High level post-installation tasks

Prev Next

Completing the installation includes enabling and configuring the settings and policies for your products.

  1. Configure an evidence server to store the files that trigger a rule.

  2. Configure one or more syslog servers, if necessary.

  3. Configure server settings.

  4. (Optional) Specify a Trellix DLP Discover server configured as Trellix DLP Server in the Policy Catalog to use registered documents in Trellix DLP Network appliance policies.

  5. (Optional) Enable DLP Capture to store email, web, and network data analyzed by your Trellix DLP Network appliances.

  6. (Optional) Enable a cluster of Trellix DLP Network Prevent appliances to load the balance incoming traffic and ensure high availability.

  7. Enable relevant predefined policies and rules.

  8. Create additional classifications, policies, and rules to detect potential data loss incidents.

  9. Assign and push the configurations and policies to the appliances from System Tree.

  10. Integrate with an MTA server or web proxy.

    For Trellix DLP Network Prevent appliances that analyze email traffic:

    • Verify connectivity and mail flow between the mail transfer agent (MTA) server and the Trellix DLP Network Prevent appliance.

    • Confirm that the X-RCIS-Action: Allow header is added to received email.

    For Trellix DLP Network Prevent appliances that analyze web traffic, verify connectivity between the web proxy server and the appliance.

  11. Confirm that incidents are recorded in the DLP Incident Manager.