Protocol Identifier Template definitions page

Prev Next

Use this page to specify details about protocols for Trellix DLP Network Monitor.

Option definitions

Option

Definition

Name

(Required) Replace the default definition name with a unique name.

Description

(Optional) Use this field for information to identify the definition or indicate when used.

Available Properties

  • Encapsulated — Select whether the traffic (such as SOCKS) is encapsulated

  • Port — Specify the TCP or UDP port that the traffic is sent over. For example, SMTP typically uses port 25

  • Protocol — The protocol that you want to identify, such as SMTP or ICAP

  • Transport — Specify whether the traffic is sent over TCP or UDP, or both

  • VLAN ID — Specify whether the traffic is sent over a VLAN.