Data Loss Prevention

 View Only
  • 1.  How to monitor network share trafic with DLP network monitor

    Posted May 22, 2017 08:36 AM

    Hello all,

    We need to monitor network share trafic with Network Monitor Module (Symantec DLP), because we have a big latency with agent Endpoint when he analyse data sends to network share.

    Such, we have disable network share channel on agent Endpoint configuration.

    There is any procedure to monitor network share trafic with Network Monitor.

    Thank's for your help.



  • 2.  RE: How to monitor network share trafic with DLP network monitor

    Posted May 23, 2017 12:57 PM

    you could crate a SPAN port from the switch that is connected to the network share, and then feed that SPAN into the network monitor server. That way your network monitor sees all the traffic to/from the share.



  • 3.  RE: How to monitor network share trafic with DLP network monitor

    Posted May 24, 2017 07:16 AM

    we have configured SPAN port on Switch to see all trafic to/from any connection, but what can i configure on protocole in Network Monitor setting ?

    There is any procedure to monitor network share on network server ?

    Thank's a lot for your return.



  • 4.  RE: How to monitor network share trafic with DLP network monitor

    Posted May 24, 2017 09:20 AM

    Haven't tried this, but I'll put my thoughts out there.

    For example, if it's a CIFS share, you could try adding an IP and/or port-based protocol to monitor port 445. I would begin testing with the default settings from another protocol for Search Depth, Sampling, and Content Processing.



  • 5.  RE: How to monitor network share trafic with DLP network monitor

    Posted May 24, 2017 09:46 AM

    Right off the top of my head I think you'll need to define the SMB/CIFS protocol then add that to your list of monitored protocols in NetMon.

    Can you tell us more of what you're trying to achive?  Remember, Network Monitor has no ability to block or modify any traffic (hence the Monitor part of the name).  So if the only thing you can achive with Network Monitor is some kind of metric on share traffic, is latency that much of a concern?  Maybe I'm thinking of this wrong.

     

    Will