Users and groups

Prev Next

Select the registered LDAP servers that you want to push group information to Trellix DLP Network, and add details of Trellix Logon Collector servers.

Option definitions

Option

Definition

Apply Policy

By default, Allow Policy Push is enabled. Deselecting Allow Policy Push doesn't apply the configuration or policy changes you have made and this allows you to review the changes. After reviewing the configuration or policy changes, select Allow Policy Push.

LDAP Servers

  • Server Name — Registered LDAP server

  • Server IP/Domain — The IP address or domain name of a registered LDAP server that you want to use.

    Use the Registered Servers page to connect LDAP servers with ePO - On-prem.

  • Initiate daily synchronization at — Use this field to set the time when the daily synchronization of the appliance with the LDAP servers must happen.

    The default is 3.00 a.m.

  • Delay synchronization start by up to (hours) — Select the checkbox to specify the synchronization delay between the appliances.

    The default is 2 hours. You can set the random synchronization start interval between 1–10 hours.

Appliance Administrators

To expand appliance management capabilities, add up to 5 users with administrator privileges. All administrators must be assigned from the same external AD server.

Password Complexity

To improve appliance security, configure password complexity requirements for the local appliance administrator. Password complexity can only be set for the local administrator account and not administrator accounts added from AD server.

Password complexity allows you to set the minimum length, alphanumeric characters, and special characters required in a password. It also enables to set the expiration time for a password.

Note

The password must be changed only from the appliance console or SSH menu. Setting it through the command line does not synchronize the password for all DLP services. If changed through the command line, the password has to be updated again from the SSH menu.

Trellix Logon Collector

  • Identify users making web requests — Select to enable Trellix Logon Collector with Trellix DLP Network.

  • + — Opens the Add dialog box where you can specify the details of the Trellix Logon Collector server.

    • Server IP or Hostname — The Trellix Logon Collector IP address.

    • Port — The Trellix Logon Collector port. The default port is 61613.

    • Import from file — Browse to a file that contains the Base64 certificate text you copied from Trellix Logon Collector.

    • Paste from clipboard — Add the Base64 certificate text from Trellix Logon Collector.

  • Server — Contains the IP address or host name of the selected Trellix Logon Collector server.

    You can add more than one Trellix - LC.

  • Port — The Trellix Logon Collector port.

Save

Click to save the LDAP server, LDAP synchronization, and Trellix Logon Collector server settings.