Cisco Cisco Web Security Appliance S670 User Guide

Page of 606
 
13-9
Cisco IronPort AsyncOS 7.7 for Web User Guide
 
Chapter 13      Data Security and External DLP Policies
Controlling Upload Requests Using Cisco IronPort Data Security Policies
Step 8
Submit your changes.
Step 9
If you are creating a Data Security Policy group, configure its control settings to define how the Web 
Proxy handles upload requests.
The new Data Security Policy group automatically inherits global policy group settings until you 
configure options for each control setting. For more information, see 
.
Step 10
If you are creating an External DLP Policy group, configure its control settings to define how the Web 
Proxy handles upload requests.
The new External DLP Policy group automatically inherits global policy group settings until you 
configure custom settings. For more information, see 
.
Step 11
Submit and commit your changes.
Controlling Upload Requests Using Cisco IronPort Data Security 
Policies
Each upload request is assigned to a Data Security Policy group and inherits the control settings of that 
policy group. The control settings of the Data Security Policy group determine whether the appliance 
blocks the connection or evaluates it against the Access Polices.
Configure control settings for Data Security Policy groups on the Web Security Manager > Cisco 
IronPort Data Security page.
 shows where you can configure control settings for the Data Security Policy groups.
User Agents
Choose whether or not to define policy group membership by the user agent used 
in the client request. You can select some commonly defined browsers, or define 
your own using regular expressions. Choose whether this policy group should 
apply to the selected user agents or to any user agent that is not in the list of 
selected user agents.
For more information on creating user agent based policies, see 
Note: If the Identity associated with this policy group defines Identity 
membership by this advanced setting, the setting is not configurable at the 
non-Identity policy group level.
User  Location
Choose whether or not to define policy group membership by user location, either 
remote or local. 
This option only appears when the Secure Mobility is enabled. For more 
information, see 
.
Table 13-1
Data Security and External DLP Policy Group Advanced Options (continued)
Advanced Option
Description