Fortinet white logo
Fortinet white logo

CLI Reference

config dlp settings

config dlp settings

Configure settings for DLP.

config dlp settings
    Description: Configure settings for DLP.
    set cache-mem-percent {integer}
    set chunk-size {integer}
    set config-builder-timeout {integer}
    set db-mode [stop-adding|remove-modified-then-oldest|...]
    config ocr
        Description: Configure settings for optical character recognition (OCR) conversion.
        set confidence {integer}
        set filetype-ignore-list <name1>, <name2>, ...
        set max-file-size {integer}
        set scan [enable|disable]
    end
    set size {integer}
    set storage-device {string}
end

config dlp settings

Parameter

Description

Type

Size

Default

cache-mem-percent *

Maximum percentage of available memory allocated to caching DLP fingerprints (1 - 15).

integer

Minimum value: 1 Maximum value: 15

2

chunk-size *

Maximum fingerprint chunk size. Caution, changing this setting will flush the entire database.

integer

Minimum value: 100 Maximum value: 100000

2800

config-builder-timeout

Maximum time allowed for building a single DLP profile (default 60 seconds).

integer

Minimum value: 10 Maximum value: 100000

60

db-mode *

Behavior when the maximum size is reached in the DLP fingerprint database.

option

-

stop-adding

Option

Description

stop-adding

Stop adding entries.

remove-modified-then-oldest

Remove modified chunks first, then oldest file entries.

remove-oldest

Remove the oldest files first.

size *

Maximum total size of files within the DLP fingerprint database (MB).

integer

Minimum value: 16 Maximum value: 4294967295

16

storage-device *

Storage device name.

string

Maximum length: 35

* This parameter may not exist in some models.

config ocr

Parameter

Description

Type

Size

Default

confidence

Minimum confidence threshold for the OCR converted content to be scanned (0 - 100, default = 80).

integer

Minimum value: 0 Maximum value: 100

80

filetype-ignore-list <name>

List of file types to be exempt from OCR scanning.

File type name.

string

Maximum length: 39

max-file-size

Maximum file size for an image to be a candidate for OCR conversion in kilobytes (0 - 1644544, 0 = unlimited).

integer

Minimum value: 0 Maximum value: 1644544 **

0

scan

Enable/disable OCR conversion of images for DLP content scanning.

option

-

enable

Option

Description

enable

Enable OCR conversion during DLP scan.

disable

Disable OCR conversion during DLP scan.

** Values may differ between models.

config dlp settings

config dlp settings

Configure settings for DLP.

config dlp settings
    Description: Configure settings for DLP.
    set cache-mem-percent {integer}
    set chunk-size {integer}
    set config-builder-timeout {integer}
    set db-mode [stop-adding|remove-modified-then-oldest|...]
    config ocr
        Description: Configure settings for optical character recognition (OCR) conversion.
        set confidence {integer}
        set filetype-ignore-list <name1>, <name2>, ...
        set max-file-size {integer}
        set scan [enable|disable]
    end
    set size {integer}
    set storage-device {string}
end

config dlp settings

Parameter

Description

Type

Size

Default

cache-mem-percent *

Maximum percentage of available memory allocated to caching DLP fingerprints (1 - 15).

integer

Minimum value: 1 Maximum value: 15

2

chunk-size *

Maximum fingerprint chunk size. Caution, changing this setting will flush the entire database.

integer

Minimum value: 100 Maximum value: 100000

2800

config-builder-timeout

Maximum time allowed for building a single DLP profile (default 60 seconds).

integer

Minimum value: 10 Maximum value: 100000

60

db-mode *

Behavior when the maximum size is reached in the DLP fingerprint database.

option

-

stop-adding

Option

Description

stop-adding

Stop adding entries.

remove-modified-then-oldest

Remove modified chunks first, then oldest file entries.

remove-oldest

Remove the oldest files first.

size *

Maximum total size of files within the DLP fingerprint database (MB).

integer

Minimum value: 16 Maximum value: 4294967295

16

storage-device *

Storage device name.

string

Maximum length: 35

* This parameter may not exist in some models.

config ocr

Parameter

Description

Type

Size

Default

confidence

Minimum confidence threshold for the OCR converted content to be scanned (0 - 100, default = 80).

integer

Minimum value: 0 Maximum value: 100

80

filetype-ignore-list <name>

List of file types to be exempt from OCR scanning.

File type name.

string

Maximum length: 39

max-file-size

Maximum file size for an image to be a candidate for OCR conversion in kilobytes (0 - 1644544, 0 = unlimited).

integer

Minimum value: 0 Maximum value: 1644544 **

0

scan

Enable/disable OCR conversion of images for DLP content scanning.

option

-

enable

Option

Description

enable

Enable OCR conversion during DLP scan.

disable

Disable OCR conversion during DLP scan.

** Values may differ between models.