General

Prev Next

Apply timeout and load balancing settings to Trellix DLP Network systems. This category is available from Policy CatalogDLP Appliance Management<version>General.

Option definitions

Option

Definition

Apply Policy

By default, Allow Policy Push is enabled. Deselecting Allow Policy Push doesn't apply the configuration or policy changes you have made and this allows you to review the changes. After reviewing the configuration or policy changes, select Allow Policy Push.

Load balancing

  • Enable — Allow the appliance to be part of a cluster.

  • Cluster Id — Add an identifier for the cluster. The identifier must be from 1 — 254.

  • Virtual IP — If load balancing is enabled, add a virtual IP address for all appliances in the cluster to listen to.

    The cluster appliances use the netmask assigned to the physical IP address.

Caution

The cluster ID and virtual IP address of the Trellix DLP Network Monitor cluster must be different from the cluster ID and virtual IP address of the Trellix DLP Network Prevent cluster.

Security mode

Enable FIPS 140-2 mode — When selected, Trellix DLP Network performs cryptographic operations in a way that is compliant with FIPS 140-2. Using FIPS 140-2 can impact performance when analyzing SMTP content.

Analysis Settings

  • Maximum analysis time — The maximum time, in minutes, that Trellix DLP Network Prevent attempts to analyze an email or a web message. For Trellix DLP Network Monitor, this is the maximum time in minutes taken to analyze any network payload.

    The maximum analysis time you can set is 999 minutes.

  • Maximum nesting depth — The maximum depth of .zip file attachments that Trellix DLP Network Prevent or Trellix DLP Network Monitor analyzes.

    The maximum nesting depth you can set is 100.

  • Maximum file size — The maximum file size, in megabytes, of expanded attachments that Trellix DLP Network Prevent or Trellix DLP Network Monitor analyzes.

    The maximum file size you can set for analysis is 2047 MB.

Out-of-Band Management

Disable in-band access to management ports — When selected, Trellix DLP Network Monitor accesses management ports using the management interface rather than the traffic interface.

  • 22 (SSH)

  • 161 (SNMP)

  • 10443 (Local UI)

You can add or remove management ports as needed.

NDLP Scanning Service

Enable scanning service API — When selected, enables the generation of API tokens required to authorize content inspection over API calls integrated with third-party cloud gateways. The generated tokens are pushed to DLP Network Prevent for authorizing API requests, which verifies them via the authorization header.

By default, the port number is set to 941. Click + to generate a new token. It is prefixed with NDLPScan_ followed by 64 randomly generated alphanumeric characters with a total length of 73 characters. The extension creates a secure SHA512 hash of the token and stores the token information in the policy. The generated token and its details are displayed only once. Make sure to copy the token details for future reference as it will not be shown again.

You can edit the Description, Expiry date, and Staus of the token as required.

Trellix DLP Server for Evidence Copy

If your Trellix DLP Network is in a demilitarized zone (DMZ) with no network access to the evidence file share, you can provide the host name or IP address of a DLP Server.

The appliance then sends the evidence files to the configured DLP Server, which in turn copies the evidence files onto the evidence file share.

  • Use TLS — Specify whether TLS encryption is used for the connection.

  • Host — Enter the IP addresses or host names of the DLP Servers.

If multiple DLP servers are configured, the appliance uses a round-robin approach to send the evidence files.

If a DLP server is configured for evidence copy, it is also used for deleting any evidence files associated with DLP Capture searches when you delete a capture search.

Note

Make sure that Evidence Storage HTTP Service is enabled in the Data Loss Prevention <version>Server ConfigurationShared Storage and Evidence page.

Trellix DLP Server for Registered Documents

Connects the Trellix DLP Network system and a Trellix DLP Discover server installed in the DLP Server role.

  • Use TLS — Specify whether TLS encryption is used for the connection.

  • Host — Enter the IP addresses or host names of the Trellix DLP Discover database servers.

Microsoft Information Protection (MIP) Decryption Service

Select the Azure server that is registered for decryption service.

Custom Logon Banner

Display a custom banner (must be plain text) — When selected, you can type your own text for display on the top of the Trellix DLP Network console and SSH logon screen.



Proxy Settings — For information about configuring proxy settings from ePO - On-prem, see Trellix Agent proxy settings.