27.11.2012 Views

IronPort - Configuration Guide - AsyncOS 7.6.1

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Chapter 11 Data Loss Prevention<br />

Enabling RSA Email DLP<br />

OL-25136-01<br />

Both RSA Email DLP and RSA Enterprise Manager offer the option to log the content that violates your<br />

DLP policies, along with the surround content, which can then be viewed in the Message Tracking. This<br />

content may include sensitive data such as credit card numbers and social security numbers. Do not<br />

select this option if you don’t want the appliance to log this information.<br />

You can switch back to managing data loss prevention on the local appliance using RSA Email DLP<br />

whenever you want.<br />

Note If you want to use the DLP Assessment Wizard to configure the appliance’s DLP policies, see Using the<br />

DLP Assessment Wizard, page 11-17.<br />

Step 1 Select Security Services > RSA Email DLP.<br />

Step 2 Click Enable.<br />

Step 3 The license agreement page is displayed.<br />

Note If you do not accept the license agreement, RSA Email DLP is not enabled on the appliance.<br />

Step 4 Scroll to the bottom of the page and click Accept to accept the agreement.<br />

Step 5 Under Data Loss Prevention, select RSA Email DLP.<br />

Step 6 Check the Enable RSA Email Data Loss Prevention check box.<br />

Step 7 If message tracking is already enabled on your appliance, choose whether or not to enable matched<br />

content logging. By selecting this, the Cisco <strong>IronPort</strong> appliance logs DLP violations and <strong>AsyncOS</strong><br />

displays the DLP violations and surrounding content in Message Tracking, including sensitive data such<br />

as credit card numbers and social security numbers.<br />

Step 8 Submit and commit your changes.<br />

Enabling RSA Enterprise Manager<br />

If you want to use RSA Enterprise Manager to manage data loss prevention for your appliances, you need<br />

to configure your Email Security appliance as a partner device for Enterprise Manager. After you<br />

configure the RSA Enterprise Manager settings, the Email Security appliance sends its configuration to<br />

Enterprise Manager, which automatically adds the appliance as a partner device. The next time you open<br />

Enterprise Manager, the appliance will be shown as a partner device.<br />

If you want to use SSL for communication between the Email Security appliance and Enterprise<br />

Manager, import one or more certificates to use as a server and client certificate into the appliance along<br />

with a certificate file for a certificate authority. The server and client certificates can be the same<br />

certificate, but must have the Email Security appliance’s hostname for the common name. You can use<br />

a certificate generation tool provided by RSA to create the certificate, if you choose. See Certificates,<br />

page 11-28 for more information.<br />

Cisco <strong>IronPort</strong> <strong>AsyncOS</strong> 7.6 for Email <strong>Configuration</strong> <strong>Guide</strong><br />

11-3

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!