Configuring a DLP Sensor object
A DLP Sensor defines which dictionaries to check. You can match any dictionary or all dictionaries. It can also count the number of dictionary matches to trigger the sensor.
Before you begin:
- You must have a valid FortiGuard DLP service license and have enabled the service on FortiADC. For details, see FortiGuard DLP service.
- Configure a DLP Dictionary object. For details, see Configuring a DLP Dictionary object.
Predefined DLP Sensor objects
You can use the following predefined DLP Sensor objects in Data Loss Prevention rules.
Predefined DLP Sensor object |
Match Type |
Description |
Dictionaries |
---|---|---|---|
can-hia |
Any |
Canadian Health Information Act (HIA) Sensor |
|
can-pii |
Any |
Canadian Personal Identifiable Information (PII) Sensor |
|
source_code |
Any |
Source Code Sensor |
|
To configure a DLP Sensor:
- Go to Web Application Firewall > Data Loss Prevention.
- Click the DLP Sensor tab.
- Click Create New to display the configuration editor.
- Configure the following DLP Sensor settings:
Setting
Description
Name Specify a name for the DLP Sensor object.
Valid characters areA
-Z
,a
-z
,0
-9
,_
, and-
. No spaces. The configuration name cannot be edited once it has been saved.Match Type Select the match type:
Any — Data meeting the criteria specified by any one of the dictionaries will be identified as a match.
All — Data meeting the criteria specified by all dictionaries will be identified as a match.
The default is Any.
Description Comments about this DLP Sensor object. - Click Save.
After the DLP Sensor configuration is saved, the Dictionaries section becomes available to configure. - Under the Dictionaries section, click Create New to display the configuration editor.
- Configure the following Dictionaries settings for the DLP Sensor:
Setting
Description
Status Enable the Status if you intend to apply this sensor. DLP Dictionary Select a DLP Dictionary object from the drop-down menu. Count Specify the occurrence threshold for the dictionary match. The sensor will be triggered when the dictionary match reaches the specified number of times. Default: 1 Range: 1-255.
For example, if the dictionary applies to credit card numbers and the count is set to 4, the sensor will be triggered when credit card number occurs four times in the HTTP request or response.
- Click Save.
Once the Dictionaries configuration is saved, the editor dialog closes. - Click Save to update the DLP Sensor configuration.
Once the DLP Sensor is saved, you can reference it in a DLP Policy.