Retrieve and synchronize information from registered LDAP servers

Prev Next

Trellix DLP Network can get user and group information from LDAP servers that are registered with ePO - On-prem. You need to select the registered LDAP servers that you want Trellix DLP Network to get information from.

Make sure that the LDAP servers are registered with ePO - On-prem.

User and groups details are used when evaluating the Sender information. Trellix DLP Network can:

  • Connect to OpenLDAP and Active Directory servers.

  • Communicate with a registered LDAP server over SSL.

  • Configure or set the daily synchronization time of appliances with LDAP servers as synchronizing multiple appliances with LDAP servers at the same time can overload the LDAP servers.

  • Connect to Global Catalog ports instead of standard LDAP ports to retrieve user and group information when querying Active Directory.

    If you configured Active Directory to use Global Catalog ports, make sure that at least one of these attributes is replicated to the Global Catalog server from the domains in the forest:

    • proxyAddresses

    • mail

    If Trellix DLP Network needs to use NTLM or WINNT authentication for analyzing web protection rules, these LDAP attributes must also be replicated:

    • configurationNamingContext

    • netbiosname

    • msDS-PrincipalName

Messages are temporarily rejected with a 451 status code when both of these conditions are met:

  • Trellix DLP Network Prevent uses rules that specify the sender is a member of a particular LDAP user group.

  • Trellix DLP Network Prevent is not configured to receive information from the LDAP server that contains the specified user group.

Events are sent to the Client Events page if synchronization with the LDAP server or an LDAP query fails.

  1. In ePO - On-prem, open the Policy Catalog.

  2. Select the DLP Appliance Management product, choose the Users and groups category, and open the policy that you want to edit.

  3. In LDAP Servers, select at least one valid LDAP server to enable synchronization configuration.

  4. In the Initiate daily synchronization at field, set the daily synchronization time. The default synchronization start time is set to 3 a.m.

    The synchronization of the appliance with LDAP servers happens daily at the configured time.

  5. (Optional) Select and update the Delay synchronization start by up to (hours) field to configure the delay between the synchronization start of appliances. The default synchronization delay between appliances is set to two hours. You can configure the random delay synchronization start interval between 1–10 hours.

  6. Click Save.