Jump to content

Recommended Posts

Posted

Apologies, the title might still be a bit vague as I'm not sure how to express it properly. Currently, my friend has purchased a Kaspersky Endpoint Security - Select license. He has installed Kaspersky Security Center (KSC) on the management server. However, on the client machines, he has installed the Security for Windows Server package (In my case, I only used the Endpoint for Windows package before).

Additional information is that both my client servers or his servers are using the Windows Server operating system.

I want to ask if it is correct for me to only install the Endpoint for Windows version on my servers? And is it correct in terms of the license for my friend to use the Security for Windows Server version? (I also don't see a manual activation option for servers like the Endpoint for Windows version).

And the Task section for these two versions in KSC is also different; I don't see the Scan task for Security for Windows Server. Am I missing any part?

On the server with Security for Windows Server installed, my friend encountered a minor issue where he had to disable the Local Server (TCP) blocking in order to perform scans, even though he had added the IP range of the scanning machine to the exclusion list. I would like to ask if there is any way to resolve this issue? Or have we misconfigured something?

These are some issues I am currently facing and I hope you guys can help me overcome these issues. English is not my native language, so some parts may be difficult to understand. Thank you for your understanding and support. thank you very much.

Posted

If what I read is correct, now the Endpoint app for Windows can also be used on servers

  • Like 1
Posted
15 hours ago, betoO said:

If what I read is correct, now the Endpoint app for Windows can also be used on servers

You are right, I have read it in the document

"Kaspersky Endpoint Security supports core components of the application on computers running the Windows operating system for servers. You can use Kaspersky Endpoint Security for Windows instead of Kaspersky Security for Windows Server on servers and clusters of your organization (Cluster Mode)"

But I still have one question, is there anything noteworthy about the Security for Windows Server version? Have you tried using it? Please give me some advice. Thank you.

And with the KES Select license that my friend currently has, is it the best option to use the Endpoint for Windows version?

Posted (edited)

Good day

I will try to explain

1. Licensing

first of all, familiarize yourself with the capabilities of your license package ...

https://b2b-compare.kaspersky.ru/

unfortunately I found only the Russian version, try using the translation of the page Google Chrome

Спойлер

image.thumb.png.10006f442b41ccb85d01e0542b2e6472.png

you need to understand that the applications you install have a full range of functions, but their activation depends on the type of your license

Select license (as well as other licenses) allows you to use many solutions to protect end devices running different systems

KES - for workstation (7,8,10,11) and Servers

KSWS - for Windows Servers (2008, 2012, 2016, 2019 etc)

IOS

Android

Linux

these are different solutions, however, you will need the same license to activate them, counting licenses by total number of devices, for example...

KES - 5, KSWS -3, Linux - 2, Android -2, iOS - 1 = 13

 

2.what to use for servers - KES or KSWS

in terms of licenses - no difference KSWS - initially better tested for working with servers, and has a completely different set of components than KES. What to use depends on your security approach and functionality requirements.

however, I would like to clarify that at the moment the version of KSWS is 11.0.1 - and its further development is not planned, everything is being replaced by a single KES solution (now KSWS capabilities are being actively added to it), support for the solution will be extended until the end of 2024. Therefore, it is worth thinking about the transition to this solution.

https://support.kaspersky.com/help/KESWin/12.1/en-US/181834.htm

 

3. problems with network blocking of scanners ...

more information is needed here to understand the essence of the problem ... in any case, you can always contact technical support through your personal account

https://companyaccount.kaspersky.com

support is available to all business license users

 

4. local management of the KSWS client (adding keys)

if KSWS is connected to a KSC server, the installation of licenses can be done either automatically or using a task, there is no need to do it manually on each server.

By default, KSWS does not have such a local interface for managing the solution (like KES for example), to connect to the interface, you will need to additionally install the management console ... You can download it from the manufacturer's website (full distribution)

https://www.kaspersky.com/small-to-medium-business-security/downloads/endpoint?icid=ru_sup-site_trd_ona_oth__onl_b2b_klsupport_tri-dl____ksws___

Спойлер

image.thumb.png.32a43d2889306e7d8b9b5b94eeab682f.png

Extract the contents of the archive, and run setup.exe, on the server where you want to install the console, select the appropriate item for installation. It is not necessary to install the console on all servers in the network, the console has the ability to connect remotely to the KSWS solution, you will be asked about this in one of the console installation steps.

Спойлер

image.thumb.png.a096441906ee11cd5b349118f919e827.png

after that you can launch the console from the start menu or tray icons... add or remove a license or configure the settings manually if the device is not connected to the KSC

Спойлер

image.thumb.png.8d15b0d8067b27e2c9cb816d0933342c.png

Спойлер

image.thumb.png.3c3f97db7d029d505a1cdc82335af535.png

Спойлер

image.thumb.png.17f1c37f45ea8f4214649e480ced7159.png

 

5. no ability to create tasks and policies for KSWS

you probably forgot to install the management plugin for the KSWS solution ... it will allow you to customize the solution ... you can install it from KSC

Спойлер

image.thumb.png.8e9eb0c62b237d23aaefe21d93fc4ce8.png

Спойлер

image.thumb.png.b38ef5f8d49cd359eedf240e9976cedb.png

Спойлер

image.thumb.png.29f50a1328b865f97cf3c8dd0ff70278.png

download and run the installation of the plugin, after it is completed, restart the console... you should now be able to pop in and set up policies and tasks

Спойлер

image.thumb.png.a06f3ec586534e7f835f97c4b7c6754b.pngimage.thumb.png.428800246f187237319f9e96b3ba3d97.png

 

6. tasks

for each of the products there is a list of tasks, and if I understand correctly you did not find the virus scan task ... for KSWS this is an on-demand scan

Спойлер

image.thumb.png.804aef751767e57dcf316967ae73018e.pngimage.thumb.png.cd2a1d48f8b90a5c8ef7be92bbdabe01.png

 

sorry for such a long post

Edited by ElvinE5
  • Thanks 1
Posted
2 hours ago, ElvinE5 said:

Good day

I will try to explain

1. Licensing

first of all, familiarize yourself with the capabilities of your license package ...

https://b2b-compare.kaspersky.ru/

unfortunately I found only the Russian version, try using the translation of the page Google Chrome

  Hide contents

image.thumb.png.10006f442b41ccb85d01e0542b2e6472.png

you need to understand that the applications you install have a full range of functions, but their activation depends on the type of your license

Select license (as well as other licenses) allows you to use many solutions to protect end devices running different systems

KES - for workstation (7,8,10,11) and Servers

KSWS - for Windows Servers (2008, 2012, 2016, 2019 etc)

IOS

Android

Linux

these are different solutions, however, you will need the same license to activate them, counting licenses by total number of devices, for example...

KES - 5, KSWS -3, Linux - 2, Android -2, iOS - 1 = 13

 

2.what to use for servers - KES or KSWS

in terms of licenses - no difference KSWS - initially better tested for working with servers, and has a completely different set of components than KES. What to use depends on your security approach and functionality requirements.

however, I would like to clarify that at the moment the version of KSWS is 11.0.1 - and its further development is not planned, everything is being replaced by a single KES solution (now KSWS capabilities are being actively added to it), support for the solution will be extended until the end of 2024. Therefore, it is worth thinking about the transition to this solution.

https://support.kaspersky.com/help/KESWin/12.1/en-US/181834.htm

 

3. problems with network blocking of scanners ...

more information is needed here to understand the essence of the problem ... in any case, you can always contact technical support through your personal account

https://companyaccount.kaspersky.com

support is available to all business license users

 

4. local management of the KSWS client (adding keys)

if KSWS is connected to a KSC server, the installation of licenses can be done either automatically or using a task, there is no need to do it manually on each server.

By default, KSWS does not have such a local interface for managing the solution (like KES for example), to connect to the interface, you will need to additionally install the management console ... You can download it from the manufacturer's website (full distribution)

https://www.kaspersky.com/small-to-medium-business-security/downloads/endpoint?icid=ru_sup-site_trd_ona_oth__onl_b2b_klsupport_tri-dl____ksws___

  Hide contents

image.thumb.png.32a43d2889306e7d8b9b5b94eeab682f.png

Extract the contents of the archive, and run setup.exe, on the server where you want to install the console, select the appropriate item for installation. It is not necessary to install the console on all servers in the network, the console has the ability to connect remotely to the KSWS solution, you will be asked about this in one of the console installation steps.

  Hide contents

image.thumb.png.a096441906ee11cd5b349118f919e827.png

after that you can launch the console from the start menu or tray icons... add or remove a license or configure the settings manually if the device is not connected to the KSC

  Hide contents

image.thumb.png.8d15b0d8067b27e2c9cb816d0933342c.png

  Hide contents

image.thumb.png.3c3f97db7d029d505a1cdc82335af535.png

  Reveal hidden contents

image.thumb.png.17f1c37f45ea8f4214649e480ced7159.png

 

5. no ability to create tasks and policies for KSWS

you probably forgot to install the management plugin for the KSWS solution ... it will allow you to customize the solution ... you can install it from KSC

  Hide contents

image.thumb.png.8e9eb0c62b237d23aaefe21d93fc4ce8.png

  Hide contents

image.thumb.png.b38ef5f8d49cd359eedf240e9976cedb.png

  Hide contents

image.thumb.png.29f50a1328b865f97cf3c8dd0ff70278.png

download and run the installation of the plugin, after it is completed, restart the console... you should now be able to pop in and set up policies and tasks

  Hide contents

image.thumb.png.a06f3ec586534e7f835f97c4b7c6754b.pngimage.thumb.png.428800246f187237319f9e96b3ba3d97.png

 

6. tasks

for each of the products there is a list of tasks, and if I understand correctly you did not find the virus scan task ... for KSWS this is an on-demand scan

  Hide contents

image.thumb.png.804aef751767e57dcf316967ae73018e.pngimage.thumb.png.cd2a1d48f8b90a5c8ef7be92bbdabe01.png

 

sorry for such a long post

Thank you so much, it's been very helpful to me.

I have one more question for KSWS regarding transferring the license key from this machine to another. In the event of a malfunction (data wiped), will the activated key on the machine be automatically removed? Or is there a way to revoke the key from the KSC server?

Currently, I want to apply a new key for 11 client machines (3 of them haven't been activated, while the others are using different keys). After running the 'Task add key,' only the 3 new machines received the key (I checked in the 'Kaspersky Licenses' section on KSC). Thank you once again.

Posted

1. Use of licenses

1.1 You need to understand that licenses are counted only from those devices that are connected to the KSC server. If you install a security solution on the device, activate it manually, but don't install the agent, and don't connect it to the KSC... this license will not be registered on the KSC server. This is not a problem, but excessive abuse of this feature (activating more copies than the license allows) can lead to legal claims, and blocking the active key.

1.2 In the standard scenario, when the client was connected to the KSC server, when removing the security solution (we no longer want to use it, or for example, before decommissioning the device), the network agent will send information to the server that the device no longer has a security solution - in this case, KSC will "release " license by increasing the number of free licenses by one.

1.3 in a scenario where it was not possible to remove the security solution (by standard means) for a reason, let's say that the hard drive failed, the agent did not transfer information to the server, and the license will not be released until information about this device is in the system. To revoke the license, simply remove the destroyed device from the KSC server, twice. First from managed devices, and then from a group of unassigned devices. The server will "forget" this device and release the license by incrementing the free license counter by one.

 

2. Key distribution problem

I will assume that on the remaining devices (those that "did not receive" a new key) the current keys are still active (the validity period has not expired), and you have not unchecked the key distribution task

KSWS

Спойлер

image.thumb.png.57d0b9acd72e8774511404063de09db0.png

KES

Спойлер

image.thumb.png.331599d5ae531a79369451297e389bf6.png

the key has been added, but is not applied to the device until the current (old key) expires. To replace the key with a new one right now, just restart the execution of this task by first unchecking this item.

  • Thanks 1
Posted
On 7/18/2023 at 3:34 PM, ElvinE5 said:

1. Use of licenses

1.1 You need to understand that licenses are counted only from those devices that are connected to the KSC server. If you install a security solution on the device, activate it manually, but don't install the agent, and don't connect it to the KSC... this license will not be registered on the KSC server. This is not a problem, but excessive abuse of this feature (activating more copies than the license allows) can lead to legal claims, and blocking the active key.

1.2 In the standard scenario, when the client was connected to the KSC server, when removing the security solution (we no longer want to use it, or for example, before decommissioning the device), the network agent will send information to the server that the device no longer has a security solution - in this case, KSC will "release " license by increasing the number of free licenses by one.

1.3 in a scenario where it was not possible to remove the security solution (by standard means) for a reason, let's say that the hard drive failed, the agent did not transfer information to the server, and the license will not be released until information about this device is in the system. To revoke the license, simply remove the destroyed device from the KSC server, twice. First from managed devices, and then from a group of unassigned devices. The server will "forget" this device and release the license by incrementing the free license counter by one.

 

2. Key distribution problem

I will assume that on the remaining devices (those that "did not receive" a new key) the current keys are still active (the validity period has not expired), and you have not unchecked the key distribution task

KSWS

  Hide contents

image.thumb.png.57d0b9acd72e8774511404063de09db0.png

KES

  Hide contents

image.thumb.png.331599d5ae531a79369451297e389bf6.png

the key has been added, but is not applied to the device until the current (old key) expires. To replace the key with a new one right now, just restart the execution of this task by first unchecking this item.

I truly appreciate your help in the past few days. It has been very meaningful to me.

Almost all the issues have been resolved.

Thank you once again.

Posted
On 7/18/2023 at 3:34 PM, ElvinE5 said:

1. Use of licenses

1.1 You need to understand that licenses are counted only from those devices that are connected to the KSC server. If you install a security solution on the device, activate it manually, but don't install the agent, and don't connect it to the KSC... this license will not be registered on the KSC server. This is not a problem, but excessive abuse of this feature (activating more copies than the license allows) can lead to legal claims, and blocking the active key.

1.2 In the standard scenario, when the client was connected to the KSC server, when removing the security solution (we no longer want to use it, or for example, before decommissioning the device), the network agent will send information to the server that the device no longer has a security solution - in this case, KSC will "release " license by increasing the number of free licenses by one.

1.3 in a scenario where it was not possible to remove the security solution (by standard means) for a reason, let's say that the hard drive failed, the agent did not transfer information to the server, and the license will not be released until information about this device is in the system. To revoke the license, simply remove the destroyed device from the KSC server, twice. First from managed devices, and then from a group of unassigned devices. The server will "forget" this device and release the license by incrementing the free license counter by one.

 

2. Key distribution problem

I will assume that on the remaining devices (those that "did not receive" a new key) the current keys are still active (the validity period has not expired), and you have not unchecked the key distribution task

KSWS

  Hide contents

image.thumb.png.57d0b9acd72e8774511404063de09db0.png

KES

  Reveal hidden contents

image.thumb.png.331599d5ae531a79369451297e389bf6.png

the key has been added, but is not applied to the device until the current (old key) expires. To replace the key with a new one right now, just restart the execution of this task by first unchecking this item.

Hi Elvin, I apologize for bothering you again.

My current issue is that I have added a key and unchecked the "Use as an additional key" option, but it seems that everything is not going smoothly.

The Task report shows "Completed Successfully," but when I checked the machines, they still haven't received the key!?

I checked each machine by selecting the client machine -> Properties -> Applications -> KSWS -> Properties -> License keys, but the License keys table is completely empty.

I recreated the Task and started over, but it didn't help. Have you ever encountered a similar situation?

Posted

Sometimes this behavior occurs ...

Try on a test machine to go through the KSWS console, and first delete all the keys that are on the server ... then try to re-run the key installation task ... and it should wait until the server receives it on its own (if you have auto-discovery of licenses enabled)

another option is to remove the KSWS solution remotely and install it again...

Posted
2 hours ago, ElvinE5 said:

Sometimes this behavior occurs ...

Try on a test machine to go through the KSWS console, and first delete all the keys that are on the server ... then try to re-run the key installation task ... and it should wait until the server receives it on its own (if you have auto-discovery of licenses enabled)

another option is to remove the KSWS solution remotely and install it again...

I tried to delete unused keys in the Kaspersky License tab, but I couldn't find a place to delete them.

I attempted to delete them through the Web Console, but it still didn't work.

I want to ask about remote KSWS solution deletion, is it similar to removing the entire KSWS from the client machine, or is it just removing the client from the Manage Device and Unassigned Device sections?

Posted
9 минут назад, LouisLewis сказал:

I tried to delete unused keys in the Kaspersky License tab, but I couldn't find a place to delete them.

The keys in the "lab licenses" tab are simply records of available licenses that the server compares with which key you have activated the product (KES for example) on devices, and counts them.

1. Removing their keys from this section will not result in their removal from the client computer.

2. if according to the records of the KSC server, at least one device connected to the server is still using this key, then this key will be marked for deletion (its icon will turn gray) and it will not disappear until no device uses it.

 

24 минуты назад, LouisLewis сказал:

it similar to removing the entire KSWS from the client machine,

Yes, this is equivalent to uninstalling KSWS locally from the device.

 

I meant the following

1. Connect to the server using the KSWS console (I wrote about this earlier)

2. Go to the license section

Спойлер

image.thumb.png.6abb08c7b566f235d9c02105e5c453e5.png

3. remove all licenses well, either wait for auto distribution or try to make it a task

 

 

  • Thanks 1
Posted
On 7/24/2023 at 4:37 PM, ElvinE5 said:

The keys in the "lab licenses" tab are simply records of available licenses that the server compares with which key you have activated the product (KES for example) on devices, and counts them.

1. Removing their keys from this section will not result in their removal from the client computer.

2. if according to the records of the KSC server, at least one device connected to the server is still using this key, then this key will be marked for deletion (its icon will turn gray) and it will not disappear until no device uses it.

 

Yes, this is equivalent to uninstalling KSWS locally from the device.

 

I meant the following

1. Connect to the server using the KSWS console (I wrote about this earlier)

2. Go to the license section

  Reveal hidden contents

image.thumb.png.6abb08c7b566f235d9c02105e5c453e5.png

3. remove all licenses well, either wait for auto distribution or try to make it a task

 

 

I understand now, thank you for supporting me all this time

Please sign in to comment

You will be able to leave a comment after signing in



Sign In Now


×
×
  • Create New...