<h2 style="margin-top: 0px; margin-bottom: 10px;">What is included in Kaspersky Security for Internet Gateway Base?</h2>
<p style="margin-top: 0px; margin-bottom: 0px;"><strong>Kaspersky Web Traffic Security</strong> – Main application that scans inbound and outbound web traffic.<br /> <strong>Anti-malware engine</strong> – Blocks malware, ransomware, miners and potentially unwanted programs.<br /> <strong>Anti-phishing stack</strong> – Blocks phishing pages using deep learning and reputation data.<br /> <strong>Web control</strong> – Restricts more than 40 categories of web resources.<br /> <strong>Web-based console</strong> – Role-based access, event view and SIEM export included.<br /> <strong>Important</strong> – No endpoint, mail or EDR components are included here.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">What are the main benefits of Kaspersky Security for Internet Gateway Base?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Kaspersky Security for Internet Gateway is an on-premises secure web gateway whose main application is Kaspersky Web Traffic Security, the name many administrators still search for. Base denotes the initial licence variant in Kaspersky retail naming, as opposed to the renewal variant, and it is administered centrally from its own web console rather than device by device.<br /><br /> <strong>Blocking before the endpoint</strong> – Downloads are stopped at the proxy, not on workstations.<br /> <strong>ICAP integration</strong> – Works with an existing Squid or other ICAP proxy.<br /> <strong>All-in-one appliance</strong> – Ships with a pre-configured proxy for faster rollout.<br /> <strong>Encrypted traffic option</strong> – Analyses HTTPS objects where SSL bumping is already configured.<br /> <strong>Multiple workspaces</strong> – Separate policies per branch office or per customer tenant.<br /> <strong>SIEM export</strong> – Gateway events feed your existing monitoring and audit trail.</p>
<p style="margin-top: 15px; margin-bottom: 15px;"><a href="#" target="_blank" data-ke-doc="windows-defender-not-enough"><strong>Best antivirus? Why Windows Defender alone is not enough</strong><br />Explains why perimeter and endpoint protection cover different attack stages and why one does not replace the other.</a></p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Which company size is Kaspersky Security for Internet Gateway Base suitable for?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The deciding factor is not headcount but whether web traffic already passes through a proxy server you control. Organisations without their own proxy infrastructure gain little from this licence, while organisations that already run Squid or a comparable gateway can add scanning to it without changing the network path.</p>
<table style="width: 100%; border-collapse: collapse; background-color: #efefef; margin-top: 15px; margin-bottom: 15px; font-size: 14px; line-height: 1.35;">
<tbody>
<tr><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: left; font-weight: bold; background-color: #dedede;">Requirement</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Small business</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Medium-sized company</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Large company</th></tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Reporting obligation Switzerland</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Mostly exempt</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">NIS 2 in the European Union</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Security questionnaire from large customers</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Occasionally</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Own proxy or gateway in use</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Rare</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Often</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">This product fits</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">With a proxy</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
</tbody>
</table>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does Kaspersky Security for Internet Gateway Base meet the requirements of Swiss cybersecurity legislation?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The obligation under the revised Information Security Act applies to operators of critical infrastructure, for example energy and drinking water suppliers, transport companies, listed hospitals and cantonal and communal administrations, not to every Swiss company. Those organisations must report a cyberattack to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery, with 14 days to complete the report. Where this product helps is the first hours of that window: the gateway event log records which host contacted which URL and which object was blocked, which is often what turns a vague alert into a datable incident, and the SIEM export moves those events into the system your incident process already uses. What it does not do is detect the incident on the endpoint, reconstruct the attack chain, or produce the report itself, so an organisation relying on this licence alone will still be missing endpoint telemetry when the clock starts. This text is not legal advice; whether your organisation falls under the reporting obligation should be clarified with your own legal counsel.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does Kaspersky Security for Internet Gateway Base meet the requirements of European cybersecurity legislation?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">No software product creates NIS 2 compliance, because the directive addresses organisational risk management rather than any single tool. The NIS 2 Directive requires measure categories including risk analysis and information system security policies, incident handling, business continuity and backup, supply chain security, access control policies and the use of cryptography. This product contributes to two of them: it is a technical control for network and information system security at the perimeter, and its event data supports incident handling. It contributes nothing to business continuity and backup, supply chain security, identity and access management across the organisation, or cryptographic key handling, and it covers only traffic that actually crosses the gateway. Buyers who need those categories covered should plan them as separate line items rather than assuming a gateway product addresses them.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">What should you know about official assessments of Kaspersky?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">On 20 June 2024 the US Department of Commerce, through its Bureau of Industry and Security, issued a Final Determination prohibiting Kaspersky from supplying antivirus and cybersecurity products or services to US persons; new sales stopped on 20 July 2024 and signature updates, codebase updates and operation of the Kaspersky Security Network in the United States stopped on 29 September 2024. Germany's Federal Office for Information Security (BSI) has warned against the use of Kaspersky antivirus software since 15 March 2022 under the BSI Act, and that warning remains published. Both measures remain in force at the time of writing. Kaspersky rejects the assessments, states that no evidence of misuse has been presented, points to its Global Transparency Initiative and its data processing in Switzerland, and has publicly asked the BSI for a re-evaluation. Independent laboratories including AV-TEST and AV-Comparatives have continued to test and certify Kaspersky products through this period, so the detection performance question and the vendor origin question are separate. In practice this matters most for public sector tenders, for suppliers to US-linked or German-linked customers, and for anyone whose supply chain questionnaire asks about vendor jurisdiction; for a purely domestic private company with no such clauses it may not matter at all. The decision is yours.</p>
<p style="margin-top: 15px; margin-bottom: 15px;"><a href="#" target="_blank" data-ke-doc="norton-vs-kaspersky-2025"><strong>Norton vs. Kaspersky – Which antivirus program offers the best protection in 2025?</strong><br />A side-by-side look at detection results and product scope for buyers weighing a change of vendor.</a></p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does Kaspersky Security for Internet Gateway Base help with security questionnaires from large customers?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Partly, and only in the network security block. It answers items on malware filtering of inbound internet traffic, blocking of known malicious and phishing URLs, enforcement of an acceptable use policy through category-based web control, restriction of file transfers by type and size, role-based administrator access, and forwarding of security events to a SIEM. It answers nothing on endpoint protection and EDR, email and phishing protection at the mailbox, patch and vulnerability management, disk and removable media encryption, multi-factor authentication, backup and restore testing, mobile device management, or asset inventory, and it produces no evidence at all for staff that work outside the gateway. Increasingly, questionnaires also ask which vendors are used and in which jurisdiction they operate, which is worth reading in the light of the section above. To close the technical gaps, adding products from the same Kaspersky family, such as an endpoint tier for workstation and EDR coverage and a mail gateway product for email, is usually cheaper and simpler to document than mixing vendors, because the answers then come from one set of consoles and reports.</p>
<p style="margin-top: 15px; margin-bottom: 15px;"><a href="#" target="_blank" data-ke-doc="data-loss-backups-avoid-outages"><strong>Data loss is expensive: How backups help you avoid outages</strong><br />Covers the backup and restore questions this product does not answer, and what auditors expect to see.</a></p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Which limitations should you know before buying?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Regional availability is the first thing to check: following the US prohibition, Kaspersky trials and downloads are not available to US customers, so this licence is not an option for a US entity or a group with US-based sites. The standalone application requires an HTTP(S) proxy server supporting ICAP with REQMOD and RESPMOD, and it installs on Linux only, with Ubuntu, CentOS, RHEL, Debian and SLES named as supported; if you have no proxy, you need the all-in-one appliance instead, which runs on VMware ESXi or Microsoft Hyper-V. HTTPS content is only analysed where SSL bumping has been configured on the proxy, so an untouched HTTPS setup gives you URL blocking but not object scanning. The largest practical gap is coverage: laptops used at home or on mobile networks are unprotected by this product unless their traffic is forced back through the gateway, which is the most common reason buyers add an endpoint product afterwards.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Frequently asked questions about Kaspersky Security for Internet Gateway Base</h3>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does this licence replace antivirus on workstations and servers?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">No. It scans traffic passing through the gateway and installs no agent on any workstation or server. Endpoints still need their own protection, which is a separate product.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does it protect employees working from home?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Only if their traffic is routed back through the corporate proxy, for example over a VPN with full tunnelling. Split tunnelling or direct internet access bypasses the gateway entirely, and nothing is scanned or logged.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Can it handle growing traffic volumes?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Yes, through cluster deployment: additional traffic-processing nodes can be added as load increases, and multiple workspaces let separate branch offices or tenants keep their own policies under one top-level administration.</p>
<div class="ke-block mceNonEditable" data-ke-block="blogteaser" data-topics="sec-console,compliance-ch-isg,compliance-nis2" data-audience="b2b" data-count="3"> </div>