Edit the Enterprise DLP Snippet Settings on Panorama
Focus
Focus
Enterprise DLP

Edit the Enterprise DLP Snippet Settings on Panorama

Table of Contents


Edit the Enterprise DLP Snippet Settings on Panorama

Configure the Enterprise Data Loss Prevention (E-DLP) snippet settings on your Panorama® management server to specify if and how snippets are stored.
  1. Log in to the Panorama web interface.
  2. Select PanoramaDLPConfiguration and edit the Snippet Settings.
  3. Check (enable) Store Snippets of Sensitive Data to store the snippets of sensitive data that match your data patterns in the DLP cloud service.
  4. Configure how to Mask Sensitive Field for storage in Enterprise DLP.
    • Do not maskEnterprise DLP displays the entire matched sensitive data snippet in cleartext.
    • Partial maskEnterprise DLP partially masks the matched sensitive data snippet and displays only the last two characters in cleartext.
    • Full maskEnterprise DLP fully masks the entire matched sensitive data snippet.
  5. Click OK to save your configuration changes.
  6. Commit and push the new configuration to your managed devices.
    The Commit and Push command isn’t recommended for Enterprise DLP configuration changes. Using the Commit and Push command requires the additional and unnecessary overhead of manually selecting the impacted templates and managed devices in the Push Scope Selection.
    • Full configuration push from Panorama
      1. Select CommitCommit to Panorama and Commit.
      2. Select CommitPush to Devices and Edit Selections.
      3. Select Device Groups and Include Device and Network Templates.
      4. Click OK.
      5. Push your configuration changes to your managed devices that are using Enterprise DLP.
    • Partial configuration push from Panorama
      You must always include the temporary __dlp administrator when performing a partial configuration push. This is required to keep Panorama and Strata Cloud Manager in sync.
      For example, if admin is logged in and making changes, they must select both admin and __dlp in the partial commit and push.
      1. Select CommitCommit to Panorama.
      2. Select Commit Changes Made By and then click the current Panorama admin user to select additional admins to include in the partial commit.
        Select your logged-in admin user, the __dlp user, and any other admins whose changes to include. Click OK to continue.
      3. Commit.
      4. Select CommitPush to Devices.
      5. Select Push Changes Made By and then click the current Panorama admin user to select additional admins to include in the partial push.
        Select your logged-in admin user, the __dlp user, and any other admins whose changes to include. Click OK to continue.
      6. Select Device Groups and Include Device and Network Templates.
      7. Click OK.
      8. Push your configuration changes to your managed devices that are using Enterprise DLP.