Adding Or Editing A Rule Or Compound Rule In A Dlp Sensor - Fortinet FortiGate Series Administration Manual

Hide thumbs Also See for FortiGate Series:
Table of Contents

Advertisement

Data Leak Prevention

Adding or editing a rule or compound rule in a DLP sensor

FortiGate Version 4.0 MR1 Administration Guide
01-410-89802-20090903
http://docs.fortinet.com/
Feedback
A DLP sensor must be created before it can be configured by adding rules and compound
rules. To create a DLP sensor, go to UTM > Data Leak Prevention > Sensor and select
Create New. Enter the DLP sensor name and optional comment, and select OK. You can
then add the required rules and compound rules.
To configure a DLP sensor, go to UTM > Data Leak Prevention > Sensor and select the
Edit icon of the sensor to be configured. A list of the DLP rules and DLP compound rules
included in the DLP sensor is displayed. A newly created sensor will include no rules.
Figure 358: List of rules in a DLP sensor
Name
Comment
Create New
Enable
Rule name
Action
Comment
Delete and Edit icons
To add a rule to a DLP sensor go to UTM > Data Leak Prevention > Sensor and select the
Edit icon of the sensor to be configured. Select Create New, set the Member type to Rule
and select the rule to add to the sensor. Configure the settings for the rule.
To add a compound rule to a DLP sensor go to UTM > Data Leak Prevention > Sensor
and select the Edit icon of the sensor to be configured. Select Create New, set the
Member type to Compound Rule and select the compound rule to add to the sensor.
Configure the settings for the compound rule.
To edit a rule or compound rule already included in a sensor, go to UTM > Data Leak
Prevention > Sensor and select the Edit icon of the sensor to be configured. Select the
edit icon of the rule or compound rule to edit. Change the settings for the rule or
compound rule.
The DLP sensor name.
The optional description of the DLP sensor.
Select Create New to add a new rule or compound rule to the sensor.
You can disable a rule or compound rule by clearing this check box.
The item will be listed as part of the sensor, but it will not be used.
The names of the rules and compound rules included in the sensor.
The action configured for each rule. If the selected action is None, no
action will be listed.
Although archiving is enabled independent of the action, the Archive
designation appears with the selected action.
For example, if you select the Block action and set Archive to Full for a
rule, the action displayed in the sensor rule list is Block, Archive.
The optional description of the rule or compound rule.
Delete or edit a rule or compound rule.
DLP Sensors
Delete
Edit
585

Advertisement

Table of Contents
loading

Table of Contents