Fortinet white logo
Fortinet white logo

CLI Reference

config dlp sensor

config dlp sensor

Configure DLP sensors.

config dlp sensor
    Description: Configure DLP sensors.
    edit <name>
        set comment {var-string}
        set dlp-log [enable|disable]
        set extended-log [enable|disable]
        config filter
            Description: Set up DLP filters for this sensor.
            edit <id>
                set action [allow|log-only|...]
                set archive [disable|enable]
                set company-identifier {string}
                set expiry {user}
                set file-size {integer}
                set file-type {integer}
                set filter-by [credit-card|ssn|...]
                set match-percentage {integer}
                set name {string}
                set proto {option1}, {option2}, ...
                set regexp {string}
                set sensitivity <name1>, <name2>, ...
                set severity [info|low|...]
                set type [file|message]
            next
        end
        set full-archive-proto {option1}, {option2}, ...
        set nac-quar-log [enable|disable]
        set options {option}
        set replacemsg-group {string}
        set summary-proto {option1}, {option2}, ...
    next
end

config dlp sensor

Parameter

Description

Type

Size

comment

Comment.

var-string

Maximum length: 255

dlp-log

Enable/disable DLP logging.

option

-

Option

Description

enable

Enable DLP logging.

disable

Disable DLP logging.

extended-log

Enable/disable extended logging for data leak prevention.

option

-

Option

Description

enable

Enable setting.

disable

Disable setting.

full-archive-proto

Protocols to always content archive.

option

-

Option

Description

smtp

SMTP.

pop3

POP3.

imap

IMAP.

http-get

HTTP GET.

http-post

HTTP POST.

ftp

FTP.

nntp

NNTP.

mapi

MAPI.

ssh

SFTP and SCP.

nac-quar-log

Enable/disable NAC quarantine logging.

option

-

Option

Description

enable

Enable NAC quarantine logging.

disable

Disable NAC quarantine logging.

name

Name of the DLP sensor.

string

Maximum length: 35

options

Configure DLP options.

option

-

replacemsg-group

Replacement message group used by this DLP sensor.

string

Maximum length: 35

summary-proto

Protocols to always log summary.

option

-

Option

Description

smtp

SMTP.

pop3

POP3.

imap

IMAP.

http-get

HTTP GET.

http-post

HTTP POST.

ftp

FTP.

nntp

NNTP.

mapi

MAPI.

ssh

SFTP and SCP.

config filter

Parameter

Description

Type

Size

action

Action to take with content that this DLP sensor matches.

option

-

Option

Description

allow

Allow the content to pass through the FortiGate and do not create a log message.

log-only

Allow the content to pass through the FortiGate, but write a log message.

block

Block the content and write a log message.

quarantine-ip

Quarantine all traffic from the IP address and write a log message.

archive

Enable/disable DLP archiving.

option

-

Option

Description

disable

No DLP archiving.

enable

Enable full DLP archiving.

company-identifier

Enter a company identifier watermark to match. Only watermarks that your company has placed on the files are matched.

string

Maximum length: 35

expiry

Quarantine duration in days, hours, minutes format (dddhhmm).

user

Not Specified

file-size

Match files this size or larger (0 - 4294967295 kbytes).

integer

Minimum value: 0 Maximum value: 4294967295

file-type

Select the number of a DLP file pattern table to match.

integer

Minimum value: 0 Maximum value: 4294967295

filter-by

Select the type of content to match.

option

-

Option

Description

credit-card

Match credit cards.

ssn

Match social security numbers.

regexp

Use a regular expression to match content.

file-type

Match a DLP file pattern list.

file-size

Match any file over with a size over the threshold.

fingerprint

Match against a fingerprint sensitivity.

watermark

Look for defined file watermarks.

encrypted

Look for encrypted files.

id

ID.

integer

Minimum value: 0 Maximum value: 4294967295

match-percentage *

Percentage of fingerprints in the fingerprint databases designated with the selected sensitivity to match.

integer

Minimum value: 1 Maximum value: 100

name

Filter name.

string

Maximum length: 35

proto

Check messages or files over one or more of these protocols.

option

-

Option

Description

smtp

SMTP.

pop3

POP3.

imap

IMAP.

http-get

HTTP GET.

http-post

HTTP POST.

ftp

FTP.

nntp

NNTP.

mapi

MAPI.

ssh

SFTP and SCP.

regexp

Enter a regular expression to match (max. 255 characters).

string

Maximum length: 255

sensitivity <name>

Select a DLP file pattern sensitivity to match.

Select a DLP sensitivity.

string

Maximum length: 35

severity

Select the severity or threat level that matches this filter.

option

-

Option

Description

info

Informational.

low

Low.

medium

Medium.

high

High.

critical

Critical.

type

Select whether to check the content of messages (an email message) or files (downloaded files or email attachments).

option

-

Option

Description

file

Check the contents of downloaded or attached files.

message

Check the contents of email messages, web pages, etc.

* This parameter may not exist in some models.

config dlp sensor

config dlp sensor

Configure DLP sensors.

config dlp sensor
    Description: Configure DLP sensors.
    edit <name>
        set comment {var-string}
        set dlp-log [enable|disable]
        set extended-log [enable|disable]
        config filter
            Description: Set up DLP filters for this sensor.
            edit <id>
                set action [allow|log-only|...]
                set archive [disable|enable]
                set company-identifier {string}
                set expiry {user}
                set file-size {integer}
                set file-type {integer}
                set filter-by [credit-card|ssn|...]
                set match-percentage {integer}
                set name {string}
                set proto {option1}, {option2}, ...
                set regexp {string}
                set sensitivity <name1>, <name2>, ...
                set severity [info|low|...]
                set type [file|message]
            next
        end
        set full-archive-proto {option1}, {option2}, ...
        set nac-quar-log [enable|disable]
        set options {option}
        set replacemsg-group {string}
        set summary-proto {option1}, {option2}, ...
    next
end

config dlp sensor

Parameter

Description

Type

Size

comment

Comment.

var-string

Maximum length: 255

dlp-log

Enable/disable DLP logging.

option

-

Option

Description

enable

Enable DLP logging.

disable

Disable DLP logging.

extended-log

Enable/disable extended logging for data leak prevention.

option

-

Option

Description

enable

Enable setting.

disable

Disable setting.

full-archive-proto

Protocols to always content archive.

option

-

Option

Description

smtp

SMTP.

pop3

POP3.

imap

IMAP.

http-get

HTTP GET.

http-post

HTTP POST.

ftp

FTP.

nntp

NNTP.

mapi

MAPI.

ssh

SFTP and SCP.

nac-quar-log

Enable/disable NAC quarantine logging.

option

-

Option

Description

enable

Enable NAC quarantine logging.

disable

Disable NAC quarantine logging.

name

Name of the DLP sensor.

string

Maximum length: 35

options

Configure DLP options.

option

-

replacemsg-group

Replacement message group used by this DLP sensor.

string

Maximum length: 35

summary-proto

Protocols to always log summary.

option

-

Option

Description

smtp

SMTP.

pop3

POP3.

imap

IMAP.

http-get

HTTP GET.

http-post

HTTP POST.

ftp

FTP.

nntp

NNTP.

mapi

MAPI.

ssh

SFTP and SCP.

config filter

Parameter

Description

Type

Size

action

Action to take with content that this DLP sensor matches.

option

-

Option

Description

allow

Allow the content to pass through the FortiGate and do not create a log message.

log-only

Allow the content to pass through the FortiGate, but write a log message.

block

Block the content and write a log message.

quarantine-ip

Quarantine all traffic from the IP address and write a log message.

archive

Enable/disable DLP archiving.

option

-

Option

Description

disable

No DLP archiving.

enable

Enable full DLP archiving.

company-identifier

Enter a company identifier watermark to match. Only watermarks that your company has placed on the files are matched.

string

Maximum length: 35

expiry

Quarantine duration in days, hours, minutes format (dddhhmm).

user

Not Specified

file-size

Match files this size or larger (0 - 4294967295 kbytes).

integer

Minimum value: 0 Maximum value: 4294967295

file-type

Select the number of a DLP file pattern table to match.

integer

Minimum value: 0 Maximum value: 4294967295

filter-by

Select the type of content to match.

option

-

Option

Description

credit-card

Match credit cards.

ssn

Match social security numbers.

regexp

Use a regular expression to match content.

file-type

Match a DLP file pattern list.

file-size

Match any file over with a size over the threshold.

fingerprint

Match against a fingerprint sensitivity.

watermark

Look for defined file watermarks.

encrypted

Look for encrypted files.

id

ID.

integer

Minimum value: 0 Maximum value: 4294967295

match-percentage *

Percentage of fingerprints in the fingerprint databases designated with the selected sensitivity to match.

integer

Minimum value: 1 Maximum value: 100

name

Filter name.

string

Maximum length: 35

proto

Check messages or files over one or more of these protocols.

option

-

Option

Description

smtp

SMTP.

pop3

POP3.

imap

IMAP.

http-get

HTTP GET.

http-post

HTTP POST.

ftp

FTP.

nntp

NNTP.

mapi

MAPI.

ssh

SFTP and SCP.

regexp

Enter a regular expression to match (max. 255 characters).

string

Maximum length: 255

sensitivity <name>

Select a DLP file pattern sensitivity to match.

Select a DLP sensitivity.

string

Maximum length: 35

severity

Select the severity or threat level that matches this filter.

option

-

Option

Description

info

Informational.

low

Low.

medium

Medium.

high

High.

critical

Critical.

type

Select whether to check the content of messages (an email message) or files (downloaded files or email attachments).

option

-

Option

Description

file

Check the contents of downloaded or attached files.

message

Check the contents of email messages, web pages, etc.

* This parameter may not exist in some models.