config dlp sensor
Configure DLP sensors.
config dlp sensor Description: Configure DLP sensors. edit <name> set comment {var-string} set replacemsg-group {string} config filter Description: Set up DLP filters for this sensor. edit <id> set name {string} set severity [info|low|...] set type [file|message] set proto {option1}, {option2}, ... set filter-by [credit-card|ssn|...] set file-size {integer} set company-identifier {string} set sensitivity <name1>, <name2>, ... set match-percentage {integer} set file-type {integer} set regexp {string} set archive [disable|enable] set action [allow|log-only|...] set expiry {user} next end set dlp-log [enable|disable] set nac-quar-log [enable|disable] set full-archive-proto {option1}, {option2}, ... set summary-proto {option1}, {option2}, ... next end
config dlp sensor
Parameter |
Description |
Type |
Size |
Default |
||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
name |
Name of the DLP sensor. |
string |
Maximum length: 35 |
|
||||||||||||||||||||||
comment |
Comment. |
var-string |
Maximum length: 255 |
|
||||||||||||||||||||||
replacemsg-group |
Replacement message group used by this DLP sensor. |
string |
Maximum length: 35 |
|
||||||||||||||||||||||
dlp-log |
Enable/disable DLP logging. |
option |
- |
enable |
||||||||||||||||||||||
|
|
|||||||||||||||||||||||||
nac-quar-log |
Enable/disable NAC quarantine logging. |
option |
- |
disable |
||||||||||||||||||||||
|
|
|||||||||||||||||||||||||
full-archive-proto |
Protocols to always content archive. |
option |
- |
|
||||||||||||||||||||||
|
|
|||||||||||||||||||||||||
summary-proto |
Protocols to always log summary. |
option |
- |
|
||||||||||||||||||||||
|
|
config filter
Parameter |
Description |
Type |
Size |
Default |
||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
id |
ID. |
integer |
Minimum value: 0 Maximum value: 4294967295 |
0 |
||||||||||||||||||||||
name |
Filter name. |
string |
Maximum length: 35 |
|
||||||||||||||||||||||
severity |
Select the severity or threat level that matches this filter. |
option |
- |
medium |
||||||||||||||||||||||
|
|
|||||||||||||||||||||||||
type |
Select whether to check the content of messages (an email message) or files (downloaded files or email attachments). |
option |
- |
file |
||||||||||||||||||||||
|
|
|||||||||||||||||||||||||
proto |
Check messages or files over one or more of these protocols. |
option |
- |
|
||||||||||||||||||||||
|
|
|||||||||||||||||||||||||
filter-by |
Select the type of content to match. |
option |
- |
credit-card |
||||||||||||||||||||||
|
|
|||||||||||||||||||||||||
file-size |
Match files this size or larger. |
integer |
Minimum value: 0 Maximum value: 4294967295 |
10 |
||||||||||||||||||||||
company-identifier |
Enter a company identifier watermark to match. Only watermarks that your company has placed on the files are matched. |
string |
Maximum length: 35 |
|
||||||||||||||||||||||
sensitivity |
Select a DLP file pattern sensitivity to match. Select a DLP sensitivity. |
string |
Maximum length: 35 |
|
||||||||||||||||||||||
match-percentage |
Percentage of fingerprints in the fingerprint databases designated with the selected sensitivity to match. |
integer |
Minimum value: 1 Maximum value: 100 |
10 |
||||||||||||||||||||||
file-type |
Select the number of a DLP file pattern table to match. |
integer |
Minimum value: 0 Maximum value: 4294967295 |
0 |
||||||||||||||||||||||
regexp |
Enter a regular expression to match (max. 255 characters). |
string |
Maximum length: 255 |
|
||||||||||||||||||||||
archive |
Enable/disable DLP archiving. |
option |
- |
disable |
||||||||||||||||||||||
|
|
|||||||||||||||||||||||||
action |
Action to take with content that this DLP sensor matches. |
option |
- |
allow |
||||||||||||||||||||||
|
|
|||||||||||||||||||||||||
expiry |
Quarantine duration in days, hours, minutes (format = dddhhmm). |
user |
Not Specified |
5m |