What are the key advantages of Kaspersky Security for Internet Gateway Base Plus?
Central console – Own web console manages every scanning node
Gateway scanning – Checks HTTP, HTTPS and FTP traffic
Web control – Blocks sites by category and content type
Phishing block – Stops phishing pages before users open them
Proxy required – Needs an ICAP proxy such as Squid
Important note – No endpoint, mail or EDR protection included
Web traffic scanning – Removes malware from HTTP, HTTPS and FTP downloads
Anti-phishing engine – Blocks phishing and infected pages before they load
Web control rules – Restricts sites by category, content type and user group
Own web console – Dashboards, events and rules for all cluster nodes
SIEM event export – Publishes traffic and system events over the syslog protocol
Important – No endpoint agent, no mail scanning, no EDR component
Kaspersky Security for Internet Gateway is a gateway-level secure web gateway that works as an ICAP server behind your proxy server; the application it actually installs is Kaspersky Web Traffic Security, which is why buyers still find it under the name KWTS. It is managed centrally from its own web interface, which also controls every traffic processing node in a cluster.
Threats stopped early – Blocked at the proxy before reaching endpoints
Fewer endpoint alerts – One gateway event instead of many device alerts
Default deny option – Allow only the web resources a role needs
Cluster scaling – Add traffic processing nodes as bandwidth grows
Directory integration – Active Directory roles with NTLM and Kerberos sign-in
Tenant workspaces – Separate workspaces for each managed customer tenant
The deciding factor is not headcount but architecture: the product only sees traffic that already passes through a proxy server supporting ICAP. Companies that route internet access through Squid or a comparable proxy get value immediately, while companies whose devices go straight out through a router do not.
| Requirement | Small business | Medium-sized company | Large company |
|---|---|---|---|
| Reporting obligation Switzerland | Rarely | By sector | Often |
| NIS 2 in the European Union | Rarely | By sector | Often |
| Security questionnaire from large customers | Sometimes | ✓ | ✓ |
| Own ICAP proxy already in use | Rarely | Often | ✓ |
| This product fits | ✕ | With proxy | ✓ |
No security product creates compliance on its own, and this one is no exception. Under the revised Information Security Act, operators of critical infrastructure in Switzerland must report a qualifying cyberattack to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery, with the report completed within 14 days; the obligation applies to bodies such as energy and drinking water suppliers, transport companies and cantonal and communal administrations, not to every company. Where the product helps is evidence and detection at the network edge: traffic processing and system events can be written over the syslog protocol into an existing SIEM, so the time a blocked download, a phishing page or a connection to a known malicious address was seen is recorded outside the gateway itself. It does not help with the parts most organisations underestimate — it produces no endpoint telemetry, cannot reconstruct what happened on a workstation after execution, and cannot decide whether an incident is reportable or generate the report for you. Anything a device does outside the proxy path, including traffic from a laptop working from home, is invisible to it. This description is product information and not legal advice; whether your organisation falls under the reporting obligation should be clarified with a qualified adviser.
The NIS 2 Directive requires essential and important entities to take risk management measures and to handle and report significant incidents; it does not certify products, and buying software never produces compliance by itself. The product supports the network security and access control measure categories directly: it filters HTTP, HTTPS and FTP traffic at the proxy, restricts which web resource categories and content types a user group may reach, and can enforce a default deny scenario in which only explicitly needed resources stay reachable. For incident handling it contributes detection data rather than case management, through role-based access to its console and event export to a SIEM. The gaps are substantial and should be planned for: it covers no endpoints, no mailboxes, no servers or workloads, no backup and business continuity, no patch management, no encryption and no multi-factor authentication, and it does nothing for the governance, training and supply chain elements the directive also expects.
Several authorities have published assessments of the vendor, and they remain relevant for procurement. In March 2022 the German Federal Office for Information Security (BSI) issued a warning recommending that Kaspersky protection software be replaced with alternative products; it did not ban sales, and the office confirmed in 2024 that the warning still stood. In June 2024 the US Department of Commerce, Bureau of Industry and Security, issued a Final Determination prohibiting Kaspersky from providing antivirus and cybersecurity products or services in the United States or to US persons: new sales ended on 20 July 2024 and signature and codebase updates ended on 29 September 2024, and three group entities were added to the Entity List. Canada, Italy, the Netherlands and the United Kingdom have restricted use in government or public sector contexts rather than banning consumer or business sales. Kaspersky rejects the reasoning, stating that the US decision was based on the geopolitical climate and theoretical concerns rather than an evaluation of its products, and has proposed an assessment framework allowing an independent reviewer to verify its solutions, database updates and detection rules; independent testing laboratories such as AV-TEST and AV-Comparatives have continued to include Kaspersky products in their test cycles. In practice this matters most if you sell to the public sector, answer supply chain requirements from large customers, or operate a group entity subject to US rules; the product remains sold and updated in Switzerland and the European Union, and the decision belongs to the buyer.
Partly, and only in the network section. It answers questions about web content filtering and URL categorisation, malware scanning of downloaded files, anti-phishing at the perimeter, restriction of web access by user group, role-based administrative access, directory-based authentication of administrators, and forwarding of security events to a SIEM. It answers nothing in the sections that usually carry the most weight: endpoint protection and EDR, mail and phishing protection at the mailbox, server and workload protection, disk encryption and key recovery, patch management with proof of deployment, mobile device management, multi-factor authentication, backup and recovery testing, and log retention policies for endpoint data. It also cannot evidence protection for staff working outside the corporate network, which reviewers now ask about routinely. To close those gaps, adding endpoint and server protection from the same vendor family is normally cheaper to operate than mixing vendors, because you keep one support contract and one set of licence renewals; where a questionnaire demands detection and response evidence, the gateway data only becomes useful once it is combined with endpoint telemetry in a SIEM or an EDR platform.
The most important regional fact: the product cannot be sold to or updated for customers in the United States following the 2024 Commerce Department determination, so groups with US entities need a different plan for those sites. Technically, the product works as an ICAP server and needs an HTTP(S) proxy that supports the REQMOD and RESPMOD services — Squid is the recommended option, and compatibility with other proxy software is not guaranteed — although the all-in-one appliance image ships with a pre-configured proxy included. Encrypted traffic is the second common surprise: without SSL Bumping configured on the proxy, the anti-virus and anti-phishing modules cannot inspect data inside the encrypted channel, and enabling it requires an exclusion list because it breaks applications that pin certificates. Deep analysis of unknown files in a sandbox is not part of this product; it is delivered by integration with the separately licensed Kaspersky Anti Targeted Attack Platform. Finally, protection stops where the proxy path stops, so home office and travelling laptops need their own protection layer.
Only if their traffic is still routed through the corporate proxy, for example over an always-on VPN tunnel. A device connected directly to a home or hotel network bypasses the gateway entirely, so the scanning, category filtering and phishing blocks do not apply to it.
Any HTTP(S) proxy that supports the ICAP protocol with Request Modification and Response Modification services can send traffic to it, and Squid is the option Kaspersky documents and recommends. If you install from the ISO appliance image the built-in proxy comes pre-configured, but its configuration files cannot be edited afterwards, which is why administrators who need custom proxy rules install the package version on an existing Linux system instead.
This variant is a base licence for the product itself rather than a renewal of an existing licence, and it does not require another Kaspersky product to run, since the gateway is deployed as its own application or appliance. If you already run this solution and only want to continue it, check the renewal variant instead.
| Operating Systems | CentOS: 7.7 64-bit Rocky Linux: 8.10 / 9.4 64-bit Red Hat Enterprise Linux: 7.7 / 8.10 / 9.4 64-bit Ubuntu: 18.04 LTS / 20.04 LTS / 22.04 LTS / 24.04 LTS 64-bit Debian: 9.13 / 10.13 / 11.10 / 12.10 64-bit SUSE Linux Enterprise Server: 15 SP1 64-bit RED OS: 7.3 / 8.0 64-bit ALT Server: 10 64-bit 64-bit operating system required |
| Processor | 8 CPU cores / x86-x64-v2 required for Rocky Linux 9.4 or Red Hat Enterprise Linux 9.4 |
| Memory RAM | 16 GB |
| Swap | 8 GB or more |
| Storage | 200 GB hard drive space / 25 GB for temporary file storage / 25 GB for log file storage |
| Locale | en_US.UTF-8 locale installed |
| Required Packages | sudo / less |
| Additional Packages | Red Hat Enterprise Linux or Rocky Linux or RED OS: libxcrypt-compat / initscripts / SUSE Linux Enterprise Server: insserv-compat |
| Time Synchronization | Time synchronization configured / same time zone on all servers |
| Web Server | Nginx 1.14.0 or higher |
| Load Balancer | HAProxy 1.5 or later |
| Proxy Server | HTTP or HTTPS proxy server with ICAP / REQMOD / RESPMOD / Squid recommended |