Kaspersky SD-WAN

Integration with Kaspersky CyberSecurity for Networks

You can integrate Kaspersky SD-WAN with Kaspersky Industrial CyberSecurity for Networksmirror traffic from service interfaces of CPE devices to network interfaces of Kaspersky Industrial CyberSecurity for Networks nodes. Before configuring the integration, you need to enable traffic encryption on CPE devices from whose service interfaces you want to mirror traffic. We recommend putting CPE devices on a dedicated Kaspersky Industrial CyberSecurity network

.

Mirrored traffic is identified by VLAN tags added to traffic packets in accordance with the IEEE 802.1q standard. You must make sure that matching VLAN tags are used on the service interfaces of CPE devices and on the network interfaces of Kaspersky Industrial CyberSecurity for Networks nodes.

For effective integration of Kaspersky SD-WAN with Kaspersky Industrial CyberSecurity for Networks, you can raise the limit on the number of monitoring points by additionally configuring components of Kaspersky Industrial CyberSecurity for Networks. Maximum possible limits:

  • Up to 100 monitoring points on a Kaspersky Industrial CyberSecurity for Networks node
  • Up to 100 monitoring points in total in Kaspersky Industrial CyberSecurity for Networks node

The rest of the requirements for the deployment of Kaspersky Industrial CyberSecurity for Networks components are similar to other deployment scenarios, for example, installation of a server without external sensors

.

If you need more information on configuring the components of Kaspersky Industrial CyberSecurity for Networks to integrate with Kaspersky SD-WAN, please contact your Technical Account Manager (TAM).

You can also get more information about the integration of Kaspersky SD-WAN and Kaspersky Industrial CyberSecurity for Networks in the Appendices section.

The figure below shows an example deployment scenario for Kaspersky SD-WAN and Kaspersky Industrial CyberSecurity for Networks. Dotted lines indicate the traffic mirroring path. First, the network switches at remote locations 1 and N mirror traffic to CPE devices with the standard CPE device role. Then the standard CPE devices mirror the traffic to the CPE device with the SD-WAN gateway role, which in turn mirrors the traffic to the Kaspersky Industrial CyberSecurity for Networks server. The components of Kaspersky SD-WAN and Kaspersky Industrial CyberSecurity for Networks are located in the central office of the organization.

SD-WAN_intergration_with_KICS

Example of integration of Kaspersky SD-WAN with Kaspersky Industrial CyberSecurity for Networks