Integrate DLP Network Prevent with IVX Cloud for enhanced file scanning

Prev Next

To enhance file scanning capabilities, you can integrate DLP Network Prevent with IVX Cloud through the IVX Cloud DLP settings. This integration enables IVX Cloud to query rule match information through the DLP Network Prevent API and execute actions based on your defined policies.

Ensure the following requirements are met:

  • Network configuration: Your firewall must be configured to allow IVX Cloud IPs (11.64.0.0/16 for the IVX Cloud USA region) to access port 941 on your appliance.

  • Version compatibility: To utilize API Tokens for authentication, your DLP Network Prevent appliance must be higher than version 11.11.0.

Configure the DLP Network Prevent settings to connect with IVX Cloud

  1. Log on to the IVX Cloud portal and go to SettingsDLP Settings.

  2. In the DLP Network Prevent tab, select an API key from the dropdown list. If the selected API key does not have DLP scanning enabled, the default values will be loaded.

  3. Provide the following details:

    • Host: Enter the IP address or hostname of your Trellix DLP appliance.

    • Port: Enter the port number where the Trellix DLP applicable is exposed. The default port number is 941.

      IVX Cloud uses this hostname and port to connect to the Trellix DLP appliance through Trellix DLP Prevent API.

    • Timeout: Enter the timeout value (in seconds). The default timeout value is 120 seconds.

      If Trellix DLP responds within the timeout period, the IVX Cloud action will be executed based on the response. If there is no response from Trellix DLP before the timeout, the DLP policy evaluation will be skipped to prevent further delays.

    • API Key: Enter the API key to authorize the API call to the host. This field is optional. If authorization is not required for the specified host, leave this field empty.

    • Actions: Select one of the following action as part of DLP settings:

      • Admin quarantine

      • User quarantine

      • No Action

      Note

      These options can be used for integration. For manually created API keys, this option is not available. When DLP is blocked due to a policy or rule, users can configure the available actions for the respective integration.

  4. Turn on TLS Verify to enable TLS verification for IVX Cloud – DLP communication. Enabling this option ensures enhanced security. If you are using self-signed certificates on the DLP - Network Prevent, you can disable this option.

  5. Turn on DLP Scan to enable and manage DLP scanning actions in IVX Cloud.

  6. Click Save. The system performs a health check to verify if the DLP appliance hostname/IP on the configured port is reachable from IVX Cloud. If successful connection is established, the settings are saved. If the connection fails, review your network firewall changes and verify the configured hostname/port.

  7. Upload a sample file from your account for scanning. IVX Cloud will scan the file using DLP policies and display the results in the DLP information section of the Reports page.

Manage DLP Network Prevent settings:

  • Enable/Disable: Check an entry and click the appropriate button above the table.

  • Remove: Select an entry and click the remove button.

  • Edit: Click the edit icon in the last column of the table.

  • View results: Scan results are available on the reports page after completion.