Integrating Trellix DLP Network Prevent in your web environment to secure your web environment

Prev Next

The Trellix DLP Network Prevent appliance works with your web proxy to protect web traffic.

Trellix DLP Network Prevent appliance uses ICAP or ICAPS (ICAP over TLS) to process web traffic, which uses these ports:

  • ICAP — 1344

  • ICAPS — 11344

Use this workflow to configure your environment for web protection.

  1. Configure endpoint clients to send web traffic to the web proxy.

  2. Configure the web proxy to forward HTTP traffic to Trellix DLP Network Prevent via ICAP.

  3. Configure policy on the Trellix DLP Network Prevent appliance to specify the action to take based on the content of the traffic.

    Example: Configure a rule to allow or block traffic from particular users that contains credit card numbers.

After the Trellix DLP Network Prevent appliance analyzes the traffic, it performs one of these actions:

  • Allows the traffic and informs the web proxy.

  • Denies the traffic and supplies a block page, which is presented to the user.