Your users reach the web through a proxy. It forwards what it cannot read — Kaspersky Web Traffic Security scans every web request your proxy carries — malware, phishing, categories and files, with TLS decrypted by rule — on nodes you run, so the logs never leave your own data centre.
Buy through TechBag
Same software. Better outcome — at a lower cost.
How it’s rated
Full scoreboard ↓Quick answer
This page covers Kaspersky Web Traffic Security — the on-premises web gateway sold as Kaspersky Security for Internet Gateway. The rest:
Most product pages skip this. We start here — so you buy a capability, not a buzzword.
A proxy you run that opens each web request, scans it and decides before it reaches the user.
What consolidation actually replaces, dimension by dimension.
| Dimension | A bare proxy, blind to HTTPS | Kaspersky Web Traffic Security |
|---|---|---|
| Malware in downloads | Passed through; the endpoint has to catch it | Scanned at the proxy before it reaches a laptop |
| HTTPS traffic | A blind tunnel the proxy cannot read | Decrypted by rule, with pinned apps tunnelled |
| Who may visit what | A hand-kept blocklist of domains | Category and file rules tied to AD groups |
| Proof for auditors | Raw access logs on one box | Events in CEF to your SIEM, kept as long as you set |
| Growing traffic | A bigger single server | More nodes in a cluster, up to 20 |
| What it is NOT | — | A cloud SWG, a roaming agent, a CASB or a DNS filter |
The cheapest test is the free trial: deploy one ISO node, point one department's browsers at it, and read a week of events.
Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.
The ISO build installs a proxy on every cluster node and manages it from the web console; the DEB build sits beside a proxy you already run and receives its objects over ICAP.
Each node scans requests and responses against traffic processing rules: anti-virus, anti-phishing, web categories and file filters, then hands an allow, block or redirect verdict back.
One node holds the rules, workspaces and roles and pushes them to the cluster; it also collects events and shows dashboards, reports and node health in the browser console.
Active Directory maps users and groups into rules; Kaspersky Security Network, or a private KPSN, supplies URL and file reputation; KATA can receive files and return detections.
A proxy hands each object to ICAP scanning nodes — rules come from one control node, logs stay on hardware you own.
Kaspersky Web Traffic Security turns the proxy you run into a gateway that opens, scans and rules on each request.
Downloads over HTTP, HTTPS and FTP are scanned by machine-learning and emulation engines before they reach a laptop.
A separate Anti-Phishing module checks pages and links against Kaspersky’s phishing models and reputation data.
SSL rules choose Bump, Tunnel, Tunnel with SNI check or Terminate per source or site, so banking apps can pass untouched.
Access rules allow, block or redirect by category; 6.2 added a Generative AI tools category beside gambling and adult content.
Files in either direction can be stopped by name, MIME type, size, true format or MD5 and SHA256 checksum.
Kerberos or NTLM single sign-on identifies the user; 6.2 adds domain-forest support so cross-domain group members match.
Departments or managed client organisations each get a workspace with their own rules, block page and admin roles.
Traffic and system events publish over syslog, in CEF if you choose, and node status is readable over SNMP.
Up to 20 nodes form one cluster behind a load balancer; Kaspersky suggests one standby node for every five active.
Why scanning belongs at the proxy, the Kaspersky Security Network reputation service it draws on, and a recorded console walkthrough in German.
A 90-second case for scanning at the proxy, naming Kaspersky Web Traffic Security as the tool.
The cloud reputation service the gateway queries for URLs and files, in under a minute.
A recorded 2019 walkthrough of KWTS rules and the console from Kaspersky’s German channel; screens have changed since.
Want a live, India-context walkthrough for your environment?
Book a guided demo →Here’s what genuinely sets it apart — and exactly where it stops.
KWTS runs on virtual machines or servers you own, so decrypted traffic, access logs and reports are stored where you put them — in your Indian data centre if that is the rule. The only outbound call is reputation lookup to Kaspersky Security Network, and a private KPSN removes even that for estates that must keep every query inside.
Because it speaks ICAP, KWTS can sit behind a proxy that is already in production and add anti-virus, anti-phishing and category control without re-routing users. Or deploy the ISO image, which brings its own proxy, cluster and TLS bumping in one build. Either way the CERT-In rule that internet access goes through a proxy is met by design.
The 6.2 help gives tested throughput per node: 44 Mbps on an 8-vCPU virtual machine with anti-virus, anti-phishing and KSN, up to 757 Mbps on a 48-core Xeon server, and roughly 40% less once category filtering is on. A cluster holds 20 nodes. You can size hardware before a pilot rather than after it.
Nothing covers a laptop that is not on your network or VPN: there is no roaming agent and no cloud PoP. There is no CASB, no DLP and no DNS-layer service. Prices are quote-only, Gartner has not placed Kaspersky in its SSE quadrant, and US buyers cannot get it at all after the 2024 Commerce ban.
Measure peak Mbps through today’s proxy, list sites and AD groups, and decide between the ISO build and ICAP beside it.
Use Kaspersky’s per-core bandwidth tables to pick node count, add 10% for a load balancer and one standby per five.
Deploy nodes in your Indian data centre, issue the interception certificate and push it to every managed device.
Start with one department, tunnel banking and pinned apps by SNI rule, and track breakage before widening.
Send CEF events to your SIEM, set retention to at least 180 days, and agree who approves unblock requests.
Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.
“We put KWTS behind our existing proxy over ICAP and had malware scanning on all branches without touching a single PAC file.”
“The sizing tables were close: our 250 Mbps peak needed two Xeon nodes with category filtering on, plus one standby.”
“Tunnel with SNI check saved us. Our bank portals and a pinned ERP client broke under Bump until we exempted them by rule.”
“Auditors asked where proxy logs live for 180 days. Answer: our own SIEM in Mumbai, fed by CEF from the cluster.”
“Workspaces let us run one cluster for three subsidiaries, each with its own rules, block page and admins.”
“It covers the office well, but sales staff on hotel Wi-Fi are outside it unless the VPN is up. Plan for that gap.”
Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the secure web gateway market — tap any vendor to see why it sits where it does.
Execution strength vs product vision — the classic market map, minus the paywall.
On-premises only; quoted per user through partners.
The grid nobody publishes — how much of the inspection path and its logs you host yourself vs how deep the inspection goes.
Self-hosted; full TLS bump, anti-virus, anti-phishing and file rules.
Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
Against Fortinet FortiProxy, Zscaler Internet Access, Cisco Umbrella, Cloudflare One Gateway and Sophos Firewall — on layer, TLS, roaming, CASB, price, scale and India.
| Dimension | Kaspersky Web Traffic Security | Fortinet FortiProxy | Zscaler Internet Access | Cisco Umbrella | Cloudflare One Gateway | Sophos Firewall (web) |
|---|---|---|---|---|---|---|
| What it is | On-prem proxy + ICAP | On-prem SWG appliance | Cloud inline proxy | Cloud DNS + proxy | Cloud DNS + HTTP filter | Firewall web module |
| Deployment | VM image or DEB | Hardware, VM or cloud | Cloud only | Cloud, resolver change | Cloud, WARP client | XGS appliance at edge |
| Enforcement layer | Proxy only | Proxy only | Proxy | DNS and proxy | DNS and proxy | Proxy at the edge |
| TLS inspection | Full, four actions | Full SSL decryption | Full | Selective | Full | Full, in Xstream |
| Off-network users | No roaming agent | PAC or SSL-VPN | Client Connector | Roaming client | WARP client | Office only |
| CASB and DLP | File rules only | Inline CASB, OCR DLP | Inline and API | API CASB | Inline and API | None documented |
| Pricing model | Per user, in bands | Per user seat | Per user, by edition | Per user, by tier | Per user per month | Bundle per appliance |
| Published entry price | Not published | Not published | ~$6–12 reported | $2.25–6.50/user/mo | Free to 50, then $7 | Bundle quote |
| Scale | 20 nodes, 757 Mbps | Up to 60,000 users | Large estates verified | Large estates verified | No user cap | Unverified past 5,000 |
| Integrations | AD, SIEM, KATA, SNMP | Fortinet Security Fabric | Zero Trust Exchange | Cisco console | Cloudflare One suite | Sophos Central |
| India and logs | Your servers | Your servers | Four Indian cities | Mumbai and Chennai | Six Indian cities | Your edge |
| Analyst standing | Not ranked for SSE | SASE MQ Challenger | SSE Leader, 2026 | Placement unconfirmed | SSE Visionary, 2026 | Not ranked for SSE |
| Lock-in and exit | Keep proxy, swap scanner | Fortinet hardware | Cloud policy, new cert | Revert a DNS setting | Client and certificate | Tied to the firewall |
| Best fit | Office traffic, own DC | Fortinet, on-prem depth | Deepest cloud proxy | Fast DNS floor | Published price, cloud | Firewall already there |
Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.
Kaspersky Web Traffic Security is one of 44 secure web & DNS products TechBag carries. The Secure Web & DNS guide narrows them to a shortlist and shows the reasoning. →
Drag the sliders (users behind the proxy; IT-hour cost). Estimates model IT time spent cleaning web-borne infections and handling access requests at an assumed 1.5 hours per user a year, with 70% of it removed by scanning and category rules at the gateway. Both figures are assumptions. Illustrative.
Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.
Not published: Kaspersky prints no price for Kaspersky Security for Internet Gateway, the SKU that carries Web Traffic Security. Partner price lists sell it per user, in bands, and Kaspersky offers annual or monthly subscription terms; it is also included in Total Security for Business. Hardware, the hypervisor and RED OS (if chosen) are yours to supply. TechBag sizes the nodes first, then quotes in INR with GST.
Best for a web gateway on its own
Best for a broader rollout
Best when endpoints and mail are in scope too
Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.
Tell us your requirements and current tools — we’ll model it against what you spend today.
Take this into your next vendor call — including ours.
What share of users work off the network? KWTS has no roaming agent, so they need a VPN or a second product.
ISO image with its own proxy, or the DEB package behind a proxy you already run and trust over ICAP?
Is your peak Mbps known, and do the node tables cover it with category filtering on, plus 10% for balancing?
Who issues the interception CA, and how will it reach phones, contractors and servers as well as laptops?
Which apps pin certificates or break under Bump? List them for Tunnel or Tunnel with SNI check rules first.
Will proxy logs reach your SIEM in CEF and be kept 180 days, as CERT-In’s 2022 Directions require?
Is a call to Kaspersky Security Network acceptable, or do you need a private KPSN inside your network?
Does the quote name the user band, term, KSIG or Total Security SKU and support level, in INR with GST?
Size the nodes against your peak traffic first, or let a TechBag advisor scope a pilot that puts one department behind the gateway with TLS decryption on.
Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.