Configuring the On-prem DLP Integration

On the DLP page, configure only the ICAPS protocol settings to allow DLP integration for the Forcepoint Cloud RBI.

Steps

  1. Sign in to Forcepoint ONE Platform.
  2. Click the settings icon on the top . Then, navigate to Integration > DLP.
  3. Under Data Loss Prevention Configuration, click the On-prem DLP toggle switch. Following dialog is displayed:
  4. Under Data Loss Prevention Configuration > On-prem DLP, click the Enable ICAPS for Data Protection toggle switch to enable the data protection.
    By default Enable ICAPS for Data Protection is disabled.
  5. Enter the FQDN server name in the Server FQDN Name field.
  6. Enter the port number of the ICAPS server in the Port field.
  7. Enter the path value of the ICAPS server in the Path field.
  8. Click the Browse Certificate to attach CA client certificate for the ICAPS server.
    To see the procedure to generate the certificate, refer this Knowledge Base article 36918 .
  9. Under Data Protection Preferences:
    1. Click the Permit Traffic for Communication Errors toggle switch to allow traffic when there is a communication error. By default, this option is disabled.
      Note:
      • The communication error can occur due to one of the following reasons:
        • DLP is not able to analyze files. For example, due to timeout.
        • ICAPS communication error.
      • It is recommended not to enable Permit Traffic for Communication Errors, as this can lead to unexpected handling of DLP policies.
    2. Click the Permit Traffic for DLP Error toggle switch to allow traffic when DLP fails to analyze a file that exceeds maximum size limit. By default, this option is disabled.

      Files are not uploaded when the toggle is disabled and shows an appropriate message to the user. However, once you enable the toggle, files are uploaded without showing any error to the user. The user can view the analyzed information in the upload summary under Forcepoint ONE | Insights > RBI Dashboard > File Security tab.

  10. Click the Save button.
    Note: For end-users, RBI performance with On-premises DLP could be influenced by local network conditions and network latency. It is recommended to validate this setup before deploying it widely for your users.