Web protection rules block data from being posted to websites, including web-based email sites.
Supported browsers are Microsoft Internet Explorer, Microsoft Edge, Mozilla Firefox, and Google Chrome.
Category | Option | Definition |
|---|---|---|
Rule options | Rule name | Enter a unique name for the rule. This field is required. |
Description | Click Edit to open the description text box. The maximum description length is 2000 characters. The character counter in the lower left of the window shows the number of characters still available. This field is optional. | |
State | Select Enabled or Disabled from the drop-down list. You can also change this parameter on the DLP Rule Set page by selecting a rule or rules and selecting Actions → Change State. The default is Disabled. | |
Severity | A relative measure of the gravity of violating this rule. The default is Warning. The color code that also appears in the DLP Incident Manager is displayed next to the field. | |
Enforce on | Selects the Trellix DLP product enforcing the rule. The options are to enforce on either Trellix DLP Endpoint for Windows and McAfee Network DLP ( Trellix DLP Network Prevent). | |
Condition tab
| Classification | Use the is any data (ALL) option to bypass applying a content classification, or use the is one of (OR) or is all of (AND) options to select predefined classifications. You can use the + icon to add multiple classifications, and define their relationship with the and/or option. |
End-User | Select a user group from the drop-down list. Using the + icon, you can select multiple groups using AND/OR logic. You can exclude groups using the Exceptions tab. Include at least one group before excluding any groups. | |
Web address (URL) | Select a URL list definition or reputation. To add a URL definition to the list of values, select is one of (OR), and click ..., then select New Item. | |
Upload type | is any data upload inspects all web uploads. is file upload inspects only files. This option allows other data types, such as webmail or web forms, to be uploaded without inspection. | |
Exceptions tab
| Actions | Adds or deletes a rule exception. |
Name | Enter a unique name for the exception. This field is required. | |
Description | Optional descriptive text. | |
State | Select Enabled or Disabled from the drop-down list. The exception state is independent from the rule state. | |
Classification | Select a classification. See above for option details. The exception classification is independent from the rule classification | |
End-User | Select a user group from the drop-down list. See above for option details. The exception end-user is independent from the rule end-user. | |
Web address (URL) | Select a URL list definition or reputation. The exception web address is independent from the rule web address. | |
Upload type | Select an upload type. The exception upload type is independent from the rule upload type. | |
Reaction tab Data protection and device protection rules have a granular Action definition. You can define different actions for the following:
| Action | Select an action from the drop-down list. The default is No Action.
For a list of actions for different types of rules, see the available reactions table. |
User Notification | User notification definitions are stored in the DLP Policy in the Policy Catalog. Select a predefined definition, or click New Item to create one. For connected computers, you can also set when to close the notification. | |
Report Incident | Select the checkbox for the rule to trigger a DLP incident. | |
Store original file as evidence | Select to store the original file as evidence. If the hit highlighting option is enabled for the evidence server, the trigger text is highlighted and stored as a separate file. |