Cisco Cisco Email Security Appliance C170 Guia Do Utilizador

Página de 1212
 
18-26
User Guide for AsyncOS 10.0 for Cisco Email Security Appliances
 
Chapter 18      Data Loss Prevention
  RSA Enterprise Manager
Fingerprinting
If your Enterprise Manager deployment includes RSA’s DLP Datacenter, you can enable fingerprinting. 
Fingerprinting improves detection of source code and sensitive documents including: 
Databases 
Full or partial text matches in the text of a document
Full binary match, which is a bit-by-bit exact match of a file 
If you enable fingerprinting, Enterprise Manager sends fingerprinting detection information to the Email 
Security appliance, and the Email Security appliance uses this information when scanning messages for 
Data Loss Prevention. 
For more information about fingerprinting, see the Enterprise Manager documentation. 
Related Topics
 
(Recommended) Obtaining and Uploading Certificates for SSL Connections between Email Security 
Appliances and Enterprise Manager 
If you want to use an SSL connection between the Email Security appliance and Enterprise Manager, 
you will need one or more certificates and signing keys from a recognized certificate authority to use for 
mutual authentication of the two machines. 
When configuring the SSL connection, the Enterprise Manager server is the server and the Email 
Security appliance is the client. 
Complete all of the following procedures: 
Generating Client and Server Certificates using RSA’s Certificate Tool
RSA provides a certificate generation tool that you can use to generate a single .p12 file that you can use 
as both the server and client certificate for the connection. If you want to use different certificates for 
the appliance and the Enterprise Manager server, you must get them from another source. 
This tool creates and stores two files on the Enterprise Manager server: the .p12 certificate file and a 
.pem certificate file. If you want to use the .p12 file, you must also import the .pem file onto the Email 
Security appliance as a certificate authority list. 
For more information, see the RSA documentation.