Contents
- Cloud Environment Configuration Wizard in Kaspersky Security Center 13.1 Web Console
- Step 1. Reading information about the Wizard
- Step 2. Licensing the application
- Step 3. Selecting the cloud environment and authorization
- Step 4. Segment polling, configuring synchronization with Cloud and choosing further actions
- Step 5. Configuring Kaspersky Security Network for Kaspersky Security Center
- Step 6. Creating an initial configuration of protection
Cloud Environment Configuration Wizard in Kaspersky Security Center 13.1 Web Console
To configure Kaspersky Security Center by using this Wizard, you must have the following:
- Specific credentials for a cloud environment:
- An IAM role that has been granted the right to poll the cloud segment or an IAM user account that has been granted the right to poll the cloud segment (for work with Amazon Web Services)
- Azure Application ID, password, and subscription (for work with Microsoft Azure)
- Google client email, Project ID, and private key (for work with Google Cloud)
- Plug-in for Kaspersky Endpoint Security for Linux (Web Console plug-in)
- Plug-in for Kaspersky Endpoint Security for Windows (Web Console plug-in)
- Network Agent for Windows
- Network Agent for Linux
- Installation package for Kaspersky Endpoint Security for Linux
- Installation package for Kaspersky Security for Windows Server
The Cloud Environment Configuration Wizard starts automatically at the first connection to Administration Server through Administration Console if you deploy Kaspersky Security Center from a ready-to-use image. You can also start the Cloud Environment Configuration Wizard manually at any time.
To start the Cloud Environment Configuration Wizard manually,
In the main menu, go to DISCOVERY & DEPLOYMENT → DEPLOYMENT & ASSIGNMENT → Cloud Environment Configuration Wizard.
The Wizard starts.
An average work session with this Wizard lasts about 15 minutes.
Step 1. Reading information about the Wizard
Read about the Cloud Environment Configuration Wizard on the Welcome page and click Next to proceed.
Page topStep 2. Licensing the application
This step is displayed only if you are using a BYOL AMI and you have not activated the application with a Kaspersky Security for Virtualization license or a Kaspersky Hybrid Cloud Security license.
Specify the license key and click Next to proceed.
The license key is added to the Administration Server storage.
If you run the Wizard again, this step is not displayed.
Step 3. Selecting the cloud environment and authorization
This section describes features applicable only to Kaspersky Security Center 12.1 or a later version.
Specify the following settings:
Enter your credentials to receive authorization in the cloud environment that you specified.
AWS
If you selected AWS as the cloud segment type, you need an IAM role or an AWS IAM access key for further polling of the cloud segment.
- AWS IAM role assigned to an EC2 instance
Select this option if you have an IAM role with the required rights for the Administration Server.
- AWS IAM user
Select this option if you have an AWS IAM access key. Enter your key data:
- Access key ID
- Secret key
To see the characters that you entered, click and hold the Show button.
Azure
If you selected Azure as the cloud segment type, specify the following settings for the connection that will be used for further polling of the cloud segment:
- Azure Application ID
- Azure Subscription ID
- Azure Application password
To see the characters that you entered, click and hold the Show button.
- Azure storage account name
- Azure storage access key
To see the characters that you entered, click and hold the Show button.
Google Cloud
If you selected Google Cloud as the cloud segment type, specify the following settings for the connection that will be used for further polling the cloud segment:
- Client email address
- Project ID
- Private key
To see the characters that you entered, click and hold the Show button.
The connection that you specified is saved in the application settings.
The Cloud Environment Configuration Wizard allows you to specify only one segment. Later, you can specify more connections to manage other cloud segments.
Click Next to proceed.
Step 4. Segment polling, configuring synchronization with Cloud and choosing further actions
At this step, cloud segment polling starts, and a special administration group for cloud devices is automatically created. The devices found during polling are placed into this group. The cloud segment polling schedule is configured (every 5 minutes by default; you can change this setting later).
A Synchronize with Cloud automatic moving rule is also created. For each subsequent scan of the cloud network, virtual devices detected will be moved to the corresponding subgroup within the Managed devices\Cloud group.
Define the following settings:
If you select the Deploy protection option, the Restarting devices section becomes available. In this section, you must choose what to do when the operating system of a target device has to be restarted. Select whether to restart instances if the device operating system has to be restarted during installation of applications:
Click Next to proceed.
For Google Cloud, you can only perform deployment with Kaspersky Security Center native tools. If you selected Google Cloud, the Deploy protection option is not available.
Step 5. Configuring Kaspersky Security Network for Kaspersky Security Center
Specify the settings for relaying information about Kaspersky Security Center operations to the Kaspersky Security Network (KSN) knowledge base. Select one of the following options:
Kaspersky recommends participation in Kaspersky Security Network.
KSN agreements for managed applications may also be displayed. If you agree to use Kaspersky Security Network, the managed application will send data to Kaspersky. If you do not agree to participate in Kaspersky Security Network, the managed application will not send data to Kaspersky. (You can change this setting later in the application policy.)
Click Next to proceed.
Page topStep 6. Creating an initial configuration of protection
You can check a list of policies and tasks that are created.
Wait for the creation of policies and tasks to complete, and then click Next to proceed. On the last page of the Wizard, click the Finish button to exit.
Page top