12.07.2015 Views

McAfee Data Loss Prevention 9.2.2 Product Guide

McAfee Data Loss Prevention 9.2.2 Product Guide

McAfee Data Loss Prevention 9.2.2 Product Guide

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Managing <strong>McAfee</strong> DLP PreventHow <strong>McAfee</strong> DLP Prevent works 3How <strong>McAfee</strong> DLP Prevent works with webmailIf a webmail user violates any of the policies deployed through <strong>McAfee</strong> DLP Manager, <strong>McAfee</strong> DLPPrevent applies the appropriate action and returns the transmission to the proxy server. For example,if he sends a message that violates a Human Resources policy from his webmail account, an actionrule might be triggered to block that transmission and notify HR.Although <strong>McAfee</strong> DLP Prevent supports block, bounce, encrypt, monitor, quarantine and redirect actions,proxy servers can only BLOCK or ALLOW webmail.1 The proxy server captures outgoing HTTP/HTTPS communications traffic and sends it to <strong>McAfee</strong> DLPPrevent over ICAP (Internet Control Adaptation Protocol).2 On receiving the traffic, the <strong>McAfee</strong> DLP Prevent appliance compares it to existing policies and rulesfor web traffic.3 If a rule matches, <strong>McAfee</strong> DLP Prevent determines from its action rule whether or not the webmailshould be blocked.4 The <strong>McAfee</strong> DLP Prevent sends the webmail back to the proxy server. If it is blocked, a web pagestating that the transmission violates policy is sent to the user's browser. But if the associatedaction rule allows it, it is simply delivered to the addressee.5 The software sends notification of the action to any defined email address.Prevent policy actionsPreventive actions are added to rules that are matched to data in motion on the network. When a rulehits, the action is applied.<strong>McAfee</strong> DLP Prevent supports the following actions. But if the appliance is configured with a proxyserver, only ALLOW and BLOCK actions are supported.• Allow (default) • Monitor• Block • Notify• Bounce • Quarantine• Encrypt • RedirectEach action can be configured to automatically notify users that a preventive action has been applied,place a record in a system log, assign the incident to one or more reviewers, or apply a status thatindicates its stage of resolution.<strong>McAfee</strong> <strong>Data</strong> <strong>Loss</strong> <strong>Prevention</strong> <strong>9.2.2</strong> <strong>Product</strong> <strong>Guide</strong> 67

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!