- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Creating content filtering or DLP rule to block emails contain DEA
I tried to use DLP profile for alerting and blocking outbound emails which contains DEA numbers without success, it works great in office365 but after moving to on premise with fortimail it doesn't detect those emails, even my testing emails which detect with office365.
I wonder if I can create custom dictionary for DEA. the pattern is clear but there is no instruction how to config it in fortimail.
does any one use it?
eventually I need to detect HIPAA and DEA for outbound emails.
thank you
- Labels:
-
FortiMail
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I manage to create custom dictionary for DEA content filtering profile,
\b[a-zA-Z]{2}\d{7}$
this is the pattern for DEA.
so the content filtering is detecting DEA numbers and doing the action to stop them.
the strange thing that fortimail standard compliance doesn't work!!!!!!!!
you think DLP will be stronger than content filtering but I was wrong
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Did you open a support ticket? What Fortimail version? any screenshots to share?
FG200D 5.6.5 (HA) - primary [size="1"]FWF50B' s 4.3.x, FG60D's 5.2.x, FG60E's 5.4.x [Did my post help you? Please rate my post.][/size] FAZ-VM 5.6.5 | Fortimail 5.3.11 Network+, Security+
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Yes I open a ticket and they say also their testing is not detecting the DEA numbers so I need to continue with content filtering and he will update me.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
being picky here: the correct regex for a DEA ID would be "\b[a-zA-Z][a-zA-Z9]\d{7}".
Firstly, the second letter from the left is a '9' (not a letter) in case the registrant is using a business address.
Secondly, the '$' at the end would prevent recognizing IDs which are followed by '-xxxxx', the supervised individual's ID. Cf. https://en.wikipedia.org/wiki/DEA_number
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
thank you for adding it, I just start working with it.
