Configuring the protector
Steps
- Go to the Settings > Deployment > System Modules page.
- Select the protector instance.
- On the General tab, select Enabled.
-
On the Local Networks tab, select Include specific networks, then add all of the internal networks for all sites.
- This list is used to identify the direction of the traffic.
- The mail servers and mail relays should be considered part of the internal network.
-
On the Services tab:
- Select the SMTP service.
- On the General tab, set the Mode to Mail Transfer Agent (MTA).
- On the Mail Transfer Agent (MTA) tab, set the Operation Mode to Blocking and select the behavior desired when an unspecified error occurs during analysis.
- Set the SMTP HELO name. This is required.
- Set the next hop MTA (for example, the organization’s mail relay), if needed.
-
Set the addresses of all networks that are permitted to relay email messages through the protector.
- This is required, as it is important that not all networks have permission to send email via the protector’s SMTP service. Otherwise, the protector can be used as a mail relay.
- This list should include the addresses of any previous hops, such as the mail server.
- Click OK to save the configuration.
- Go to the Main > Policy Management > DLP Policies page.
- Select a policy rule to use for email management, then click Edit.
-
Complete the fields as follows:
- Select Destinations, and check the Network Email box.
-
Select Severity & Action, then select an action plan that includes notifications.
Note: For more information about action plans, see the Forcepoint DLP Administrator Help.
- Click OK to save the policy configuration.
- Click Deploy to activate the settings.