File size limits
Forcepoint DLP has the following file size limitations for network, endpoint, and discovery functions. This applies to all supported versions of Forcepoint DLP.
Note: In the following tables, for "unlimited" items marked with an asterisk (*), files beyond 100 MB are searched only for file name, file size, and binary fingerprint. The binary fingerprinting is
based on 5 MB of data from the beginning of the file and 5 MB from the end. It requires a 100 percent match of file content to trigger an incident. No content is extracted from the file.
Network
| Channel | Analysis Timeout (sec) | Max File Size (MB) | Max Extracted Sub-Files (MB) | Max Extracted Sub-Files (count) | Extracted Text Size Per File (MB) | Max Forensics (MB) |
|---|---|---|---|---|---|---|
| SMTP inline (protector, Forcepoint Email Security) | 35 | 100 | 50 | 100 | 1 | Unlimited |
| SMTP monitoring (protector, Forcepoint Email Security) | 300 | 100 | 50 | 100 | 1 | Unlimited |
| HTTP, HTTPS, FTP "inline" (ICAP, Content Gateway) |
10 (< 5 MB) 20 (5 MB or greater) |
50 | 50 | 100 | 1 | 20 |
| HTTP (protector monitoring mode) | 300 | 100 | 50 | 100 | 1 | 20 |
| FTP monitoring (protector monitoring mode) | 300 | 100 | 50 | 100 | 1 | Unlimited |
| Web Security Cloud | 10 | 10 | 50 | 100 | 1 | 10 |
| Cloud applications (Cloud Data Discovery) | 300 | 30 | 50 | 100 | 1 | 20 |
| Cloud applications (DLP Cloud API) | 300 | 30 | 50 | 100 | 1 | 20 |
| Cloud applications (DLP Cloud Proxy) | 10 | 10 | 50 | 100 | 1 | 10 |
| Email Security Cloud | 35 | 30 | 50 | 100 | 1 | 30 |
Endpoint
| Channel | Analysis Timeout (sec) | Confirm Dialog Timeout (sec) | Max File Size (MB) | Max Extracted Sub-Files (MB) | Max Extracted Sub-Files (count) | Extracted Text Size Per File (MB) | Max Forensics (MB) |
|---|---|---|---|---|---|---|---|
| File Access | 25 | up to 60 | Unlimited* | 50 | 100 | 1 | 20 |
| Cut, Copy, Paste | 5 | up to 60 | Unlimited* | N/A | N/A | 1 | 20 |
| Screen Capture | N/A | up to 60 | N/A | N/A | N/A | N/A | 20 |
| 25 | up to 60 | 300* | N/A | N/A | 1 | 20 | |
| HTTP/HTTPS (Browser Extension mode) | 10 | up to 60 | Unlimited* | 50 | 100 | 1 | 20 |
| HTTP/HTTPS (Inline Proxy mode) | 10 | up to 60 | 30 | 50 | 100 | 1 | 20 |
| 15 | up to 60 | Unlimited* | 50 | 100 | 1 | 20 | |
| Copy over LAN | 25 | up to 60 | Up to 100 | 50 | 100 | 1 | 20 |
|
Copy from Local Disk to Removable Media or WPD Devices (Windows 7 and Windows 10 Creators Edition) |
25 | up to 60 | Unlimited* | 50 | 100 | 1 | 20 |
|
Copy from Network Share to Removable Media or WPD Devices (Windows 7 and Windows 10 Creators Edition) |
25 | up to 60 | 10 | 50 | 100 | 1 | 20 |
Key
- Analysis Timeout (sec): Maximum analysis timeout (seconds). When the different agents submit a transaction to be analyzed by the policy engine, they specify how much time the policy engine has to analyze. At the end of this time, the policy engine returns the best answer it has. The final action is based on partial analysis.
- Extracted Text Size (MB): Assuming the transaction contains archives, the amount of text that is extracted from each file/sub-file for analysis.
- Max Forensics Size (MB): The maximum incident forensics size. Incidents do not include forensics beyond this limit. Transactions larger than this include just metadata.
- Max Intercepted Size (MB): The maximum content size submitted for analysis. Transactions larger than this are not sent to analysis.
- Max Extracted Sub-Files (MB): Assuming the transaction contains archives, the total amount of data to be extracted from these archives.
- Max Extracted Sub-Files (count): Assuming the transaction contains archives, the maximum number of sub-files that is extracted from these archives, including the archive level name.