I would like to offer Kaspersky desktop/server antivirus as part of our managed services. My basic idea is to have a Master Server on a management server of ours, create Groups for each domain we manage, and install a Slave Server at each domain site. I have opened up ports 13000, 14000, and 15000 on a public IP on the Master Server.

I have a couple questions that I have not been able to grok from the documentation:

Do I also have to open up ports on the Slave Server? I got it to work with only the one-side open, but then the Master Server reported it lost connection. If the answer to this question is Yes, that I would think a VPN might be preferable.

I would like the Slave Server to inherit policies and packages, but not to get updates from the Master Server. This could quickly eat up my bandwidth at the Master Server. Can this be done simply?

Thanks, and looking forward to any feedback from similar usage of the Administration Kit.

-e