Jump to content

Kaspersky Security Center 14: Error synchronizing mobiles to the administration server


Go to solution Solved by DonKid,

Recommended Posts

Hello team,
During our deployment of Kaspersky Endpoint Security for Business - Advanced at a customer's site, we encountered a problem and this problem is that when we install the Kaspersky security for Android agent, the agent can't synchronize with the administration server and we don't see it in the console even though the agent was generated from the console.
Can you help me to solve this problem? 
Sincerely.

Link to comment
Share on other sites

Good day

1. check again the settings of the package that you typed on KSC

Спойлер

image.png.3669fd679d184ef36cb5a1ae4063d88e.png

also check if it hits non-assigned devices after installing the agent

 

2. On the problematic device, check the availability of the KSC server and the ability to connect to port 13000 ... it should turn out something like this. Check if your gray screens are blocking the connection.

Спойлер

image.png.819f0d96924316b2ff692cb4f6bf4c1b.png

 

3. run the utility on the problem device - C:\Program Files (x86)\Kaspersky Lab\NetworkAgent\klcsngtgui.exe  - with administrator rights

Спойлер

image.png.766f4a266dd1b0926ca01c1b931544f9.png

klnagcheck - check if there are any connection errors ... look at the output of the command

Спойлер

image.thumb.png.57b556f1fb9ac6cd6c03256a8bf782d9.png

 

Link to comment
Share on other sites

I'm sorry, this is my mistake, I somehow did not see that we were talking about android ...

ok let's try again ?

I will assume that you have a new installation KSC and you have not yet done any settings for working with mobile devices

 

1. Turn on the display of menu items for working with mobile devices, don't forget to restart the console after enabling

Спойлер

image.thumb.png.54f3b4900cfa51317e1b9c10dc094f33.png

 

2. On the mobile devices tab, enable support for mobile devices, download the necessary distributions and management plugins, create and configure a certificate for connecting mobile devices (will be created during the execution of the wizard). You can manage the certificate settings using the last link in the screenshot

Спойлер

image.thumb.png.eed13e4baec62f7e0d7747cfce326f8e.png

 

3. as a result of the wizard, the service for mobile devices will be enabled, the necessary ports will be opened

Спойлер

image.thumb.png.ce7ac32f9db92f1a95ffde352369fd11.png

and also created a certificate for mobile devices (you can reissue it right there)

Спойлер

image.thumb.png.75dac3188a8941f8cb89f38b8628dff9.png

 

4. if you are using a standalone package to install on your devices, check the address and ports for connecting to your server in the package properties. your connected devices will be grouped by default KSM10 (device discovery tab)

Спойлер

image.thumb.png.61e936b6bef772c5ac4ea2ed38c5b216.png

 

now about connecting devices

first of all, check that the necessary ports are open and listened to by your server, you can use the command as in my first post by connecting the laptop to the local WiFi network (for example) and executing the command

tnc <IP or DNS> -port 13292

accordingly, you need to ensure that all the necessary routes are already in your network and your firewalls allow access on the necessary ports between the client and the server

after connecting, your devices (for sure) will initially go to "unassigned" devices, you will need to create a separate group for them in "managed" devices and move devices there (you can use auto-move rules), also do not forget to create the necessary policies and necessary tasks.

Also, if your clients connect via mobile internet on their devices, you must also ensure that your external firewall forwards all necessary packets on port 13292 (and 17100 for activation) to your KSC

also you can get the app package for your device directly from the store for your android device (look for a client specifically for business, black icon, not green), and configure the connection to the server already at the time of installation and launch of the connection wizard.

Спойлер

image.png.ea66ca7edaff921ab22b36a9468675c0.png

 

 

 

Link to comment
Share on other sites

  • 2 weeks later...

During the deployment we noticed that when we install on the phones, they can't synchronize with the administration server in order to download the defined policies and we don't see them in the console either, even though the setup is blocked from the console.
I need your assistance.
Sincerely.

Screenshot_20230302-111518.png

Capture1.PNG

Capture2.PNG

Link to comment
Share on other sites

Good day

I'm sorry, I've been busy with students.

please tell me, is this particular device that on your screen is trying to connect from the internal network via Wi-Fi, or through a mobile operator.

Спойлер

image.thumb.png.db3f8dc21617ee905f0a2ef3ae93bc32.png

any way

1. If we are connecting through an internal Wi-Fi - make sure that the device (namely, mobile) can resolve the server name specified in your settings, whether your DNS is working correctly. for the duration of the experiment, you can set the server by IP address

2. if you are using a mobile operator, make sure that the serar name you specified is also available from outside and points to your external router, and it has all the necessary rules for port forwarding from outside to the internal server and port 13292.

if the connection is successful, all your devices will be transferred from this list

Спойлер

image.thumb.png.2f68ec32b3063200aded69d4c2af8ae9.png

the "entities" themselves will by default go to the "unassigned" devices and you will need to move them to one of the groups of "managed" devices

they can also be found from the "device discovery" tab, the "KSM10" domain group will be created (same as Workgroup)

Спойлер

image.thumb.png.3a90ee5e1a18180d3e3206e5e0edaefc.png

 

if nothing really helps, as you were advised above, you can contact technical support directly.

 

Link to comment
Share on other sites

The wifi to which the device is connected is in the internal network and in the same subnet as the KSC server.

thank you for your answer however the client has no domain, no firewall. it has only the ISP connection but with all the port openings and others it does not synchronize.

 

Link to comment
Share on other sites

I have the same issue with mobile devices. I've checked all the settings and everything looks right, but it won't sync. I managed to solve it by removing Kaspersky from the device and installing it again. One message that might be relevant is 'Cannot find the device on the Administration Server.' when I try to sync through the Admin Center.

Link to comment
Share on other sites

Please sign in to comment

You will be able to leave a comment after signing in



Sign In Now


×
×
  • Create New...