12.07.2015 Views

McAfee Data Loss Prevention 9.2.2 Product Guide

McAfee Data Loss Prevention 9.2.2 Product Guide

McAfee Data Loss Prevention 9.2.2 Product Guide

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

13Managing <strong>McAfee</strong> DLP systemsUsing capture filters2 Select Capture Filters from the left pane options.Filters are displayed by device in the right panel.3 Click Create Content Filter.4 Type a filter name and optional description.5 Select Action | Drop Element.6 Open the Source/Destination category.7 Select IP Address | is any of and type an IP address into the value field.If the address is on a subnet, it is detectable only if the network and host portions of an IP addressare standard classful IP (address fields are separated into four 8‐bit groups). Separate multipleaddresses by commas, and IP ranges by dashes.8 Select the checkbox of the device on which you want the filter deployed.To decide later, click None.9 Click Save.A new capture filter is added to the existing list.How content capture filters workContent capture filters filter out or store specified types of data that are transmitted on the Applicationlayer (also known as Flow A).Standard content capture filters perform routine operations on network data to improve <strong>McAfee</strong> DLPperformance and results.Table 13-1 Standard content capture filtersContent capture filterIgnore binaryIgnore BMP and GIF imagesIgnore cryptoIgnore HTTP GZip responsesIgnore HTTP headersIgnore P2PIgnore small JPG imagesIgnore flow headersPurposeExclude binary files from network trafficExclude BMP and GIF images from network trafficExclude encrypted data from network trafficKeep compressed files from being opened by the capture engineKeep HTTP header blocks from being capturedKeep Peer‐to‐Peer traffic from being capturedExcludes insignificant images (smaller than 4 MB) from network trafficKeeps flow headers from being recognizedHow network capture filters workNetwork capture filters included with <strong>McAfee</strong> DLP systems filter data streaming on the Transport Layerto improve performance and isolate significant traffic.Network capture filters work by eliminating large portions of Transport (Layer 4) traffic. They operatein a cumulative sequence and always terminate in the BASE filter, which stores the configuration.For example, most businesses are interested in monitoring traffic carried to or from external IPaddresses. When the RFC (Request for Comments) 1918 filter is active, IP addresses set aside byIANA (Internet Assigned Numbers Authority) for internal use can be excluded from analysis by thecapture engine.252 <strong>McAfee</strong> <strong>Data</strong> <strong>Loss</strong> <strong>Prevention</strong> <strong>9.2.2</strong> <strong>Product</strong> <strong>Guide</strong>

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!