Web Application Control rule page

Prev Next

Web application control rules block web pages by URL.

Option definitions

Category

Option

Definition

Rule options

Rule name

Enter a unique name for the rule. This field is required.

Description

Click Edit to open the description text box. The maximum description length is 2000 characters. The character counter in the lower left of the window shows the number of characters still available. This field is optional.

State

Select Enabled or Disabled from the drop-down list. You can also change this parameter on the DLP Rule Set page by selecting a rule or rules and selecting ActionsChange State. The default is Disabled.

Severity

A relative measure of the gravity of violating this rule. The default is Warning. The color code that also appears in the DLP Incident Manager is displayed next to the field.

Enforce on

Selects the Trellix DLP product enforcing the rule. The only option is to enforce on Trellix DLP Endpoint for Windows.

Condition tab

Note

The default ALL can be used instead of a defined parameter.

End-User

Select a user group from the drop-down list. Using the + icon, you can select multiple groups using AND/OR logic. You can exclude groups using the Exceptions tab. Include at least one group before excluding any groups.

Web address (URL)

Select a URL list definition or reputation.

Note

Reputation is not available in the Exceptions tab.

To add a URL definition to the list of values, select is one of (OR), and click ..., then select New Item.

Exceptions tab

Note

The Exceptions tab is optional.

Actions

Adds or deletes a rule exception.

Name

Enter a unique name for the exception. This field is required.

Description

Optional descriptive text.

State

Select Enabled or Disabled from the drop-down list. The exception state is independent from the rule state.

End-User

Select a user group from the drop-down list. See above for option details. The exception end-user is independent from the rule end-user.

Web address (URL)

Select a URL list definition or reputation. The exception web address is independent from the rule web address.

Reaction tab

Data protection and device protection rules have a granular Action definition. You can define different actions for the following:

  • Computer connected to corporate network

  • Computer disconnected from the corporate network

Action

The only action available for web application control rules is Block .

Note

You can also choose to report the incident.

For a list of actions for different types of rules, see the available reactions table.

User Notification

User notification definitions are stored in the DLP Policy in the Policy Catalog. Select a predefined definition, or click New Item to create one.

For connected computers, you can also set when to close the notification.

Report Incident

Select the checkbox for the rule to trigger a DLP incident.