Trellix DLP Network Prevent – SaaS works with your web proxy to protect web traffic.
Trellix DLP Network Prevent – SaaS uses ICAP or ICAPS (ICAP over TLS) to process web traffic, which uses these ports:
ICAP — 1344
ICAPS — 11344
Use this workflow to configure your environment for web protection.
Configure endpoint clients to send web traffic to the web proxy.
Configure the web proxy to forward HTTP traffic to Trellix DLP Network Prevent – SaaS via ICAP.
Configure policy on Trellix DLP Network Prevent – SaaS to specify the action to take based on the content of the traffic.
Example: Configure a rule to allow or block traffic from particular users that contains credit card numbers.
After Trellix DLP Network Prevent – SaaS analyzes the traffic, it performs one of these actions:
Allows the traffic and informs the web proxy.
Denies the traffic and supplies a block page, which is presented to the user.