File size limits

Forcepoint DLP has the following file size limitations for network, endpoint, and discovery functions. This applies to all supported versions of Forcepoint DLP.

Note: In the following tables, for "unlimited" items marked with an asterisk (*), files beyond 100 MB are searched only for file name, file size, and binary fingerprint. The binary fingerprinting is based on 5 MB of data from the beginning of the file and 5 MB from the end. It requires a 100 percent match of file content to trigger an incident. No content is extracted from the file.

Network

Table 1. Network file size limits
Channel Analysis Timeout (sec) Max File Size (MB) Max Extracted Sub-Files (MB) Max Extracted Sub-Files (count) Extracted Text Size Per File (MB) Max Forensics (MB)
SMTP inline (protector, Forcepoint Email Security) 35 100 50 100 1 Unlimited
SMTP monitoring (protector, Forcepoint Email Security) 300 100 50 100 1 Unlimited
HTTP, HTTPS, FTP "inline" (ICAP, Content Gateway)

10 (< 5 MB)

20 (5 MB or greater)

50 50 100 1 20
HTTP (protector monitoring mode) 300 100 50 100 1 20
FTP monitoring (protector monitoring mode) 300 100 50 100 1 Unlimited
Web Security Cloud 10 10 50 100 1 10
Cloud applications (Cloud Data Discovery) 300 30 50 100 1 20
Cloud applications (DLP Cloud API) 300 30 50 100 1 20
Cloud applications (DLP Cloud Proxy) 10 10 50 100 1 10
Email Security Cloud 35 30 50 100 1 30

Endpoint

Table 2. Endpoint file size limits
Channel Analysis Timeout (sec) Confirm Dialog Timeout (sec) Max File Size (MB) Max Extracted Sub-Files (MB) Max Extracted Sub-Files (count) Extracted Text Size Per File (MB) Max Forensics (MB)
File Access 25 up to 60 Unlimited* 50 100 1 20
Cut, Copy, Paste 5 up to 60 Unlimited* N/A N/A 1 20
Screen Capture N/A up to 60 N/A N/A N/A N/A 20
Print 25 up to 60 300* N/A N/A 1 20
HTTP/HTTPS (Browser Extension mode) 10 up to 60 Unlimited* 50 100 1 20
HTTP/HTTPS (Inline Proxy mode) 10 up to 60 30 50 100 1 20
Email 15 up to 60 Unlimited* 50 100 1 20
Copy over LAN 25 up to 60 Up to 100 50 100 1 20

Copy from Local Disk to Removable Media or WPD Devices

(Windows 7 and Windows 10 Creators Edition)

25 up to 60 Unlimited* 50 100 1 20

Copy from Network Share to Removable Media or WPD Devices

(Windows 7 and Windows 10 Creators Edition)

25 up to 60 10 50 100 1 20

Key

  • Analysis Timeout (sec): Maximum analysis timeout (seconds). When the different agents submit a transaction to be analyzed by the policy engine, they specify how much time the policy engine has to analyze. At the end of this time, the policy engine returns the best answer it has. The final action is based on partial analysis.
  • Extracted Text Size (MB): Assuming the transaction contains archives, the amount of text that is extracted from each file/sub-file for analysis.
  • Max Forensics Size (MB): The maximum incident forensics size. Incidents do not include forensics beyond this limit. Transactions larger than this include just metadata.
  • Max Intercepted Size (MB): The maximum content size submitted for analysis. Transactions larger than this are not sent to analysis.
  • Max Extracted Sub-Files (MB): Assuming the transaction contains archives, the total amount of data to be extracted from these archives.
  • Max Extracted Sub-Files (count): Assuming the transaction contains archives, the maximum number of sub-files that is extracted from these archives, including the archive level name.