What are the key advantages of Kaspersky Security for Internet Gateway Base?
Central console – One web console manages all gateway nodes.
Proxy integration – Connects to your proxy server via ICAP.
Web control – Blocks more than 40 web categories.
Content filtering – Blocks files by type, size or hash.
Cluster scaling – Add traffic-processing nodes as load grows.
Important note – No endpoint agents; workstations need separate protection.
Kaspersky Web Traffic Security – Main application that scans inbound and outbound web traffic.
Anti-malware engine – Blocks malware, ransomware, miners and potentially unwanted programs.
Anti-phishing stack – Blocks phishing pages using deep learning and reputation data.
Web control – Restricts more than 40 categories of web resources.
Web-based console – Role-based access, event view and SIEM export included.
Important – No endpoint, mail or EDR components are included here.
Kaspersky Security for Internet Gateway is an on-premises secure web gateway whose main application is Kaspersky Web Traffic Security, the name many administrators still search for. Base denotes the initial licence variant in Kaspersky retail naming, as opposed to the renewal variant, and it is administered centrally from its own web console rather than device by device.
Blocking before the endpoint – Downloads are stopped at the proxy, not on workstations.
ICAP integration – Works with an existing Squid or other ICAP proxy.
All-in-one appliance – Ships with a pre-configured proxy for faster rollout.
Encrypted traffic option – Analyses HTTPS objects where SSL bumping is already configured.
Multiple workspaces – Separate policies per branch office or per customer tenant.
SIEM export – Gateway events feed your existing monitoring and audit trail.
The deciding factor is not headcount but whether web traffic already passes through a proxy server you control. Organisations without their own proxy infrastructure gain little from this licence, while organisations that already run Squid or a comparable gateway can add scanning to it without changing the network path.
| Requirement | Small business | Medium-sized company | Large company |
|---|---|---|---|
| Reporting obligation Switzerland | Mostly exempt | By sector | By sector |
| NIS 2 in the European Union | ✕ | By sector | ✓ |
| Security questionnaire from large customers | Occasionally | ✓ | ✓ |
| Own proxy or gateway in use | Rare | Often | ✓ |
| This product fits | ✕ | With a proxy | ✓ |
The obligation under the revised Information Security Act applies to operators of critical infrastructure, for example energy and drinking water suppliers, transport companies, listed hospitals and cantonal and communal administrations, not to every Swiss company. Those organisations must report a cyberattack to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery, with 14 days to complete the report. Where this product helps is the first hours of that window: the gateway event log records which host contacted which URL and which object was blocked, which is often what turns a vague alert into a datable incident, and the SIEM export moves those events into the system your incident process already uses. What it does not do is detect the incident on the endpoint, reconstruct the attack chain, or produce the report itself, so an organisation relying on this licence alone will still be missing endpoint telemetry when the clock starts. This text is not legal advice; whether your organisation falls under the reporting obligation should be clarified with your own legal counsel.
No software product creates NIS 2 compliance, because the directive addresses organisational risk management rather than any single tool. The NIS 2 Directive requires measure categories including risk analysis and information system security policies, incident handling, business continuity and backup, supply chain security, access control policies and the use of cryptography. This product contributes to two of them: it is a technical control for network and information system security at the perimeter, and its event data supports incident handling. It contributes nothing to business continuity and backup, supply chain security, identity and access management across the organisation, or cryptographic key handling, and it covers only traffic that actually crosses the gateway. Buyers who need those categories covered should plan them as separate line items rather than assuming a gateway product addresses them.
On 20 June 2024 the US Department of Commerce, through its Bureau of Industry and Security, issued a Final Determination prohibiting Kaspersky from supplying antivirus and cybersecurity products or services to US persons; new sales stopped on 20 July 2024 and signature updates, codebase updates and operation of the Kaspersky Security Network in the United States stopped on 29 September 2024. Germany's Federal Office for Information Security (BSI) has warned against the use of Kaspersky antivirus software since 15 March 2022 under the BSI Act, and that warning remains published. Both measures remain in force at the time of writing. Kaspersky rejects the assessments, states that no evidence of misuse has been presented, points to its Global Transparency Initiative and its data processing in Switzerland, and has publicly asked the BSI for a re-evaluation. Independent laboratories including AV-TEST and AV-Comparatives have continued to test and certify Kaspersky products through this period, so the detection performance question and the vendor origin question are separate. In practice this matters most for public sector tenders, for suppliers to US-linked or German-linked customers, and for anyone whose supply chain questionnaire asks about vendor jurisdiction; for a purely domestic private company with no such clauses it may not matter at all. The decision is yours.
Partly, and only in the network security block. It answers items on malware filtering of inbound internet traffic, blocking of known malicious and phishing URLs, enforcement of an acceptable use policy through category-based web control, restriction of file transfers by type and size, role-based administrator access, and forwarding of security events to a SIEM. It answers nothing on endpoint protection and EDR, email and phishing protection at the mailbox, patch and vulnerability management, disk and removable media encryption, multi-factor authentication, backup and restore testing, mobile device management, or asset inventory, and it produces no evidence at all for staff that work outside the gateway. Increasingly, questionnaires also ask which vendors are used and in which jurisdiction they operate, which is worth reading in the light of the section above. To close the technical gaps, adding products from the same Kaspersky family, such as an endpoint tier for workstation and EDR coverage and a mail gateway product for email, is usually cheaper and simpler to document than mixing vendors, because the answers then come from one set of consoles and reports.
Regional availability is the first thing to check: following the US prohibition, Kaspersky trials and downloads are not available to US customers, so this licence is not an option for a US entity or a group with US-based sites. The standalone application requires an HTTP(S) proxy server supporting ICAP with REQMOD and RESPMOD, and it installs on Linux only, with Ubuntu, CentOS, RHEL, Debian and SLES named as supported; if you have no proxy, you need the all-in-one appliance instead, which runs on VMware ESXi or Microsoft Hyper-V. HTTPS content is only analysed where SSL bumping has been configured on the proxy, so an untouched HTTPS setup gives you URL blocking but not object scanning. The largest practical gap is coverage: laptops used at home or on mobile networks are unprotected by this product unless their traffic is forced back through the gateway, which is the most common reason buyers add an endpoint product afterwards.
No. It scans traffic passing through the gateway and installs no agent on any workstation or server. Endpoints still need their own protection, which is a separate product.
Only if their traffic is routed back through the corporate proxy, for example over a VPN with full tunnelling. Split tunnelling or direct internet access bypasses the gateway entirely, and nothing is scanned or logged.
Yes, through cluster deployment: additional traffic-processing nodes can be added as load increases, and multiple workspaces let separate branch offices or tenants keep their own policies under one top-level administration.
| Operating Systems | 64-bit operating system required CentOS 7.7 64-bit Rocky Linux 8.10 64-bit Rocky Linux 9.4 64-bit Red Hat Enterprise Linux 7.7 64-bit Red Hat Enterprise Linux 8.10 64-bit Red Hat Enterprise Linux 9.4 64-bit Ubuntu 18.04 LTS 64-bit Ubuntu 20.04 LTS 64-bit Ubuntu 22.04 LTS 64-bit Ubuntu 24.04 LTS 64-bit Debian 9.13 64-bit Debian 10.13 64-bit Debian 11.10 64-bit Debian 12.10 64-bit SUSE Linux Enterprise Server 15 SP1 64-bit RED OS 7.3 64-bit RED OS 8.0 64-bit ALT Server 10 64-bit |
| Processor | Intel Broadwell or newer / 8 CPU cores / If installed on Rocky Linux 9.4 or Red Hat Enterprise Linux 9.4: CPU must support the x86-x64-v2 instruction set |
| Memory RAM | 16 GB |
| Swap | 8 GB or more |
| Storage | 200 GB hard drive space / 25 GB for temporary files / 25 GB for log files |
| Proxy Server | HTTP or HTTPS proxy server with ICAP / REQMOD / RESPMOD / Squid recommended |
| Web Server | Nginx 1.14.0 or higher |
| Load Balancer | HAProxy 1.5 or later for load balancing |
| Locale | en_US.UTF-8 locale installed |