Kaspersky Endpoint Security for Mac

Prepare for remote installation of Kaspersky Endpoint Security

This section contains information about installation of the Kaspersky Endpoint Security administration plug-in on the Kaspersky Security Center administrator's workstation and installation of Network Agent on the remote computer.

Installation of the Kaspersky Endpoint Security administration plug-in and Network Agent is a prerequisite for installation of Kaspersky Endpoint Security via Kaspersky Security Center.

In this section

Install the Kaspersky Endpoint Security administration plug-in

Install Network Agent locally

Install Network Agent via Kaspersky Security Center

Install Network Agent using the SSH protocol

Page top
[Topic kes127602]

Install the Kaspersky Endpoint Security administration plug-in

The Kaspersky Endpoint Security administration plug-in provides an interface for managing Kaspersky Endpoint Security through Administration Console.

Install the Kaspersky Endpoint Security administration plug-in

  1. On the Kaspersky Security Center administrator's workstation, unpack the archive with the files of the Kaspersky Endpoint Security installation package.
  2. Open the folder with the files of the Kaspersky Endpoint Security installation package.
  3. Double-click klcfginst.exe.

Installation of the Kaspersky Endpoint Security administration plug-in starts.

Important: Before installing the Kaspersky Endpoint Security administration plug-in, close Administration Console on the Kaspersky Security Center administrator's workstation.

Page top
[Topic kes127601]

Install Network Agent locally

Network Agent coordinates the interaction between Administration Server and Kaspersky Endpoint Security installed on computers within the corporate network.

Install Network Agent locally

  1. On the remote computer, open the folder with the Network Agent distribution kit.
  2. Open the Network Agent distribution kit (.dmg file).

    A window with the contents of the distribution kit opens.

  3. In the window with the contents of the distribution kit, double-click Kaspersky Network Agent.
  4. Confirm that you want to install Network Agent by clicking Continue.
  5. In the Introduction window, click Continue.
  6. In the License window, read the text of the Network Agent End User License Agreement between you and AO Kaspersky Lab and do the following:
    • To accept all the terms of the agreement and proceed with the installation, click the Continue button.
    • To print the text of the agreement, click the Print button.
    • To save the agreement as a text file, click the Save button.
  7. In the confirmation window, do one of the following:
    • To proceed with the installation of Network Agent, click the Agree button.
    • To return to the text of the End User License Agreement, click the Read License button.
    • To cancel the installation, click the Disagree button.
  8. In the Preferences window, do the following:
    1. In the Server field, specify the IP address or DNS name of the server on which Kaspersky Security Center is installed.
    2. In the Port field, specify the port number for an unencrypted connection to the server.
    3. In the SSL Port field, specify the port number for an SSL connection to the server.
    4. If you want to launch Network Agent immediately after installation, select the Run after installation checkbox.

    If you do not want to use SSL to connect to the server, deselect the Use SSL checkbox. To proceed with the installation, click the Continue button.

  9. In the Installation Type window, read the information about the drive on which Network Agent will be installed.

    To install Network Agent using the recommended settings, click the Install button and enter the administrator's password to confirm your choice.

    Wait until the Network Agent installer finishes installing the application components.

  10. Click the Close button to quit the installer.
Page top
[Topic kes127603]

Install Network Agent via Kaspersky Security Center

Kaspersky Security Center installs Network Agent on a client computer using an SSH connection.

Before installing Network Agent on a client computer, make sure that the following conditions are met:

  • Kaspersky Security Center Administration Server is deployed on the corporate network.
  • Administration Console is installed on the Kaspersky Security Center administrator's workstation.
  • Remote Login is enabled on remote computers.
  • A dedicated administrator account that will be used to run the remote installation task is created on a remote computer. You can use a domain account for the installation.
  • The sudo password is disabled for the dedicated account.

Create a Network Agent installation package

  1. Start Administration Console of Kaspersky Security Center.
  2. Maximize the Administration Server <Server name> node.
  3. In the console tree, select the Advanced folder, then Remote installation subfolder, and then the Installation packages subfolder.
  4. In the workspace, click the Create installation package button.
  5. In the Select installation package type window, click Create an installation package for Kaspersky Lab application.
  6. In the Defining installation package name window, type the name of the new installation package in the Name field and click Next.
  7. In the Selecting the distribution package for installation window, click the Browse button.
  8. The window for selecting a file for creating the installation package opens.
  9. Open the folder with the contents of the Network Agent installation package and select the klnagent.kud file.

    The Selecting the distribution package for installation window shows the name and version of the application to be installed remotely using the file that has been added.

  10. Click Next.

    The Kaspersky Endpoint Security installation package is created with the specified settings.

  11. In the last window of the wizard, click the Finish button to exit the New Package Wizard.

Create a task for remote installation of Network Agent on a client computer

  1. Start Administration Console of Kaspersky Security Center.
  2. Maximize the Administration Server <Server name> node.
  3. Select the Tasks folder.
  4. In the workspace, start the New Task Wizard by clicking the Create a task button.
  5. Follow the steps of the New Task Wizard below to create a task for remote installation of Kaspersky Endpoint Security on the client computer.

To proceed to the next step of the wizard, click the Next button. To return to the previous step of the wizard, click the  button. To exit the wizard at any step, click the Cancel button.

The appearance of buttons may vary depending on your version of Windows.

Step 1. Select the task type

  1. In the Select the task type window, maximize the Kaspersky Security Center 10 Administration Server node.
  2. Select the Install application remotely task.

Step 2. Select the installation package

In the Select installation package window, do one of the following:

  • If the Network Agent installation package with the required settings has been created previously, select it in the list of installation packages in the upper part of the Select installation package window.
  • If the required installation package has not been created yet, click New to start the New Package Wizard.

Step 3. Configure the installation settings

  1. Select the Using operating system resources by means of Administration server checkbox.
  2. Deselect all other checkboxes.

Step 4. Select an administration group to add computers to after installation

In the Moving to the list of managed computers window, select a group to which computers will be moved after installation if necessary.

Step 5. Define how to select the client computers for which the task will be created

In the Select devices to which the task will be assigned window, select the method you want to use to specify client computers:

  • To select from among computers detected on the network by Administration Server, select the Select networked devices detected by Administration Server option.
  • To specify the IP addresses of computers manually or import the IP addresses of computers from a file, select the Specify device addresses manually, or import addresses from list option.
  • To create a task for a selection of devices based on a preset criterion, select the Assign task to a device selection option.
  • To select computers from a specific administration group, select the Assign task to an administration group option.

Step 6. Select client computers

In the window that opens (Select devices, Device selection, or Select Administration group, depending on the option you selected in the previous step), select the client computers, specify the IP addresses of computers, specify a computer selection, or select the administration group to which the task will be applied.

Step 7. Select the account to run the task

  1. In the Selecting an account to run the task window, select the Account required (for installation without Network Agent) checkbox.
  2. Click the Add button.

    The Account window opens.

  3. Specify the login and password of the dedicated administrator account of a remote computer.
  4. Click OK.

Step 8. Configure the task schedule

  1. In the Configure task scheduling settings window, select the start mode in the Scheduled start drop-down list.
  2. If necessary, configure a scheduled task to start automatically (by specifying the task start date and time).
  3. If you want to run tasks that the application was unable to start according to schedule (for example, because the computer was turned off at the scheduled time), select the Run missed tasks checkbox.

    Kaspersky Endpoint Security starts the task as soon as the obstacle preventing the task from being started is eliminated.

Step 9. Specify the task name

In the Define the task name window, in the Name field, enter the name of the task you are creating.

Step 10. Finish creating the task

In the Finishing creating the task window, do the following:

  1. If you want the task to start as soon as the wizard is finished, select the Run task after Wizard finishes checkbox.
  2. Click the Finish button to close the wizard.
Page top
[Topic kes159648]

Install Network Agent using the SSH protocol

One way to install Network Agent on a remote computer is by using the SSH protocol.

Make sure that the following requirements are met:

  • Kaspersky Security Center Administration Server is deployed on the corporate network.
  • Administration Console is installed on the Kaspersky Security Center administrator's workstation.
  • The Network Agent installation package is created and stored in a shared folder of Administration Server.
  • Remote Login is enabled on the remote computer.
  • The computer account used to install Network Agent is included in sudoers.

For detailed information about installation packages, see Kaspersky Security Center Help.

Install Network Agent using the SSH protocol

  1. Start the SSH client on the administrator's workstation.
  2. Connect to the remote computer.
  3. Connect the shared folder of Administration Server as a network drive on the remote computer. To do this, enter the following commands in the SSH client:

    mkdir /Volumes/KLSHARE

    mount_smbfs //<administrator account>:<password>@<Administration Server IP address>/KLSHARE /Volumes/KLSHARE

    Parameter descriptions:

    • <administrator account> – Name of the administrator account on Administration Server.
    • <password> – Password of the administrator on Administration Server.
    • <Administration Server IP address> – IP address of the server hosting Kaspersky Security Center.
  4. Run the installation script. To do this, enter the following command in the SSH client:

    cd /Volumes/KLSHARE/<klnagent_package_folder>

    where <klnagent_package_folder> is the folder in which the Network Agent installation package is located.

    sudo ./install.sh -r <server> [-s <action>] [-p <port number>] [-l <SSL port number>]

    Parameter descriptions:

    • <action> – Parameter that defines whether or not encryption will be used when establishing the connection between Network Agent and Administration Server. If the value is "0", an unencrypted connection is used. If the value is "1", the connection is established via the SSL protocol (default value).
    • <server> – IP address or DNS name of the server on which Kaspersky Security Center is installed.
    • <port number> – Number of the port that will be used to establish an unencrypted connection to Administration Server. Port 14000 is used by default.
    • <SSL port number> – Number of the port that will be used to establish an encrypted connection to Administration Server using the SSL protocol. Port 13000 is used by default.

    Important: Administrator rights are required for executing this command.

  5. Disconnect the network drive on the remote computer. To do this, enter the following command in the SSH client:

    umount /Volumes/KLSHARE

  6. Check if Network Agent functions properly on the remote computer. To do this, enter the following commands in the SSH client:

    cd /Library/Application\ Support/Kaspersky\ Lab/klnagent/Binaries/

    sudo ./klnagchk

    If the check is successful, Network Agent functions properly.

Page top
[Topic kes127621]