policy, setting values are saved but not applied until you enable them.

You can enable settings by enabling groups in which the settings reside. In one policy you can enable some groups of settings or all groups of settings.

To enable a group of settings in the Kaspersky Endpoint Agent policy:

  1. Open the Kaspersky Security Center Administration Console.
  2. In the console tree, open the Policies folder.
  3. Select a policy for Kaspersky Endpoint Agent and open its settings window in one of the following ways:
    • Double-click on the name of the policy.
    • In the context menu of the policy, select Properties.
  4. In the opened window, select the Application settings tab.
    1. Select the Other settings subsection.
    2. Select one of the following options for using a proxy server:
      • Do not use proxy server.
      • Use proxy server with specified settings.

      If you selected Use proxy server with specified settings, in the Server name or IP address and Port, enter the address and port of the proxy server to which you want to connect. Port 8080 is used by default.

      Kaspersky Endpoint Agent does not encrypt the connection with the proxy server. You must take steps to make sure the network connection between your proxy server and Kaspersky Endpoint Agent is secure.

      If you want to use NTLM authentication when connecting to the proxy server:

      1. Select the Use NTLM authentication by user name and password.
      2. In the User name field, enter the name of the user whose account will be used for authorization at the proxy server.
      3. In the Password field, enter the password to obtain connection to the proxy server.

      To reveal password characters, click Show to the right of the Password field.

      If you do not want to use the proxy server for addresses internal to the organization, select the Bypass proxy server for local addresses check box.

    3. Click Apply.
  5. Select the KATA integration section.
    1. Go to the General Settings subsection.
    2. In the Data transmission settings group, set the Under policy toggle switch to active.
    3. In the Event transmission period (sec.) field, type 30.
    4. In the Event limit per one package, type 1024.
    5. In the Throttling settings group, set the Under policy toggle switch to active.
    6. Select the Enable throttling check box.
    7. Enter the maximum number of events per hour and the percentage value for events exceeding the limit.
    8. Go to the KATA integration settings subsection.
    9. In the Connection settings group, move the Enforce toggle switch to active.
    10. Select the Enable KATA integration check box.
    11. Enter the address and port of the KATA server in the Address and Port fields.
    12. Select the Use pinned certificate to secure connection check box.
    13. Click Add new TLS certificate.
    14. In the opened window, click Upload and select the server certificate file to set up a secure connection or enter certificate data in the field.
    15. Click Add.
    16. Click Add client certificate.
    17. In the opened window, select the Secure with client certificate check box.
    18. Click Upload and select a client certificate file to set up a secure connection.
    19. In the Cryptographic container password field, enter the password of the client certificate to set up a secure connection.
    20. Select the Apply TTL period for events transmission.
    21. In the TTL period (min.) field, enter the interval for sending synchronization requests.
    22. Click Apply.
  6. Click OK.

Policy settings required by Kaspersky Endpoint Agent are enabled.

Page top
[Topic 257330]