12.07.2015 Views

McAfee Data Loss Prevention 9.2.2 Product Guide

McAfee Data Loss Prevention 9.2.2 Product Guide

McAfee Data Loss Prevention 9.2.2 Product Guide

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Managing <strong>McAfee</strong> DLP systemsUsing capture filters 137 Click Save.The Capture Filters page reappears.8 Test the filter with live traffic and modify it until it is working correctly.Add network capture filtersAdd network capture filters to identify types of Transport Layer traffic that can be stored or ignored.After these blocks of data are identified, the capture engine will not capture or parse any of thattraffic.On the Network Filter page, open All. This action either captures or cuts off all traffic, depending on thecapture action you select, so that you can observe a limited pool of data before deciding what to filter.Designing network capture filters require experimentation because the order in which they are deployedis crucial, but taking the time to streamline the capture process can save a lot of processing time. Whena network capture filter is applied to the network data stream, its position in the list indicates itspriority. Because the BASE filter instructs the system to store all data that has not been dropped fromthe data stream, it must always run last.Task1 Make a note of the types of traffic you want the capture engine to store or ignore.2 Select one of these options:• In ePolicy Orchestrator, select Menu | <strong>Data</strong> <strong>Loss</strong> <strong>Prevention</strong> | DLP Sys Config | System Administration | CaptureFilters.• On your <strong>McAfee</strong> DLP appliance, select System | System Administration | Capture Filters.3 Click Create Network Filter.4 Type in a filter name and optional description.5 Select a capture action to indicate what portion of traffic is to be stored or dropped.6 Select the devices to which the capture filter is to be deployed.If you want to deploy a capture filter at a later time, select None.7 Open each category and define parameters that describe the traffic that is to be stored or dropped.8 Click Save.The Capture Filters page reappears.9 In the Network Filters table, use the Priority arrows to move the filter into the correct position.When establishing a sequence for applying network capture filters to the network data stream,remember that changing the order of a single filter might skew your results.10 Test the filter with live traffic and modify it until it is working correctly.Copy capture filtersIf you have two or more <strong>McAfee</strong> DLP appliances of the same type registered to <strong>McAfee</strong> DLP Manager,you can copy the capture filter configuration to another device.Before you beginConfigure capture filters on one of the <strong>McAfee</strong> DLP appliances you plan to copy.<strong>McAfee</strong> <strong>Data</strong> <strong>Loss</strong> <strong>Prevention</strong> <strong>9.2.2</strong> <strong>Product</strong> <strong>Guide</strong> 255

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!