Introduction
This document describes the procedure to integrate the Forcepoint ONE and Forcepoint Security Manager (FSM) solutions so that Forcepoint ONE can enforce DLP policy and associated actions setup in the FSM for CASB channel in Forcepoint ONE.
Solution Overview
Describes Forcepoint ONE SSE and FSM solutions overview.
Terminology
Forcepoint ONE SSE and Forcepoint DLP share common features, but sometimes use different terms.
Audience
Defines the audience of this document.
Additional documentation
Lists the documents referred across the document.
License Information
Describes various license SKUs needed to achieve multi-directional communication among the FSM, the cloud hosted DPS, and the Forcepoint ONE SSE cloud infrastructure and the steps to update the license in FSM.
Licensing SKUs
Describes various license SKUs needed to achieve multi-directional communication among the customer-deployed FSM server, the cloud-hosted DPS, and the Forcepoint ONE SSE CASB cloud infrastructure.
Update license in FSM
Describes the steps to update license in FSM.
Integrating Forcepoint DLP and Forcepoint ONE SSE CASB
This chapter provides an overview of how to configure the integration between Forcepoint DLP and Forcepoint ONE SSE CASB, and also configure DLP policies for sanctioned cloud applications.
General flow
Step1: Check licenses on the FSM
You should first check the required combinations of license SKUs on the FSM.
Step2: Firewall and network access prerequisites
Describes firewall and network access prerequisites.
Step3: Connect to DPS on the FSM
To benefit from the integration of the cloud channels with Forcepoint ONE SSE CASB, you should first connect the DLP Manager to DPS.
Step4: Upload DPS license JSON on Forcepoint ONE SSE
After the Forcepoint DLP and Forcepoint ONE SSE CASB integration is configured and the DLP Cloud Application license is active, you need to upload the same DPS license JSON file provided with your Forcepoint order confirmation mail as part of the on-boarding process or requested from Forcepoint Technical Support on the Forcepoint ONE SSE.
Step5: Update the Forcepoint ONE SSE URLs in the FSM SQL database
You should update the Forcepoint ONE SSE URLs in the FSM SQL database if you are not connecting to Forcepoint ONE SSE Commercial Cloud URL from FSM.
Step6: Activate the connection with Forcepoint ONE SSE CASB on the FSM
After uploading and validation JSON license file in Forcepoint ONE SSE, you should use the Cloud Applications tab to connect, or disconnect to the Forcepoint ONE SSE CASB system on the FSM.
Step7: View the list of cloud applications
After successfully connecting to the Forcepoint ONE SSE CASB system on the Cloud Applications tab of the FSM, the FSM Cloud Applications resource screen displays a list of all configured (predefined and custom) cloud applications from Forcepoint ONE SSE.
Step8: Configure DLP policies for cloud applications on the FSM
When configuring DLP Cloud policy rules, you must select DLP Cloud Applications as the destination, and you must select one or both of the DLP Cloud Applications channels – DLP Cloud API and DLP Cloud Proxy.
Step9: Configure quarantine or create copy locations for FSM controlled API policies
On the Forcepoint ONE SSE, the Settings > DLP page enables you to specify quarantine and create copy locations which will be used when FSM returns an API policy indicating a quarantine or create copy action. These are global settings and are applied only if the API policies are controlled by FSM.
Step10: Configure DLP policies for cloud applications in the Forcepoint ONE SSE
Describes how to configure DLP policies in Forcepoint ONE SSE.
Step11: View Forcepoint DLP incidents on the FSM
Viewing and managing reports for the DLP Cloud Applications feature is the same as for the on-premises DLP.
Step12: View event information on the Forcepoint ONE SSE
You can review the incidents by viewing and managing logs for the Cloud Applications on Forcepoint ONE SSE.
Activate DLP Cloud Applications channels after a Forcepoint DLP upgrade
After you upgrade Forcepoint DLP, you must recheck the license and components to make sure that everything is working properly, and then redeploy the configuration to DPS. For more information, 260916F4-9FE4-4BEF-B06E-CCF53BB8B52B.html#Check_your_licenses_on_the_Forcepoint_Se.