Chapter 15 Unified Threat Management for FortiOS 5.0 : Data leak prevention : DLP document fingerprinting : Fingerprinted Documents
  
Fingerprinted Documents
The FortiGate unit must have access to the documents for which it generates fingerprints. One method is to manually upload documents to be fingerprinted directly to the FortiGate unit. The other is to allow the FortiGate unit to access a network share that contains the documents to be fingerprinted.
If only a few documents are to be fingerprinted, a manual upload may be the easiest solution. If many documents require fingerprinting, or if the fingerprinted documents are frequently revised, using a network share makes user access easier to manage.
To configure manual document fingerprints
1. Go to Security Profiles > Data Leak Prevention > Document Fingerprinting.
2. In the Manual Document Fingerprints section, select Create New.
3. Select the file to be fingerprinted.
4. Choose a Sensitivity level. The default choices are Critical, Private and Warning, but more can be added in the CLI.
5. If the file is an archive containing other files, select Process files inside archive if you also want the individual files inside the archive to have fingerprints generated in addition to the archive itself.
6. Select OK.
The file is uploaded and a fingerprint generated.
To configure a fingerprint document source
1. Go to Security Profiles > Data Leak Prevention > Document Fingerprinting.
2. In the Document Sources section, select Create New.
3. Configure the settings:
Name
Enter a descriptive name for the document source.
Server Type
This refers to the type of server share that is being accessed. The default is Windows Share but this will also work on Samba shares.
Server Address
Enter the IP address of the server.
User Name
Password
Enter the user name and password of the account the FortiGate unit uses to access the server network share.
Path
Enter the path to the document folder.
Filename Pattern
You may enter a filename pattern to restrict fingerprinting to only those files that match the pattern. To fingerprint all files, enter an asterisk (“*”).
Sensitivity Level
Select a sensitivity level. The sensitivity is a tag for your reference that is included in the log files. It does not change how fingerprinting works.
Scan Periodically
To have the files on the document source scanned on a regular basis, select this option. This is useful if files are added or changed regularly. Once selected, you can choose Daily, Weekly, or Monthly update options, and enter the time of day the files are fingerprinted.
Advanced
Expand the Advanced heading for additional options.
Fingerprint files in subdirectories
By default, only the files in the specified path are fingerprinted. Files in subdirectories are ignored. Select this option to fingerprint files in subdirectories of the specified path.
Remove fingerprints for deleted files
Select this option to retain the fingerprints of files deleted from the document source. If this option is disabled, fingerprints for deleted files will be removed when the document source is rescanned.
Keep previous fingerprints for modified files
Select this option to retain the fingerprints of previous revisions of updated files. If this option is disabled, fingerprints for previous version of files will be deleted when a new fingerprint is generated.
4. Select OK.