The Network Data Loss Prevention (DLP) Policy controls the network used by apps running in the Blue Border.
As a Company Manager, you can determine whether or not app traffic from the Secure Enclave is routed through the Private Company Gateway (PCG) as part of your Default Policy that applies to all users. You can also create Policy Overrides to change these settings for specific users or groups as needed.
Learn how to manage Default Data Loss Prevention Policies and Overrides.
View and Manage Your Network Data Loss Prevention Policies
To view and manage your Network DLP Policies:
- Navigate to the Admin Portal.
- In your browser, go to https://login.venn.com/ and sign in if prompted. Then, click Open Admin Portal.
- From the desktop app, click the
Open web app icon. Then, click Company Admin in the top right.
- Click Policy Admin and select DLP Policy in the left menu.
You will see your default Network policy applied to all users under Default policy.
- To view details or make adjustments to your default policy, click
Edit.
- You will see any policy exceptions under Policy overrides. Check to see if any of your Policy Overrides include a different Network setting. To view details or make adjustments, click
Edit next to the Policy Override.
- You can also add additional Policy Overrides, which allow you to set DLP Policies that supersede the default policy for a single user or a group of users, as needed. For example, if a specific user needs their traffic inside Blue Border to bypass the PCG, you may want to set up a Policy Override that unrestricts their Network policy rather than enabling it for all users.
Learn how to manage Default Data Loss Prevention Policies and Overrides.
Enable the Network Policy
As a Company Manager, click the toggle next to Enable Private Company Gateway to enable the Network policy. Once you click Apply, the network path for apps running in Blue Border will be secured with traffic through your Private Company Gateway (PCG).
If you do not enable the Network policy, traffic emanating from within Blue Border is routed through the user's personal internet connection. Venn will not encrypt the traffic nor will it be subject to your Web Policies.
Network Policy Options
With the Network policy enabled, you can configure exceptions for specific traffic.
- Route all conferencing and VOIP app traffic outside of PCG
- Enable routing for localhost
- Exclude FQDNs from PCG
- Local network access
- Blue Border restricted subnet access
Route all conferencing and VOIP app traffic outside of PCG
Check this option to route web conferencing app traffic outside of the Private Company Gateway in order to enhance performance.
Enable routing for localhost
Check this option to allow network traffic directed to the loopback address (127.0.0.1) to be handled locally by the device itself, rather than being sent over the network. This ensures that applications relying on local services such as application add-ins, local web servers, and database connections can communicate properly.
Exclude FQDNs from PCG
When your Network policy is enabled, you may need to exclude traffic to certain domains from the Private Company Gateway.
To exclude a domain:
- Click Add.
- In the popup that appears, add the domain name you would like to exclude.
- Choose from the following options:
- Exclude Exact Domain: Only exclude the exact domain that you input.
-
Exclude Domain & All Subdomains: Exclude the domain(s) that you input and all subdomains (e.g., if you input
www.example.com,www.blog.example.comandwww.help.example.comwould be excluded as subdomains)
- Click Add.
To edit an excluded domain, click Edit to the right of the domain.
To delete an excluded domain, click Delete to the right of the domain.
Local network access
When your Network policy is enabled, you may need to ensure that network traffic intended for devices on the user's local subnet (e.g., printers, scanners, or VPN connections) is routed directly to the user's local network, rather than being sent over the PCG.
To enable local network access for a network address range, check the Local network access checkbox and input the subnet in the field below. Separate multiple address ranges using the enter/return key.
Blue Border restricted subnet access
To enforce secure access, you can specify certain subnets that should only be accessible from within Blue Border. If a user tries to access these subnets outside of Blue Border while they are logged into Blue Border on the device, packets will be dropped.
This setting is commonly used when a VPN is required inside Blue Border to access specific subnets.
To restrict access to a subnet, check the Blue Border restricted subnet access checkbox and input the subnet in the field below. Separate multiple address ranges using the enter/return key.
Comments
0 comments
Article is closed for comments.