Use Trellix DLP Network Monitor to learn about the quantity and types of data transferred across the network. Trellix DLP Network Monitor does not block or change network traffic, so you can integrate it into a production environment without impacting live traffic.
The router receives network packets from internal users and servers.
Trellix DLP Network Monitor connects to either a Switched Port Analyzer (SPAN) port or a network tap to passively monitor live traffic received from the router.
Trellix DLP Network Monitor receives copies of network packets and analyzes them. Sends incidents to ePO - On-prem.
ePO - On-prem sends policy to Trellix DLP Network Monitor.
Registered documents server defines sensitive information to protect it from being distributed in unauthorized ways.
.png)
Types of protection rules
Trellix DLP Network Monitor can apply one of these Trellix DLP protection rules to your network traffic.
Email Protection — By default, Trellix DLP Network Monitor inspects SMTP traffic using email protection rules, which incorporate protocol-specific information such as sender and recipient email addresses.
Web Protection — By default, Trellix DLP Network Monitor inspects HTTP and FTP traffic using web protection rules, which incorporate protocol-specific information such as the URL.
Network Communication Protection — Trellix DLP Network Monitor can inspect all supported traffic using network communication protection rules, which do not incorporate any protocol-specific information.
If you don't want to analyze SMTP, HTTP, or FTP traffic with email and web protection rules, you can configure Trellix DLP Network Monitor to use network communication protection rules. To disable the analysis of SMTP, HTTP, or FTP traffic, go to Menu → Policy Catalog → DLP Appliance Management → Trellix DLP Network Monitor Settings and deselect the options in the Protocol Rule Application field.
Note
Using Email Protection and Web Protection rules allows you to share rules with Trellix DLP Network Prevent.
Supported protocols
SMTP*
IMAP*
POP3*
HTTP
LDAP
Telnet
FTP
IRC
SMB**
Trellix DLP Network Monitor can also analyze traffic that is encapsulated in SOCKS.
* These protocols support STARTTLS (plain text initial connection converted to TLS/SSL after STARTTLS command). Trellix DLP Network Monitor treats these protocols as encrypted and does not analyze them if STARTTLS is used.
** Data transferred using SMB might be encrypted depending on the version of the protocol and your configuration.
Note
Trellix DLP Network Monitor does not analyze the content of encrypted connections directly. You can use a dedicated gateway (for example, the SSL Tap feature in Web Gateway), to intercept the encrypted connection and send the decrypted data to Trellix DLP Network Monitor for analysis. See the documentation for your gateway for information. If Trellix DLP Network Monitor can't classify a connection as a known protocol, it shows the connection as unknown.