By default, Trellix DLP Network Monitor analyzes all protocol traffic. You can create extra rules that filter the protocol traffic in priority order. This improves performance and stops incidents being created for protocols that are not relevant to your requirements.
Trellix DLP Network Monitor analyzes the traffic rules in a top-down priority order. The analysis stops when it finds a match, and takes the corresponding action.
If there is an HTTP conversation between a client 1.2.3.4 and a server 2.3.4.5, there are two transactions over the same TCP connection. As a result, the traffic filtering rules are evaluated separately. For example:
The HTTP request (source 1.2.3.4:9999, destination 2.3.4.5:80)
The HTTP response (source 2.3.4.5:80, destination 1.2.3.4:9999)
Tip
If your organization's network range is, for example, 192.168.0.0/16:
Filter out protocols or hosts that you do not want to analyze.
Analyze all traffic where the source address is in the range 192.168.0.0/16.
Do not analyze the remaining traffic.
In ePO - On-prem, open the Policy Catalog.
Select the DLP Appliance Management product, select the Trellix DLP Network Monitor Settings category, and open the policy that you want to edit.
In the Traffic Rules section, click + to open the Define Rule dialog box.
Type a name for the rule, then click + to specify the network attributes you want the rule to filter on.
Each attribute can only be added once to a rule.
Source IP Address — Specify an IP address or an IP address and netmask.
Destination IP Address — Specify an IP address or an IP address and netmask.
Source Port — Specify a port in the range of 0-65535.
Destination Port — Specify a port in the range 0-65535.
VLAN ID — Specify the VLAN tag ID. Untagged traffic uses the default 4095 ID.
Transport Protocol — Choose from TCP or UDP.
Application Protocol — Select the protocol you want the rule to match on.
SOCKS Encapsulation — Select whether the traffic is encapsulated.
Sender Email Address — Specify the sender email address to match against.
Recipient Email Address List — Specify the recipient email address to match against.
URL — Specify the HTTP URL.
Select the match operator and select or type the value for the attribute you are adding, then click Update.
Add more criteria as needed and click OK to return to DLP Network Monitor Settings.
The rule is added to the top of the list.
Use the arrows to position the new rule where you want it in the priority order and optionally select Scan Traffic.