Network communication protection rules monitor or block incoming or outgoing data on your network. Rules are not supported in clients installed on Windows server operating systems.
Category | Option | Definition |
|---|---|---|
Rule options | Rule name | Enter a unique name for the rule. This field is required. |
Description | Click Edit to open the description text box. The maximum description length is 2000 characters. The character counter | |
State | Select Enabled or Disabled from the drop-down list. You can also change this parameter on the DLP Rule Set page by selecting a rule or rules and selecting Actions → Change State. The default is Disabled. | |
Severity | A relative measure of the gravity of violating this rule. The default is Warning. The color code that also appears in the DLP Incident Manager is displayed next to the field. | |
Enforce on | Selects the Trellix DLP product enforcing the rule. This rule type is only supported on Trellix DLP Endpoint for Windows | |
Condition tab / Exceptions tab | Classification
| Use the is any data (ALL) option to bypass applying a content classification, or use the is one of (OR) or is all of (AND) options to select predefined classifications. You can use the + icon to add multiple classifications, and define their relationship with the and/or option. Using classification grouping — When you include multiple classifications in a rule, you can group classifications and create a custom expression to optimize a condition using the Boolean AND or OR operations. When more than two rows of conditions are included, a toggle button appears. Click the toggle button to enable custom classification grouping and type the custom classification grouping expression. For example, if classifications 1, 2, and 3 are included in a Classification condition, you can build an expression similar to ((1 AND 2) OR (1 AND 3)). The expressions are simplified using the Boolean logic. The brackets are added automatically to the expression if not included. If an expression has both AND and OR, the classification item numbers with AND logic are grouped first and then the classification item numbers with OR logic are grouped. The AND operation takes precedence over the OR operation and the expression is computed from left to right. A classification grouping expression must include all classification item numbers. |
End-User | Select a user group from the drop-down list. Using the + icon, you can select multiple groups using AND/OR logic. You can exclude groups using the Exceptions tab. Include at least one group before excluding any groups. | |
Network direction | Select checkboxes for incoming, outgoing, or both. | |
Network addresses | Required field. Select a network IP address definition, or click New Item to create one. | |
Network ports | Use default any port, or select a port definition. | |
Application creating the connection | Use default any application or select an application definition. | |
Exceptions
| Actions | Adds or deletes a rule exception. |
Name | Enter a unique name for the exception. This field is required. | |
Description | Optional descriptive text. | |
State | Select Enabled or Disabled from the drop-down list. The exception state is independent from the rule state. | |
End-User | Select a user group from the drop-down list. See above for option details. The exception end-user is independent from the rule end-user. | |
Network direction | Select a network direction. The exception network direction is independent from the rule network direction. | |
Network addresses | Select a network IP address definition. The exception network address is independent from the rule network address. | |
Network ports | Select a network port definition. The exception network port is independent from the rule network port. | |
Application creating the connection | Select an application definition. The exception application is independent from the rule application. | |
Reaction tab Trellix DLP Endpoint Data protection and device protection rules have a granular Action definition. You can define different actions for the following:
| Action | Select an action from the drop-down list. The default is No Action.
For a list of prevent actions for different types of rules, see the available reactions table. |
User Notification | User notification definitions are stored in the DLP Policy in the Policy Catalog. Select a predefined definition, or click New Item to create one. | |
Report Incident | Select the checkbox for the rule to trigger a DLP incident. |