Integrating Trellix DLP Network Prevent in your web environment

Prev Next

Trellix DLP Network Prevent works with your web proxy to protect web traffic.

Trellix DLP Network Prevent uses ICAP or ICAPS (ICAP over TLS) to process web traffic, which uses these ports:

  • ICAP — 1344

  • ICAPS — 11344

Use this workflow to configure your environment for web protection.

  1. Configure endpoint clients to send web traffic to the web proxy.

  2. Configure the web proxy to forward HTTP traffic to Trellix DLP Network Prevent via ICAP.

  3. Configure policy on Trellix DLP Network Prevent to specify the action to take based on the content of the traffic. Example: Configure a rule to allow or block traffic from particular users that contains credit card numbers.

After Trellix DLP Network Prevent analyzes the traffic, it performs one of these actions:

  • Allows the traffic and informs the web proxy.

  • Denies the traffic and supplies a block page which is presented to the user.