Incidents not detected through HTTP channel on DLP endpoint agents
search cancel

Incidents not detected through HTTP channel on DLP endpoint agents

book

Article ID: 164229

calendar_today

Updated On:

Products

Data Loss Prevention Endpoint Prevent

Issue/Introduction

DLP Endpoint Prevent with HTTP monitoring enabled does not flag keyword or DCM based rules.
IP Filters are enabled within the Agent Configuration.
HTTP Domain filters are enabled within the Agent Configuration.

Use Case:
Exclude local network traffic from monitoring, but monitor all other HTTP/FTP/IP traffic.

 

Cause

There is NO implied 'inspect all traffic' rule if IP Filters are configured within the Agent Configuration.


 

Resolution

If IP Filters are defined, HTTP and FTP streams are inspected based solely on the defined rules.

Examples:
A filter of +,10.67.0.0/16,*;-,*,* matches all streams going to network 10.67.x.x in the /16 sub block, but does not match any other traffic.
A filter of -,192.0.2.0/8,*;+,*,* ignores all streams going to network 192.0.2.0, but matches all other traffic.

The key take away is the final rule, +,*,*, allows for all other streams, HTTP/FTP/IP, not previously defined to be included for detection.