cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1177
Views
0
Helpful
12
Replies

content filters on public mail i.e. gmail, yahoo etc

abnk_t_ironport
Level 1
Level 1

is there a way to create content policies on web security appliances on information sent on public mails( gmail yahoo ) or IMs?
it might sound stupid as you cannot control the mail server so filter what can be sent out or not but on the other hand you can monitor the web traffic
:-)

12 Replies 12

khoanguy
Level 1
Level 1

You might be referring to our DLP (Data Loss Prevention) seen on 6.0 and above. Below is a clip from our User Guide, you can search for that section to see if it fits your needs.


DATA SECURITY AND EXTERNAL DLP POLICIES OVERVIEW

In the Information Age, your organization’s data is one of its most prized possessions. Your
organization spends a lot of money making data available to your employees, customers, and
partners. Data is always on the move by traveling over the web and email. This increased
access poses challenges for information security professionals to figure out how to prevent the
malicious, accidental, or unintentional loss of sensitive and proprietary information.
The IronPort Web Security appliance secures your data by providing the following
capabilities:
• IronPort Data Security Filters. The IronPort Data Security Filters on the Web Security
appliance evaluate data leaving the network over HTTP, HTTPS, and FTP to control what
data goes where and how and by whom.
• Third party data loss prevention (DLP) integration. The Web Security appliance integrates
with leading third party content-aware DLP systems that identify and protect sensitive
data. The Web Proxy uses the Internet Content Adaptation Protocol (ICAP) which is a
lightweight HTTP based protocol that allows proxy servers to offload content scanning to
external systems. By offloading the content scanning to dedicated external systems, the
Web Proxy can take advantage of the deep content scanning in other products while
being free to perform other Web Proxy functions with minimal performance impact.

abnk_t_ironport
Level 1
Level 1

hello khoa,
many thanks for the reply.
no plan to implement a dlp solution ( i.e. verdasys) what i want to focus on is the following as mentioned by you:
- "IronPort Data Security Filters. The IronPort Data Security Filters on the Web Security appliance evaluate data leaving the network over HTTP, HTTPS, and FTP to control what data goes where and how and by whom. "
is it possible to know any where to find m ore info and any example on the above?
cheers

khoanguy
Level 1
Level 1

More info on our site: http://www.ironport.com/technology/ironport_dlp_overview.html

there are a few pdf there, but the User Guide can help with the setup if needed.

abnk_t_ironport
Level 1
Level 1

hi again khoa,
well i am trying to activate the data security service on the ironport web appliance but i am having some difficulties.
any idea how to activate it?
here is an excerpt from the guide:
enable the IronPort Data Security Filters. To scan upload requests on the appliance, you must first enable the IronPort Data Security Filters. Usually, the IronPort Data Security Filters feature is enabled during the initial setup using the System Setup Wizard. Otherwise, go to the Security Services > Data Security Filters page to enable it.
i am finding no where the data security filters page at the security services.

the appliance is s160
cheers

JennieMorton
Level 1
Level 1

What version are you using? This feature is only available with AsyncOS for Web 6.0 and later.

abnk_t_ironport
Level 1
Level 1

yes it is the problem of the version
it is upgraded now but still it has some problems.
it cant block specific file name

khoanguy
Level 1
Level 1

is the idsdataloss_logs showing anything? it might give you some clues, if not a support ticket might be needed.

abnk_t_ironport
Level 1
Level 1

where to find it? ids_datalogd???

abnk_t_ironport
Level 1
Level 1

where i can find the ids logs?

have another question
has anyone tried to find the user name that is entered in the web mail account login page?
any idea if this is doable?
( from the access logs of the irononport?)

JennieMorton
Level 1
Level 1

You can find the Data Security Logs in the same place as all log files on the WSA (such as the Access logs). You can find them from the GUI by going to the System Administration > Log Subscriptions page. For more information on how to retrieve log files, see the Logging chapter in the user guide.

As for your other question, I'm not sure I can help you. My *guess* is that you can't, but hopefully someone else can answer for sure.

khoanguy
Level 1
Level 1

If you do not see the ids logs, then you might need to enable it:

CLI > logconfig > new > Data Security Logs

abnk_t_ironport
Level 1
Level 1

thanks khoa
its there its already activated.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: