config dlp profile
Configure DLP profiles.
config dlp profile
Description: Configure DLP profiles.
edit <name>
set comment {var-string}
set dlp-log [enable|disable]
set extended-log [enable|disable]
set fabric-force-sync [enable|disable]
set fabric-object [enable|disable]
set fabric-object-source [member|local|...]
set feature-set [flow|proxy]
set fortidata-error-action [log-only|block|...]
set fortidata-scan-timeout {integer}
set full-archive-proto {option1}, {option2}, ...
set nac-quar-log [enable|disable]
set replacemsg-group {string}
config rule
Description: Set up DLP rules for this profile.
edit <id>
set action [allow|log-only|...]
set archive [disable|enable]
set expiry {user}
set file-size {integer}
set file-type {integer}
set filter-by [sensor|label|...]
set label {string}
set match-percentage {integer}
set name {string}
set proto {option1}, {option2}, ...
set sensitivity <name1>, <name2>, ...
set sensor <name1>, <name2>, ...
set severity [info|low|...]
set type [file|message]
next
end
set summary-proto {option1}, {option2}, ...
set uuid {uuid}
next
end
config dlp profile
|
Parameter |
Description |
Type |
Size |
Default |
||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
comment |
Comment. |
var-string |
Maximum length: 255 |
|
||||||||||||||||||||||||
|
dlp-log |
Enable/disable DLP logging. |
option |
- |
enable |
||||||||||||||||||||||||
|
|
|
|||||||||||||||||||||||||||
|
extended-log |
Enable/disable extended logging for data loss prevention. |
option |
- |
disable |
||||||||||||||||||||||||
|
|
|
|||||||||||||||||||||||||||
|
fabric-force-sync * |
Enable/disable forced synchronization of configuration objects from the root FortiGate unit to the downstream devices. Configuration conflict check is skipped. |
option |
- |
disable |
||||||||||||||||||||||||
|
|
|
|||||||||||||||||||||||||||
|
fabric-object * |
Security Fabric global object setting. |
option |
- |
disable |
||||||||||||||||||||||||
|
|
|
|||||||||||||||||||||||||||
|
fabric-object-source * |
Source of truth for fabric object. |
option |
- |
root |
||||||||||||||||||||||||
|
|
|
|||||||||||||||||||||||||||
|
feature-set |
Flow/proxy feature set. |
option |
- |
flow |
||||||||||||||||||||||||
|
|
|
|||||||||||||||||||||||||||
|
fortidata-error-action |
Action to take if FortiData query fails. |
option |
- |
block |
||||||||||||||||||||||||
|
|
|
|||||||||||||||||||||||||||
|
fortidata-scan-timeout * |
FortiData inline scan timeout in seconds (10 - 30, default = 15). |
integer |
Minimum value: 10 Maximum value: 30 |
15 |
||||||||||||||||||||||||
|
full-archive-proto |
Protocols to always content archive. |
option |
- |
|
||||||||||||||||||||||||
|
|
|
|||||||||||||||||||||||||||
|
nac-quar-log |
Enable/disable NAC quarantine logging. |
option |
- |
disable |
||||||||||||||||||||||||
|
|
|
|||||||||||||||||||||||||||
|
name |
Name of the DLP profile. |
string |
Maximum length: 47 |
|
||||||||||||||||||||||||
|
replacemsg-group |
Replacement message group used by this DLP profile. |
string |
Maximum length: 35 |
|
||||||||||||||||||||||||
|
summary-proto |
Protocols to always log summary. |
option |
- |
|
||||||||||||||||||||||||
|
|
|
|||||||||||||||||||||||||||
|
uuid * |
Universally Unique Identifier (UUID; automatically assigned but can be manually reset). |
uuid |
Not Specified |
00000000-0000-0000-0000-000000000000 |
||||||||||||||||||||||||
* This parameter may not exist in some models.
config rule
|
Parameter |
Description |
Type |
Size |
Default |
||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
action |
Action to take with content that this DLP profile matches. |
option |
- |
allow |
||||||||||||||||||||||||
|
|
|
|||||||||||||||||||||||||||
|
archive |
Enable/disable DLP archiving. |
option |
- |
disable |
||||||||||||||||||||||||
|
|
|
|||||||||||||||||||||||||||
|
expiry |
Quarantine duration in days, hours, minutes (format = dddhhmm). |
user |
Not Specified |
5m |
||||||||||||||||||||||||
|
file-size |
Match files greater than or equal to this size (KB). |
integer |
Minimum value: 0 Maximum value: 1644544 ** |
0 |
||||||||||||||||||||||||
|
file-type |
Select the number of a DLP file pattern table to match. |
integer |
Minimum value: 0 Maximum value: 4294967295 |
0 |
||||||||||||||||||||||||
|
filter-by |
Select the type of content to match. |
option |
- |
none |
||||||||||||||||||||||||
|
|
|
|||||||||||||||||||||||||||
|
id |
ID. |
integer |
Minimum value: 0 Maximum value: 4294967295 |
0 |
||||||||||||||||||||||||
|
label |
Select DLP label. |
string |
Maximum length: 35 |
|
||||||||||||||||||||||||
|
match-percentage * |
Percentage of fingerprints in the fingerprint databases designated with the selected sensitivity to match. |
integer |
Minimum value: 1 Maximum value: 100 |
10 |
||||||||||||||||||||||||
|
name |
Filter name. |
string |
Maximum length: 35 |
|
||||||||||||||||||||||||
|
proto |
Check messages or files over one or more of these protocols. |
option |
- |
|
||||||||||||||||||||||||
|
|
|
|||||||||||||||||||||||||||
|
sensitivity |
Select a DLP file pattern sensitivity to match. Select a DLP sensitivity. |
string |
Maximum length: 35 |
|
||||||||||||||||||||||||
|
sensor |
Select DLP sensors. Sensor name. |
string |
Maximum length: 35 |
|
||||||||||||||||||||||||
|
severity |
Select the severity or threat level that matches this filter. |
option |
- |
medium |
||||||||||||||||||||||||
|
|
|
|||||||||||||||||||||||||||
|
type |
Select whether to check the content of messages (an email message) or files (downloaded files or email attachments). |
option |
- |
file |
||||||||||||||||||||||||
|
|
|
|||||||||||||||||||||||||||
* This parameter may not exist in some models.
** Values may differ between models.