Fortinet white logo
Fortinet white logo

CLI Reference

config dlp sensor

config dlp sensor

Configure sensors used by DLP blocking.

config dlp sensor
    Description: Configure sensors used by DLP blocking.
    edit <name>
        set comment {var-string}
        config entries
            Description: DLP sensor entries.
            edit <id>
                set count {integer}
                set dictionary {string}
                set status [enable|disable]
            next
        end
        set eval {string}
        set fabric-force-sync [enable|disable]
        set fabric-object [enable|disable]
        set fabric-object-source [member|local|...]
        set match-type [match-all|match-any|...]
        set uuid {uuid}
    next
end

config dlp sensor

Parameter

Description

Type

Size

Default

comment

Optional comments.

var-string

Maximum length: 255

eval

Expression to evaluate.

string

Maximum length: 255

fabric-force-sync *

Enable/disable forced synchronization of configuration objects from the root FortiGate unit to the downstream devices. Configuration conflict check is skipped.

option

-

disable

Option

Description

enable

Enable forced synchronization of configuration objects from the root FortiGate unit to the downstream devices.

disable

Disable forced synchronization of configuration objects from the root FortiGate unit to the downstream devices.

fabric-object *

Security Fabric global object setting.

option

-

disable

Option

Description

enable

Object is set as a security fabric-wide global object.

disable

Object is local to this security fabric member.

fabric-object-source *

Source of truth for fabric object.

option

-

root

Option

Description

member

Source of truth for this object is a non-root member of fabric.

local

Source of truth for this object is this security fabric member.

root

Source of truth for this object is the root of the fabric.

match-type

Logical relation between entries (default = match-any).

option

-

match-any

Option

Description

match-all

Match all entries.

match-any

Match any entries.

match-eval

Match an expression evaluation.

name

Name of table containing the sensor.

string

Maximum length: 35

uuid *

Universally Unique Identifier (UUID; automatically assigned but can be manually reset).

uuid

Not Specified

00000000-0000-0000-0000-000000000000

* This parameter may not exist in some models.

config entries

Parameter

Description

Type

Size

Default

count

Count of dictionary matches to trigger sensor entry match (Dictionary might not be able to trigger more than once based on its 'repeat' option, 1 - 255, default = 1).

integer

Minimum value: 1 Maximum value: 255

1

dictionary

Select a DLP dictionary or exact-data-match.

string

Maximum length: 35

id

ID.

integer

Minimum value: 1 Maximum value: 32

0

status

Enable/disable this entry.

option

-

enable

Option

Description

enable

Enable this entry.

disable

Disable this entry.

config dlp sensor

config dlp sensor

Configure sensors used by DLP blocking.

config dlp sensor
    Description: Configure sensors used by DLP blocking.
    edit <name>
        set comment {var-string}
        config entries
            Description: DLP sensor entries.
            edit <id>
                set count {integer}
                set dictionary {string}
                set status [enable|disable]
            next
        end
        set eval {string}
        set fabric-force-sync [enable|disable]
        set fabric-object [enable|disable]
        set fabric-object-source [member|local|...]
        set match-type [match-all|match-any|...]
        set uuid {uuid}
    next
end

config dlp sensor

Parameter

Description

Type

Size

Default

comment

Optional comments.

var-string

Maximum length: 255

eval

Expression to evaluate.

string

Maximum length: 255

fabric-force-sync *

Enable/disable forced synchronization of configuration objects from the root FortiGate unit to the downstream devices. Configuration conflict check is skipped.

option

-

disable

Option

Description

enable

Enable forced synchronization of configuration objects from the root FortiGate unit to the downstream devices.

disable

Disable forced synchronization of configuration objects from the root FortiGate unit to the downstream devices.

fabric-object *

Security Fabric global object setting.

option

-

disable

Option

Description

enable

Object is set as a security fabric-wide global object.

disable

Object is local to this security fabric member.

fabric-object-source *

Source of truth for fabric object.

option

-

root

Option

Description

member

Source of truth for this object is a non-root member of fabric.

local

Source of truth for this object is this security fabric member.

root

Source of truth for this object is the root of the fabric.

match-type

Logical relation between entries (default = match-any).

option

-

match-any

Option

Description

match-all

Match all entries.

match-any

Match any entries.

match-eval

Match an expression evaluation.

name

Name of table containing the sensor.

string

Maximum length: 35

uuid *

Universally Unique Identifier (UUID; automatically assigned but can be manually reset).

uuid

Not Specified

00000000-0000-0000-0000-000000000000

* This parameter may not exist in some models.

config entries

Parameter

Description

Type

Size

Default

count

Count of dictionary matches to trigger sensor entry match (Dictionary might not be able to trigger more than once based on its 'repeat' option, 1 - 255, default = 1).

integer

Minimum value: 1 Maximum value: 255

1

dictionary

Select a DLP dictionary or exact-data-match.

string

Maximum length: 35

id

ID.

integer

Minimum value: 1 Maximum value: 32

0

status

Enable/disable this entry.

option

-

enable

Option

Description

enable

Enable this entry.

disable

Disable this entry.