Talk to us
by KasperskyTechBag Intel Page

Kaspersky Web Traffic Security

Your users reach the web through a proxy. It forwards what it cannot read — Kaspersky Web Traffic Security scans every web request your proxy carries — malware, phishing, categories and files, with TLS decrypted by rule — on nodes you run, so the logs never leave your own data centre.

Scan at the proxy you runLogs on your own serversQuoted per user, in bands

Buy through TechBag

Same software. Better outcome — at a lower cost.

Right-fit discoveryBest price & discountsImplementation & rolloutRenewals & licence mgmtTier-1 support desk
Book a discovery call →

Free · 15 minutes

Trusted by 500+ enterprises across India

How it’s rated

Full scoreboard ↓
Pricing
No Kaspersky price list; partner SKUs are sold per user in bands, annual or monthly
Quote
Throughput
Kaspersky’s top tested 48-core node with anti-virus, anti-phishing and KSN; 452 Mbps adding categories
757 Mbps
Analysts
Kaspersky is not among the nine vendors in Gartner’s 2025 Security Service Edge Magic Quadrant
Not ranked
India
On-premises: events, reports and access logs are stored on the nodes and SIEM you run
Your servers

Quick answer

Kaspersky Web Traffic Security (KWTS) 6.2 is an on-premises secure web gateway: a proxy that scans HTTP, HTTPS and FTP over ICAP, decrypts TLS by certificate replacement, and filters by web category and file type. It runs as a VM image or beside your own proxy, with no cloud PoP and no roaming agent. Partners quote it per user; there is no list price. Logs stay on the servers you run in India. Read more ↓ Show less ↑
Part 01 · Orient

The Kaspersky platform family

This page covers Kaspersky Web Traffic Security — the on-premises web gateway sold as Kaspersky Security for Internet Gateway. The rest:

Quick facts

30-second orientation
Product
On-premises proxy and ICAP web gateway for HTTP, HTTPS and FTP traffic
Maker
Kaspersky, founded 1997 by Eugene and Natalia Kaspersky; Jaydeep Singh is GM for India
Version
6.2.0.155, released 5 October 2025; full support until 30 September 2027
Bought as
Kaspersky Security for Internet Gateway, or inside Total Security for Business
Price
Not published; partners sell it per user, in bands, on annual or monthly terms
Deploy
VM image on Rocky Linux 9.6 or RED OS 8.0, or a DEB package beside your proxy
TLS
Certificate replacement on the proxy; Bump, Tunnel, Tunnel with SNI check, Terminate
Scale
Up to 20 nodes per cluster; Kaspersky’s top tested node peaked at 757 Mbps
India
Runs on your hardware, so logs and reports sit wherever you host the nodes
In India via
TechBag — node sizing, certificate plan, quote in INR with GST
Part 02 · Learn

Understand on-premises web gateways before you buy one

Most product pages skip this. We start here — so you buy a capability, not a buzzword.

What is an on-premises web gateway?

A proxy you run that opens each web request, scans it and decides before it reaches the user.

A bare proxy vs a scanning gateway — the honest table

What consolidation actually replaces, dimension by dimension.

DimensionA bare proxy, blind to HTTPSKaspersky Web Traffic Security
Malware in downloadsPassed through; the endpoint has to catch itScanned at the proxy before it reaches a laptop
HTTPS trafficA blind tunnel the proxy cannot readDecrypted by rule, with pinned apps tunnelled
Who may visit whatA hand-kept blocklist of domainsCategory and file rules tied to AD groups
Proof for auditorsRaw access logs on one boxEvents in CEF to your SIEM, kept as long as you set
Growing trafficA bigger single serverMore nodes in a cluster, up to 20
What it is NOT—A cloud SWG, a roaming agent, a CASB or a DNS filter

The cheapest test is the free trial: deploy one ISO node, point one department's browsers at it, and read a week of events.

Under the hood

The five pieces of the platform

Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.

01
Where users’ web requests arrive

Proxy

Built-in or existing proxy server

The ISO build installs a proxy on every cluster node and manages it from the web console; the DEB build sits beside a proxy you already run and receives its objects over ICAP.

02
Where each object gets a verdict

Scanning

ICAP scanning nodes

Each node scans requests and responses against traffic processing rules: anti-virus, anti-phishing, web categories and file filters, then hands an allow, block or redirect verdict back.

03
Where policy and events live

Control

Control node and web console

One node holds the rules, workspaces and roles and pushes them to the cluster; it also collects events and shows dashboards, reports and node health in the browser console.

04
What the verdicts draw on

Context

Directory, reputation and KATA

Active Directory maps users and groups into rules; Kaspersky Security Network, or a private KPSN, supplies URL and file reputation; KATA can receive files and return detections.

A proxy hands each object to ICAP scanning nodes — rules come from one control node, logs stay on hardware you own.

Part 03 · Evaluate

Nine capabilities. Inspect, control, operate.

Kaspersky Web Traffic Security turns the proxy you run into a gateway that opens, scans and rules on each request.

Inspect
Anti-virus

Malware stripped in transit

Downloads over HTTP, HTTPS and FTP are scanned by machine-learning and emulation engines before they reach a laptop.

Inspect
Anti-phishing

Fake login pages blocked

A separate Anti-Phishing module checks pages and links against Kaspersky’s phishing models and reputation data.

Inspect
TLS bump

Inside encrypted sessions

SSL rules choose Bump, Tunnel, Tunnel with SNI check or Terminate per source or site, so banking apps can pass untouched.

Control
Categories

Web control by category

Access rules allow, block or redirect by category; 6.2 added a Generative AI tools category beside gambling and adult content.

Control
File rules

Uploads and downloads filtered

Files in either direction can be stopped by name, MIME type, size, true format or MD5 and SHA256 checksum.

Control
Directory

Rules by AD group

Kerberos or NTLM single sign-on identifies the user; 6.2 adds domain-forest support so cross-domain group members match.

Operate
Workspaces

One cluster, many tenants

Departments or managed client organisations each get a workspace with their own rules, block page and admin roles.

Operate
SIEM

Events out in CEF

Traffic and system events publish over syslog, in CEF if you choose, and node status is readable over SNMP.

Operate
Cluster

Scale by adding nodes

Up to 20 nodes form one cluster behind a load balancer; Kaspersky suggests one standby node for every five active.

See it, don’t just read it

Watch Kaspersky Web Traffic Security in action

Why scanning belongs at the proxy, the Kaspersky Security Network reputation service it draws on, and a recorded console walkthrough in German.

Kaspersky (official)·Short, 2019

A gatekeeper for your network

A 90-second case for scanning at the proxy, naming Kaspersky Web Traffic Security as the tool.

Kaspersky (official)·Explainer, 2019

Kaspersky Security Network

The cloud reputation service the gateway queries for URLs and files, in under a minute.

Kaspersky Germany (official)·Webinar in German, 2019

Mitschnitt vom 15.02.2019: So funktioniert Kaspersky Web Traffic Security

A recorded 2019 walkthrough of KWTS rules and the console from Kaspersky’s German channel; screens have changed since.

Want a live, India-context walkthrough for your environment?

Book a guided demo →
Why Kaspersky Web Traffic Security

A proxy that cannot read HTTPS waves threats through. KWTS opens and scans them on servers you own.

Here’s what genuinely sets it apart — and exactly where it stops.

01

Inspection that never leaves your building

KWTS runs on virtual machines or servers you own, so decrypted traffic, access logs and reports are stored where you put them — in your Indian data centre if that is the rule. The only outbound call is reputation lookup to Kaspersky Security Network, and a private KPSN removes even that for estates that must keep every query inside.

02

A scanner that fits the proxy you already run

Because it speaks ICAP, KWTS can sit behind a proxy that is already in production and add anti-virus, anti-phishing and category control without re-routing users. Or deploy the ISO image, which brings its own proxy, cluster and TLS bumping in one build. Either way the CERT-In rule that internet access goes through a proxy is met by design.

03

Sized by numbers Kaspersky publishes

The 6.2 help gives tested throughput per node: 44 Mbps on an 8-vCPU virtual machine with anti-virus, anti-phishing and KSN, up to 757 Mbps on a 48-core Xeon server, and roughly 40% less once category filtering is on. A cluster holds 20 nodes. You can size hardware before a pilot rather than after it.

04

Where it stops

Nothing covers a laptop that is not on your network or VPN: there is no roaming agent and no cloud PoP. There is no CASB, no DLP and no DNS-layer service. Prices are quote-only, Gartner has not placed Kaspersky in its SSE quadrant, and US buyers cannot get it at all after the 2024 Commerce ban.

The idea
Scan at the proxy you already run
The residency
Every log on your own servers
The price
Quoted per user, in bands
Proof, not promises

The numbers behind the platform

757 Mbps
peak tested on a 48-core node with anti-virus, anti-phishing and KSN switched on
— Vendor
20 nodes
the most one KWTS cluster may hold, standby nodes included; beyond it, split clusters
— Vendor
4 TLS actions
Bump, Tunnel, Tunnel with SNI check and Terminate, set per SSL rule
— Vendor
1000+ criteria
that Kaspersky says its anti-phishing models weigh, from images to page scripts
— Vendor
2027
the year full support for 6.2 runs to (30 September); limited support follows to 2028
— Vendor
180 days
of logs CERT-In’s 2022 Directions require kept; its FAQ lists proxy-server logs
— Regulator

What your Kaspersky Web Traffic Security rollout looks like

Week 1Model

Map the traffic and the peak

Measure peak Mbps through today’s proxy, list sites and AD groups, and decide between the ISO build and ICAP beside it.

Week 2Decide

Size nodes from the tables

Use Kaspersky’s per-core bandwidth tables to pick node count, add 10% for a load balancer and one standby per five.

Week 3Pilot

Build the cluster and the CA

Deploy nodes in your Indian data centre, issue the interception certificate and push it to every managed device.

Month 2Prove

Turn on Bump, rule by rule

Start with one department, tunnel banking and pinned apps by SNI rule, and track breakage before widening.

Month 3Commit

Wire logs to the SIEM

Send CEF events to your SIEM, set retention to at least 180 days, and agree who approves unblock requests.

Verified reviews

The review scoreboard

Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.

4
38+ reviews*
78% would recommend
Malware and phishing catch4.4
TLS inspection control4.0
Policy and AD rules4.1
Ease of deployment3.7
Value for money3.9
5★
38%
4★
40%
3★
16%
2★
4%
1★
2%

Quick poll — what’s driving your evaluation?

Talk to an advisor
BFSI
“We put KWTS behind our existing proxy over ICAP and had malware scanning on all branches without touching a single PAC file.”
Network Architect
BFSI
Manufacturing
“The sizing tables were close: our 250 Mbps peak needed two Xeon nodes with category filtering on, plus one standby.”
Infrastructure Lead
Manufacturing
Logistics
“Tunnel with SNI check saved us. Our bank portals and a pinned ERP client broke under Bump until we exempted them by rule.”
Security Engineer
Logistics
Healthcare
“Auditors asked where proxy logs live for 180 days. Answer: our own SIEM in Mumbai, fed by CEF from the cluster.”
CISO
Healthcare
Retail
“Workspaces let us run one cluster for three subsidiaries, each with its own rules, block page and admins.”
IT Manager
Retail
Pharma
“It covers the office well, but sales staff on hotel Wi-Fi are outside it unless the VPN is up. Plan for that gap.”
Head of IT
Pharma
The market maps

Where everyone sits — the grids

Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the secure web gateway market — tap any vendor to see why it sits where it does.

Grid 01 · The market

TechBag Secure Web & DNS Grid

Execution strength vs product vision — the classic market map, minus the paywall.

ChallengersLeadersSpecialistsVisionaries
Kaspersky Web Traffic SecurityThis page

On-premises only; quoted per user through partners.

Grid 02 · The architecture

Data-Path Control × Inspection Depth

The grid nobody publishes — how much of the inspection path and its logs you host yourself vs how deep the inspection goes.

Cloud inspection servicesSelf-run inspection proxiesCloud DNS-first filtersEdge appliance filters
Kaspersky Web Traffic SecurityThis page

Self-hosted; full TLS bump, anti-virus, anti-phishing and file rules.

Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.

Part 04 · Decide

Kaspersky Web Traffic Security vs the secure web field

Against Fortinet FortiProxy, Zscaler Internet Access, Cisco Umbrella, Cloudflare One Gateway and Sophos Firewall — on layer, TLS, roaming, CASB, price, scale and India.

DimensionKaspersky Web Traffic SecurityFortinet FortiProxyZscaler Internet AccessCisco UmbrellaCloudflare One GatewaySophos Firewall (web)
What it isOn-prem proxy + ICAPOn-prem SWG applianceCloud inline proxyCloud DNS + proxyCloud DNS + HTTP filterFirewall web module
DeploymentVM image or DEBHardware, VM or cloudCloud onlyCloud, resolver changeCloud, WARP clientXGS appliance at edge
Enforcement layerProxy onlyProxy onlyProxyDNS and proxyDNS and proxyProxy at the edge
TLS inspectionFull, four actionsFull SSL decryptionFullSelectiveFullFull, in Xstream
Off-network usersNo roaming agentPAC or SSL-VPNClient ConnectorRoaming clientWARP clientOffice only
CASB and DLPFile rules onlyInline CASB, OCR DLPInline and APIAPI CASBInline and APINone documented
Pricing modelPer user, in bandsPer user seatPer user, by editionPer user, by tierPer user per monthBundle per appliance
Published entry priceNot publishedNot published~$6–12 reported$2.25–6.50/user/moFree to 50, then $7Bundle quote
Scale20 nodes, 757 MbpsUp to 60,000 usersLarge estates verifiedLarge estates verifiedNo user capUnverified past 5,000
IntegrationsAD, SIEM, KATA, SNMPFortinet Security FabricZero Trust ExchangeCisco consoleCloudflare One suiteSophos Central
India and logsYour serversYour serversFour Indian citiesMumbai and ChennaiSix Indian citiesYour edge
Analyst standingNot ranked for SSESASE MQ ChallengerSSE Leader, 2026Placement unconfirmedSSE Visionary, 2026Not ranked for SSE
Lock-in and exitKeep proxy, swap scannerFortinet hardwareCloud policy, new certRevert a DNS settingClient and certificateTied to the firewall
Best fitOffice traffic, own DCFortinet, on-prem depthDeepest cloud proxyFast DNS floorPublished price, cloudFirewall already there
● Strong◐ Partial / add-on○ Weak / externalCompiled from public vendor materials and review platforms for orientation; verify before relying on it.

Which approach fits you?

Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.

Choose Kaspersky Web Traffic Security if…

  • ✓Most users work on your network and you want a proxy whose decrypted traffic and logs never leave your own hardware
  • ✓You already run a proxy and want anti-virus, anti-phishing and category control added over ICAP without re-routing anyone
  • ✓You can size nodes from published throughput figures and run Linux VMs in your own data centre

Compare alternatives if…

  • ✓Laptops spend much of their time off the network — Zscaler, Cloudflare One and Umbrella carry policy anywhere
  • ✓You need CASB or DLP in the gateway — FortiProxy and the cloud SSE services include them
  • ✓You want a price you can read before a sales call — Cloudflare and Umbrella publish theirs

Do not expect…

  • ✓A cloud PoP, a roaming agent or a DNS-layer service
  • ✓A published price, or a Gartner SSE placement for Kaspersky
  • ✓Availability or updates in the United States after the 2024 Commerce ban

Kaspersky Web Traffic Security is one of 44 secure web & DNS products TechBag carries. The Secure Web & DNS guide narrows them to a shortlist and shows the reasoning. →

Do the math

What do web-borne incidents cost you?

Drag the sliders (users behind the proxy; IT-hour cost). Estimates model IT time spent cleaning web-borne infections and handling access requests at an assumed 1.5 hours per user a year, with 70% of it removed by scanning and category rules at the gateway. Both figures are assumptions. Illustrative.

300
2510,000
₹800
₹300₹2,000

Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.

Current annual web-incident cost
₹3,60,000
Estimated annual savings
₹2,52,000
≈ ₹12,60,000 over 5 years
Turn this into a real quote →
Pricing & plans

Three ways to consume it

Not published: Kaspersky prints no price for Kaspersky Security for Internet Gateway, the SKU that carries Web Traffic Security. Partner price lists sell it per user, in bands, and Kaspersky offers annual or monthly subscription terms; it is also included in Total Security for Business. Hardware, the hypervisor and RED OS (if chosen) are yours to supply. TechBag sizes the nodes first, then quotes in INR with GST.

Security for Internet Gateway

Best for a web gateway on its own

  • Quoted per user, in bands
  • Annual licence or monthly subscription
  • ISO image or DEB package included

+ Platform add-ons

Best for a broader rollout

  • Scoped to your estate
  • Add-on modules as needed
  • Phased, right-sized deployment

Total Security for Business

Best when endpoints and mail are in scope too

  • Web Traffic Security included
  • Quoted through Kaspersky partners
  • Free trial before you commit

Buy it for less — TechBag pricing beats list

Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.

Get a discounted quote →

Get an India-ready quote

Tell us your requirements and current tools — we’ll model it against what you spend today.

Get Quote
Evaluation kit

The 8 questions to ask every vendor

Take this into your next vendor call — including ours.

1
Coverage

What share of users work off the network? KWTS has no roaming agent, so they need a VPN or a second product.

2
Build

ISO image with its own proxy, or the DEB package behind a proxy you already run and trust over ICAP?

3
Sizing

Is your peak Mbps known, and do the node tables cover it with category filtering on, plus 10% for balancing?

4
Certificates

Who issues the interception CA, and how will it reach phones, contractors and servers as well as laptops?

5
Exceptions

Which apps pin certificates or break under Bump? List them for Tunnel or Tunnel with SNI check rules first.

6
Logs

Will proxy logs reach your SIEM in CEF and be kept 180 days, as CERT-In’s 2022 Directions require?

7
Reputation

Is a call to Kaspersky Security Network acceptable, or do you need a private KPSN inside your network?

8
Licence

Does the quote name the user band, term, KSIG or Total Security SKU and support level, in INR with GST?

FAQ

Questions buyers ask

KWTS is Kaspersky’s on-premises secure web gateway. It scans HTTP, HTTPS and FTP passing through a proxy, removes malware, blocks phishing and controls access by web category and file type. Version 6.2.0.155 shipped on 5 October 2025 and has full support until 30 September 2027.

Ready to evaluate Kaspersky Web Traffic Security?

Size the nodes against your peak traffic first, or let a TechBag advisor scope a pilot that puts one department behind the gateway with TLS decryption on.

Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.