12.07.2015 Views

McAfee Data Loss Prevention 9.2.2 Product Guide

McAfee Data Loss Prevention 9.2.2 Product Guide

McAfee Data Loss Prevention 9.2.2 Product Guide

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Using <strong>McAfee</strong> DLP DiscoverManaging scans 4Scanning network attached storage<strong>McAfee</strong> DLP Discover scans storage devices by using the protocols that are used to access them.Table 4-19 Common network storage typesStorage typeAccess methodNetwork Attached Storage Network Attached Storage presents a conventional file system to thenetwork, and can be accessed directly by <strong>McAfee</strong> DLP systems.Storage Area NetworksStore data in an unusable format using physical blocks of disk space, but<strong>McAfee</strong> DLP Discover can connect through any server that owns a pool ofdata on that device.Firewall options for scanningBefore scanning a repository, its firewall must be configured to allow scans.Source ports are randomly chosen unless explicitly noted. Network and host‐based firewalls typicallypermit connections only on certain ports and might have to be configured to permit connections onothers.Table 4-20 Firewall optionsRepository type Direction PortsCIFSFTP Active Mode (triedby Discover if PassiveMode fails)FTP Active ModeFTP Passive Mode (triedfirst by Discover)HTTPHTTPSNFS<strong>Data</strong>baseDiscover to Server TCP 139 and 445 on serverDiscover to Server TCP destination port 21 on server (control)Server to Discover TCP source port 20 (from server), and destination port(on Discover) chosen by Discover (data)Discover to Server TCP destination port 21 on server (control), andanother port on server (data) chosen by the serverDiscover to Server TCP destination port 80 on server, unless port ismanually configured in the URL itselfDiscover to Server TCP destination port 443 on server, unless port ismanually configured in the URL itselfDiscover to Server TCP and UDP destination ports 111; 2049 on serverDiscover to Server Standard ports, by database:• DB2 — 50000• Microsoft SQL — 1433• MySQL — 3306• Oracle — 1521If the database server is running on a non‐standardport, that port number must be punctured in a firewall.EMC DocumentumMicrosoft SharePointDiscover to Server TCP destination port 1489 on serverDiscover to Server TCP destination ports 80 (HTTP) or 443 (HTTPS) onserver, unless port is manually configured in the URLitself<strong>McAfee</strong> <strong>Data</strong> <strong>Loss</strong> <strong>Prevention</strong> <strong>9.2.2</strong> <strong>Product</strong> <strong>Guide</strong> 93

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!