DLP in NGAF

IT Infra Lv1Posted Feb-13-2026 09:46

Hii there, i've been adding custom DLP Signature in my NGAF, but how do i call my custom DLP into Policies? Thanks.

By solving this question, you may help 971 user(s).

Posting a reply earns you 2 coins. An accepted reply earns you 20 coins and another 10 coins for replying within 10 minutes. (Expired) What is Coin?

Enter your mobile phone number and company name for better service. Go

net_specialist Lv2Posted Feb-13-2026 11:52
  
Once you have configured your custom application signatures in Network Secure (NGAF), you can directly call them in the application control policy under the option [Applications]. For standard version Network Secure (NGAF) 7.4 and above, this is done by configuring under [Policies] - [Access Control] - [Application Control][1].
Humayun Ahmed Lv3Posted Feb-13-2026 12:14
  
Custom DLP Signature
        ↓
DLP Template / Profile
        ↓
Security Policy (Firewall Policy)
        ↓
Traffic Matching
Muhammad Abid Lv2Posted Feb-13-2026 13:39
  
On Sangfor NGAF:

1️⃣ Create your Custom DLP Signature (and enable it).
2️⃣ Add it to a Custom Signature Group.
3️⃣ Go to Security Policy → DLP Policy.
4️⃣ Create/Edit a rule and select that Signature Group in the DLP/Profile section.
5️⃣ Set action (Block/Alert) and Apply/Commit.

Damai_Group Lv1Posted Mar-21-2026 20:33
  
Once you've created your custom DLP signature, you need to reference it inside a policy. For DLP, you'll typically use an Application Control policy, as the custom signature essentially acts like a new application for the firewall to detect.

Here is how to call your custom signature in a policy:

1. Find Your Custom Signature
First, confirm your custom signature has been created and is active:
- Navigate to Objects > Content Identification Database > Application Signatures.
- Click on the Custom App Signatures tab. Your new signature should be listed here.
- Critical Step: Ensure the "Prioritize custom app signatures" checkbox at the top of this page is selected. This ensures your rule is matched before any built-in ones, preventing conflicts.

2. Create the Policy
Now, go to the policy section where you want to enforce the rule. To block or monitor traffic matching your DLP signature:
- Go to Policies > Application Control (this is the most common place to control custom signatures).
- Click Add to create a new policy.
- Set the Source and Destination zones (usually your internal network to the internet).
- Define the Action (e.g., "Deny" to block the data leak, or "Allow" to simply monitor it).

3. Select Your Custom DLP Object
In the policy configuration window, you will see an area to select applications:
- In the Application selection field, search for the App Name you assigned when creating the signature.
- Select your custom application from the list.
- Complete the rest of the policy configuration and click OK.

4. Apply and Move to Top
- Ensure the new policy is placed at the top of the policy list to ensure it is processed before more general "Allow All" rules.

Important Note: If you are specifically looking for a "DLP Policy" section and don't see it, confirm that your NGAF license includes the DLP feature. It is often part of a higher-tier subscription bundle. If it's not available, the Application Control method is the standard way to enforce rules based on custom signatures.

Try creating the Application Control policy first and let me know if you run into any issues selecting your custom signature object

I Can Help:

Change

Moderator on This Board

1
148
3

Started Topics

Followers

Follow

954
194
98

Started Topics

Followers

Follow

Board Leaders