External ICAP DLP Integration

To configure DLP integration between SphereShield and a provider sign in to the Admin Portal's admin area.

I.E: http://example.comany.com/admin

Change the "Enable DLP Integration" Setting to "Yes" in  Settings → DLP Integration, or by using the following URL: /admin/settings?category=settings_dlp_integration_category_header

Configure the following(bolded values are what need to be changed):

General
NameValuesDetails
DLP ProviderOther/Symantec/ForcePoint (Websense)/Mcafee/FidelisThe DLP Provider(Other is custom ICAP server)
DLP ICAP ServerIP/Hostname of the  ICAP serverEnter the IP or the hostname for the ICAP Server
DLP ICAP Server portPort numberEnter the port on which ICAP requests will be sent to the ICAP server
DLP ICAP Service Namereqmodthis is the service in the Symantec Enforce server we need to contact.(default for most providers should be reqmod)
Enable Secure ICAPYes/NoEnable ICAP over TLS
DLP ICAP Block Message PatternThe configured block message response from the ICAP server The format of the message for a blocked message from the ICAP server

Supported Providers Presets

ProviderService nameBlock Message Pattern
SymantecreqmodContent blocked due to policy violation
ForcePoint (Websense)reqmodNot relevant
McafeereqmodAccess Denied
Fidelisfss-reqAccess to this website is restricted by your administrator

Example

Example of DLP integration via ICAP with symantec