LUCIDTextjet - Print logo

Kaspersky Security for Internet Gateway Add-On

Short Description

Open HTML

What are the core benefits of Kaspersky Security for Internet Gateway Add-On?
Central console – All gateway nodes managed from one web interface.
Gateway scanning – Checks HTTP, HTTPS and FTP traffic at the proxy.
Web control – Blocks site categories, file types and phishing pages.
Flexible deployment – Virtual appliance or install on existing Linux servers.
SIEM export – Sends each event to syslog for correlation.
Important note – No endpoint protection; needs an existing Kaspersky licence.

Long Description

Open HTML

What is included in Kaspersky Security for Internet Gateway Add-On?

Anti-malware and anti-phishing – Scans traffic passing the proxy and blocks infected downloads.
Web control – Controls access by website category, file type and size.
ICAP integration – Works with any proxy server supporting REQMOD and RESPMOD.
All-in-one appliance – ISO image with a pre-configured Squid proxy included.
Cluster deployment – Add traffic-processing nodes and export events to syslog.
Important – No endpoint or mail server protection is included.

What are the main benefits of Kaspersky Security for Internet Gateway Add-On?

Kaspersky Security for Internet Gateway is a secure web gateway that scans HTTP, HTTPS and FTP traffic passing through a proxy server; its main application is Kaspersky Web Traffic Security, the name many buyers still search for. Every traffic-processing node is managed centrally from the application web interface, not from an endpoint management console.

Fewer endpoint alerts – Threats are stopped before they reach user devices.
Encrypted traffic scanning – Reads HTTPS content once SSL bumping is configured.
Default deny option – Restrict browsing to the resources a group needs.
Scales with traffic – Add processing nodes as bandwidth demand grows.
Directory-based rules – Apply policies per user or group from Active Directory.
Evidence for audits – Every event is written to syslog for SIEM.

Best antivirus? Why Windows Defender alone is not enough
Explains why device-level antivirus leaves gaps that a second filter at the network boundary closes.

Which company size is Kaspersky Security for Internet Gateway Add-On suitable for?

The deciding factor is not headcount but whether web traffic already passes through a proxy server. Organisations without one would have to build that layer first, which is why this product mostly lands where Squid or a commercial proxy is already in production and the browsing policy needs to be enforced in one place instead of on every device.

RequirementSmall businessMedium-sized companyLarge company
Reporting obligation Switzerland Rarely By sector Usually
NIS 2 in the European Union Rarely By sector Usually
Security questionnaire from large customers Occasionally ✓ ✓
Proxy server with ICAP already in place ✕ Sometimes ✓
This product fits ✕ With a proxy ✓

Does Kaspersky Security for Internet Gateway Add-On meet the requirements of Swiss cybersecurity legislation?

The Swiss reporting obligation applies to operators of critical infrastructure — energy and drinking water suppliers, transport companies, hospitals above the defined thresholds, cloud and data centre providers, and cantonal and communal administrations — not to every company in Switzerland. Since 1 April 2025 the revised Information Security Act obliges those operators to report a cyberattack to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery, with a further 14 days to complete the report; since 1 October 2025 a failure to report can be sanctioned. A secure web gateway helps with one concrete part of that: the event log of blocked downloads, phishing hits and outbound connections to known malicious resources usually carries the earliest timestamp available, which is exactly what the initial report asks for. What it does not deliver is what happened on the device itself, forensic preservation of evidence, or the report — it sees only traffic that actually passed the proxy, and nothing from devices working outside the corporate network. This text is not legal advice; whether your organisation falls under the reporting obligation should be clarified with your own legal advisers.

Does Kaspersky Security for Internet Gateway Add-On meet the requirements of European cybersecurity legislation?

No product makes a company NIS 2 compliant. The directive obliges entities in scope to take risk-management measures and to report significant incidents, and it makes management answerable for them. The measure categories it names include risk analysis and information system security, incident handling, business continuity, supply chain security, security in the acquisition and maintenance of network and information systems, and policies on cryptography. A secure web gateway contributes to two of those: it enforces a single browsing policy for the whole site regardless of the device, blocks known malicious and phishing resources before delivery, and produces the event stream an incident handling process runs on. It contributes nothing to business continuity, backup, access control, cryptography policy, staff awareness or supplier assessment, and it covers neither endpoints nor email. The concrete duties, thresholds and deadlines follow from the national law of the country in which your entity is established.

What should you know about official assessments of Kaspersky?

The German Federal Office for Information Security (BSI) has warned against the use of Kaspersky antivirus software since 15 March 2022, originally under Section 7 and since December 2025 under Section 13 of the BSI Act. The BSI confirmed in 2026 that it maintains the warning and continues to recommend replacing the products; it has no legal basis to issue a sales ban. In the United States, the Department of Commerce issued a final determination in June 2024 prohibiting the sale and updating of Kaspersky products; that measure applies to the US market only, and the products are sold and updated normally in Switzerland and the European Union. Kaspersky states that the decision was made on political rather than technical grounds, that it is a privately held company without ties to any government, and it has formally demanded withdrawal of the BSI warning while reserving legal steps. The authorities' stated concern is vendor trust and jurisdiction — security software holds deep system rights and a permanent update channel — rather than a documented failure of detection quality. In practice this matters most for public sector procurement, suppliers to German federal bodies, groups with a US entity, and anyone whose customer questionnaires ask about the origin of security suppliers; for other buyers it is a risk decision to take deliberately and to document.

Norton vs. Kaspersky – Which antivirus program offers the best protection in 2025?
Compares both vendors on detection quality and features if you are weighing up a switch.

Does Kaspersky Security for Internet Gateway Add-On help with security questionnaires from large customers?

Yes for the network boundary and logging sections, and not at all for the rest. It answers items on filtering of malicious web content, blocking of known phishing and malware URLs, inspection of encrypted traffic, category-based restriction of internet use, and central logging with export of every event to a SIEM over syslog. It answers nothing on endpoint protection and EDR, patch and vulnerability management, disk and file encryption, multi-factor authentication, backup and restore, mobile device management, email security or awareness training — and nothing on devices that work outside the corporate network, an item questionnaires now name explicitly. Closing those gaps is usually cheaper within one vendor's line than by mixing products, since a higher endpoint tier from the same family keeps one licence relationship and one support contact. One caveat specific to this vendor: if the questionnaire asks about the origin of your security suppliers, staying inside the family does not answer that question.

Data loss is expensive: How backups help you avoid outages
Covers the backup and recovery questionnaire items that a gateway product cannot answer for you.

Which limitations should you know before buying?

The decisive regional restriction is the United States: a Department of Commerce determination prohibits the sale and updating of Kaspersky products there, so this licence is no route to covering a US entity or US site. Protection reaches only traffic that actually passes the proxy, which means notebooks browsing from home or a mobile hotspot stay outside its scope unless they are forced through it. HTTPS content remains invisible until SSL bumping is configured on the proxy, and that in turn requires an exclusion list, because applications using certificate pinning break when their sessions are intercepted. The product runs on Linux, either from an ISO image on a supported hypervisor or installed on a supported distribution, so there is no Windows gateway version. Follow-up purchases most often arise for what is not in the box: endpoint protection, mail server protection, and cover for off-network devices.

We help you decide. Test: Antivirus program: Best antivirus programs for Windows 2025
Helps you pick the device-level protection that a gateway product deliberately does not replace.

Frequently asked questions about Kaspersky Security for Internet Gateway Add-On

Do you need your own proxy server?

For the standalone application, yes. It acts as an ICAP server and needs a proxy that supports the REQMOD and RESPMOD services, for example Squid 3.5 or later, which can run on the same machine. The all-in-one appliance deployed from the ISO image ships with a pre-configured proxy, but in that variant the proxy configuration files cannot be edited by hand.

Can it run without sending data to Kaspersky Security Network?

Yes. The application can be integrated with Kaspersky Private Security Network, which supplies file and URL reputation data from an installation inside your own infrastructure, so reputation lookups do not leave your network.

Does it work together with a sandbox or targeted attack platform?

It integrates with the Kaspersky Anti Targeted Attack Platform through a two-way API. Gateway events add context to the platform's analysis, and its verdicts can be applied at the gateway to block further payload transfers and attacker communications.

 

System requirements

Operating Systems 64-bit operating system required
CentOS: 7.7 64-bit
Rocky Linux: 8.10 / 9.4 64-bit
Red Hat Enterprise Linux: 7.7 / 8.10 / 9.4 64-bit
Ubuntu: 18.04 LTS / 20.04 LTS / 22.04 LTS / 24.04 LTS 64-bit
Debian: 9.13 / 10.13 / 11.10 / 12.10 64-bit
SUSE Linux Enterprise Server: 15 SP1 64-bit
RED OS: 7.3 / 8.0 64-bit
ALT Server: 10 64-bit
Processor 8 CPU cores / x86-x64-v2 required for Rocky Linux 9.4 or Red Hat Enterprise Linux 9.4
Memory RAM 16 GB
Swap 8 GB or more
Storage 200 GB hard drive space / 25 GB for temporary file storage / 25 GB for log file storage
Locale en_US.UTF-8 locale installed
Required Packages sudo / less
Additional Packages Red Hat Enterprise Linux or Rocky Linux or RED OS: libxcrypt-compat / initscripts / SUSE Linux Enterprise Server: insserv-compat
Time Synchronization Time synchronization configured / same time zone on all servers
Web Server Nginx 1.14.0 or higher
Load Balancer HAProxy 1.5 or later
Proxy Server HTTP or HTTPS proxy server with ICAP / Request Modification REQMOD / Response Modification RESPMOD / Squid recommended

Meta Description

Scans HTTP, HTTPS and FTP traffic at the proxy via ICAP, adding URL filtering and anti-phishing. Add-on licence; needs an existing proxy server.

Keywords

Kaspersky Security for Internet Gateway Add-On, Kaspersky, Kaspersky Web Traffic Security, secure web gateway, web traffic scanning, icap proxy integration, url filtering, anti-phishing

  

   

COMPANY NAME | First Name, Last name | Address | Phone 0000 - 00 00 00 | Email info@kundendomain.com

By continuing to browse our site you agree to our use of cookies, revised Privacy Policy and Terms of Service.
More information about 
cookies

I agree