Trellix DLP Network Monitor – SaaS inspects several protocols.
SMTP*
IMAP*
POP3*
HTTP
LDAP
Telnet
FTP
IRC
SMB**
Trellix DLP Network Monitor – SaaS can also analyze traffic that is encapsulated in SOCKS.
* These protocols support STARTTLS (plain text initial connection converted to TLS/SSL after STARTTLS command). Trellix DLP Network Monitor – SaaS treats these protocols as encrypted and does not analyze them if STARTTLS is used.
** Data transferred using SMB might be encrypted depending on the version of the protocol and your configuration.
Note
Trellix DLP Network Monitor – SaaS does not analyze the content of encrypted connections directly. You can use a dedicated gateway (for example, the SSL Tap feature in Skyhigh Security Secure Web Gateway), to intercept the encrypted connection and send the decrypted data to Trellix DLP Network Monitor – SaaS for analysis. See the documentation for your gateway for information. If Trellix DLP Network Monitor – SaaS cannot classify a connection as a known protocol, it shows the connection as unknown.