<h2 style="margin-top: 0px; margin-bottom: 10px;">What is included in Kaspersky Security for Internet Gateway Base Plus?</h2>
<p style="margin-top: 0px; margin-bottom: 0px;"><strong>Web traffic scanning</strong> – Removes malware from HTTP, HTTPS and FTP downloads<br /> <strong>Anti-phishing engine</strong> – Blocks phishing and infected pages before they load<br /> <strong>Web control rules</strong> – Restricts sites by category, content type and user group<br /> <strong>Own web console</strong> – Dashboards, events and rules for all cluster nodes<br /> <strong>SIEM event export</strong> – Publishes traffic and system events over the syslog protocol<br /> <strong>Important</strong> – No endpoint agent, no mail scanning, no EDR component</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">What are the main benefits of Kaspersky Security for Internet Gateway Base Plus?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Kaspersky Security for Internet Gateway is a gateway-level secure web gateway that works as an ICAP server behind your proxy server; the application it actually installs is Kaspersky Web Traffic Security, which is why buyers still find it under the name KWTS. It is managed centrally from its own web interface, which also controls every traffic processing node in a cluster.<br /><br /> <strong>Threats stopped early</strong> – Blocked at the proxy before reaching endpoints<br /> <strong>Fewer endpoint alerts</strong> – One gateway event instead of many device alerts<br /> <strong>Default deny option</strong> – Allow only the web resources a role needs<br /> <strong>Cluster scaling</strong> – Add traffic processing nodes as bandwidth grows<br /> <strong>Directory integration</strong> – Active Directory roles with NTLM and Kerberos sign-in<br /> <strong>Tenant workspaces</strong> – Separate workspaces for each managed customer tenant</p>
<p style="margin-top: 15px; margin-bottom: 15px;"><a href="#" target="_blank" data-ke-doc="windows-defender-not-enough"><strong>Best antivirus? Why Windows Defender alone is not enough</strong><br />Explains why a single protection layer rarely covers all attack paths, which is the argument for adding gateway-level scanning.</a></p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Which company size is Kaspersky Security for Internet Gateway Base Plus suitable for?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The deciding factor is not headcount but architecture: the product only sees traffic that already passes through a proxy server supporting ICAP. Companies that route internet access through Squid or a comparable proxy get value immediately, while companies whose devices go straight out through a router do not.</p>
<table style="width: 100%; border-collapse: collapse; background-color: #efefef; margin-top: 15px; margin-bottom: 15px; font-size: 14px; line-height: 1.35;">
<tbody>
<tr><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: left; font-weight: bold; background-color: #dedede;">Requirement</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Small business</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Medium-sized company</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Large company</th></tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Reporting obligation Switzerland</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Rarely</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Often</td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">NIS 2 in the European Union</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Rarely</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Often</td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Security questionnaire from large customers</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Sometimes</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Own ICAP proxy already in use</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Rarely</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Often</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">This product fits</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">With proxy</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
</tbody>
</table>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does Kaspersky Security for Internet Gateway Base Plus meet the requirements of Swiss cybersecurity legislation?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">No security product creates compliance on its own, and this one is no exception. Under the revised Information Security Act, operators of critical infrastructure in Switzerland must report a qualifying cyberattack to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery, with the report completed within 14 days; the obligation applies to bodies such as energy and drinking water suppliers, transport companies and cantonal and communal administrations, not to every company. Where the product helps is evidence and detection at the network edge: traffic processing and system events can be written over the syslog protocol into an existing SIEM, so the time a blocked download, a phishing page or a connection to a known malicious address was seen is recorded outside the gateway itself. It does not help with the parts most organisations underestimate — it produces no endpoint telemetry, cannot reconstruct what happened on a workstation after execution, and cannot decide whether an incident is reportable or generate the report for you. Anything a device does outside the proxy path, including traffic from a laptop working from home, is invisible to it. This description is product information and not legal advice; whether your organisation falls under the reporting obligation should be clarified with a qualified adviser.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does Kaspersky Security for Internet Gateway Base Plus meet the requirements of European cybersecurity legislation?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The NIS 2 Directive requires essential and important entities to take risk management measures and to handle and report significant incidents; it does not certify products, and buying software never produces compliance by itself. The product supports the network security and access control measure categories directly: it filters HTTP, HTTPS and FTP traffic at the proxy, restricts which web resource categories and content types a user group may reach, and can enforce a default deny scenario in which only explicitly needed resources stay reachable. For incident handling it contributes detection data rather than case management, through role-based access to its console and event export to a SIEM. The gaps are substantial and should be planned for: it covers no endpoints, no mailboxes, no servers or workloads, no backup and business continuity, no patch management, no encryption and no multi-factor authentication, and it does nothing for the governance, training and supply chain elements the directive also expects.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">What should you know about official assessments of Kaspersky?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Several authorities have published assessments of the vendor, and they remain relevant for procurement. In March 2022 the German Federal Office for Information Security (BSI) issued a warning recommending that Kaspersky protection software be replaced with alternative products; it did not ban sales, and the office confirmed in 2024 that the warning still stood. In June 2024 the US Department of Commerce, Bureau of Industry and Security, issued a Final Determination prohibiting Kaspersky from providing antivirus and cybersecurity products or services in the United States or to US persons: new sales ended on 20 July 2024 and signature and codebase updates ended on 29 September 2024, and three group entities were added to the Entity List. Canada, Italy, the Netherlands and the United Kingdom have restricted use in government or public sector contexts rather than banning consumer or business sales. Kaspersky rejects the reasoning, stating that the US decision was based on the geopolitical climate and theoretical concerns rather than an evaluation of its products, and has proposed an assessment framework allowing an independent reviewer to verify its solutions, database updates and detection rules; independent testing laboratories such as AV-TEST and AV-Comparatives have continued to include Kaspersky products in their test cycles. In practice this matters most if you sell to the public sector, answer supply chain requirements from large customers, or operate a group entity subject to US rules; the product remains sold and updated in Switzerland and the European Union, and the decision belongs to the buyer.</p>
<p style="margin-top: 15px; margin-bottom: 15px;"><a href="#" target="_blank" data-ke-doc="norton-vs-kaspersky-2025"><strong>Norton vs. Kaspersky – Which antivirus program offers the best protection in 2025?</strong><br />A direct comparison of detection performance and features between the two vendors, useful if vendor choice is being questioned internally.</a></p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does Kaspersky Security for Internet Gateway Base Plus help with security questionnaires from large customers?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Partly, and only in the network section. It answers questions about web content filtering and URL categorisation, malware scanning of downloaded files, anti-phishing at the perimeter, restriction of web access by user group, role-based administrative access, directory-based authentication of administrators, and forwarding of security events to a SIEM. It answers nothing in the sections that usually carry the most weight: endpoint protection and EDR, mail and phishing protection at the mailbox, server and workload protection, disk encryption and key recovery, patch management with proof of deployment, mobile device management, multi-factor authentication, backup and recovery testing, and log retention policies for endpoint data. It also cannot evidence protection for staff working outside the corporate network, which reviewers now ask about routinely. To close those gaps, adding endpoint and server protection from the same vendor family is normally cheaper to operate than mixing vendors, because you keep one support contract and one set of licence renewals; where a questionnaire demands detection and response evidence, the gateway data only becomes useful once it is combined with endpoint telemetry in a SIEM or an EDR platform.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Which limitations should you know before buying?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The most important regional fact: the product cannot be sold to or updated for customers in the United States following the 2024 Commerce Department determination, so groups with US entities need a different plan for those sites. Technically, the product works as an ICAP server and needs an HTTP(S) proxy that supports the REQMOD and RESPMOD services — Squid is the recommended option, and compatibility with other proxy software is not guaranteed — although the all-in-one appliance image ships with a pre-configured proxy included. Encrypted traffic is the second common surprise: without SSL Bumping configured on the proxy, the anti-virus and anti-phishing modules cannot inspect data inside the encrypted channel, and enabling it requires an exclusion list because it breaks applications that pin certificates. Deep analysis of unknown files in a sandbox is not part of this product; it is delivered by integration with the separately licensed Kaspersky Anti Targeted Attack Platform. Finally, protection stops where the proxy path stops, so home office and travelling laptops need their own protection layer.</p>
<p style="margin-top: 15px; margin-bottom: 15px;"><a href="#" target="_blank" data-ke-doc="antivirus-programs-windows-2025"><strong>We help you decide. Test: Antivirus program: Best antivirus programs for Windows 2025</strong><br />Compares current Windows protection products, which helps when you need to close the endpoint gap this gateway product deliberately leaves open.</a></p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Frequently asked questions about Kaspersky Security for Internet Gateway Base Plus</h3>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does it protect laptops that are used outside the office network?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Only if their traffic is still routed through the corporate proxy, for example over an always-on VPN tunnel. A device connected directly to a home or hotel network bypasses the gateway entirely, so the scanning, category filtering and phishing blocks do not apply to it.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Which proxy servers can be used with the product?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Any HTTP(S) proxy that supports the ICAP protocol with Request Modification and Response Modification services can send traffic to it, and Squid is the option Kaspersky documents and recommends. If you install from the ISO appliance image the built-in proxy comes pre-configured, but its configuration files cannot be edited afterwards, which is why administrators who need custom proxy rules install the package version on an existing Linux system instead.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Is Base Plus a new licence or an extension of an existing one?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">This variant is a base licence for the product itself rather than a renewal of an existing licence, and it does not require another Kaspersky product to run, since the gateway is deployed as its own application or appliance. If you already run this solution and only want to continue it, check the renewal variant instead.</p>
<div class="ke-block mceNonEditable" data-ke-block="blogteaser" data-topics="sec-console,compliance-ch-isg,compliance-supplier" data-audience="b2b" data-count="3"> </div>