All pages
Powered by GitBook
1 of 5

Loading...

Loading...

Loading...

Loading...

Loading...

Install Nightfall DLP for Gmail

Learn how to install the Nightfall DLP for Gmail.

This document explains the process of installing Nightfall DLP for Gmail. Nightfall DLP for Gmail allows you to scan all outgoing emails for sensitive data. Nightfall DLP for Gmail can scan both, email body and attachments.

Prerequisites

  • You must have a Google Workspace account.

  • You must have administrator access to the above Google Workspace account.

Overview

When Nightfall detects emails with sensitive data, it can either Block, Quarantine, or Encrypt the email, based on the automated actions configured in the sensitive data policy for Gmail. To enable Nightfall to perform the quarantine action, you must set up compliance rules in Google Workspace.

Once you set up the compliance rules, you must then configure routing rules to setup the SMTP relay service to receive emails from Nightfall.

Configure Routing Rules - SMTP Relay Settings

Learn how to configure the routing rules for SMTP relay settings in the Google Workspace.

Once you create the content compliance rules, you must set up the routing rules to configure SMTP relay settings. This ensures that you receive emails only from Nightfall's trusted IP addresses.

Prerequisites

In the Nightfall UI, navigate to Integrations from the left navigation bar and click the Manage button for the Gmail integration.

All the headers and expressions required to create the compliance rules are available in the Installation section under Gmail settings as displayed in the image below. Keep this screen open to copy/paste the headers as you create the routing rules in Google Workspace. We will refer to this page as the Gmail settings page throughout the document.

Configure Routing Rules

To configure routing rules:

  1. Login to your Google Workspace with an admin account.

  2. Navigate to the admin console.

  3. From the left menu, expand Apps > Google Workspace > Gmail.

  4. Scroll down and select Routing

  1. Scroll down to the SMTP relay service section and click ADD ANOTHER RULE (the button can be displayed as CONFIGURE if you have not created any SMTP rules).

  1. Enter a name for the SMTP rule (the name"Routing" is used in this case).

  2. Select the Only accept mail from the specified IP addresses check box.

  3. Click ADD.

  1. In the Add Setting dialog box, enter a description in the Description field ("Nightfall IP" is used in this case).

  2. Navigate to the Gmail settings page on the Nightfall UI and copy the value from the IP Address 1 field, located under the Routing - SMTP Relay Service section.

  3. Return to the Google Admin Workspace window and paste the copied value in the Enter IP address/range field.

The IP address is added as shown in the following image.

  1. Repeat steps 8-12 to add the other two Nightfall IP addresses (In step 10, copy the values under IP address 2 and IP address 3 fields).

  2. Select the Require TLS encryption check box.

  3. Click SAVE.

Configure Content Compliance Rules

Learn how to configure Content Compliance rules in the Google Workspace.

A Content Compliance rule in Google Workspace is a predefined set of text, numerical patterns, or text patterns. You can set up rules to match the predefined text.

You must create the following compliance rules and SMTP relay service to set up Gmail DLP.

  • Content Compliance Rule for Monitoring: This rule monitors outgoing emails.

  • Content Compliance Rule for Quarantine: This rule is only required if you wish to use the quarantine action in Nightall.

  • : Once you create the content compliance rules, you must set up the routing rules to configure the SMTP relay service.

Configure Content Compliance Rule - Quarantine

Learn how to create a quarantime content compliance rule in the Google Workspace.

The Quarantine compliance rule quarantines the email that contains sensitive data.

In the Nightfall UI, navigate to Integrations from the left navigation bar and click the Manage button for the Gmail integration.

All the headers and expressions required to create the compliance rules are available in the Installation section under Gmail settings as displayed in the image below. Keep this screen open to copy/paste the headers as you create the content compliance rules in Google Workspace. We will refer to this page as the Gmail settings page throughout the document.

Configure SMTP Relay Service
.

Click SAVE.

Navigate to the Compliance page of the Google Workspace (ignore this step if you are already there else refer to steps 1-6 of the Create Content Compliance Rule - Monitoring document to navigate to the compliance section).

  • Scroll down to the Content Compliance section and click ADD ANOTHER RULE. (If you have not created any Compliance rule previously, the button might be displayed as CONFIGURE).

    1. Enter a name for the compliance rule ("Quarantine Rule" is added as the name in this document).

    2. Select Outbound and Internal - Sending checkboxes in the Email messages to affect section.

    1. Select the If ANY of the following match the message option.

    2. Click Add.

    1. In the Add setting dialog box, select the Advanced Content match option.

    2. In the Location drop-down menu, select Full headers.

    3. In the Match type drop-down menu, select Contains text.

    4. Navigate to the Gmail settings page on the Nightfall UI and copy the value from the Header field, located under the Quarantine Content Compliance Rule (Optional) section.

    5. Return to the Google Admin Workspace window and paste the copied value in the Content field. Nightfall updates the headers for all emails that need to be quarantined with “x-nightfall-quarantine”, once they are processed and before they are routed back to Gmail. This enables Gmail to quarantine the emails with this header.

    6. Click SAVE.

    1. In stage 3, select Quarantine message.

    2. (Optional) Select the Notify sender when mail is quarantined check box to notify the sender when their email is quarantined.

    3. Click SAVE.

    Important

    You must configure this rule only if you wish to use the quarantine automated action.

    Prerequisites

    Content Compliance - Quaranatine

    Step 1 - Email Messages to Affect

    If you select only the Outbound check box, only those emails that are routed out of your organization to external domains, are scanned. If you wish to scan internal emails (emails that are sent between the employees of your organization). you must select the Internal - Sending check box.

    Step 2 - Add Expressions

    Step 3 - Add Quarantine Header

    Create Content Compliance Rule - Monitoring

    Learn how to create a monitoring content compliance rule in the Google Workspace.

    This document is only applicable to new customers who are setting up Gmail DLP for the first time. If you are an existing customer and have setup Gmail DLP previously, refer .

    The first content compliance rule is used to monitor all outgoing emails.

    Important

    It is mandatory for you to create this rule to monitor outgoing emails for sensitive data.

    Summary

    1. Setup Host and Route

    2. Setup "Email Messages to Affect"

    3. Add the Regex Expressions

    In the Nightfall UI, navigate to Integrations > click the Manage button for Gmail integration.

    The steps to create content compliance rule are as follows.

    1. Login to Google Workspace with an admin account > navigate to the console.

    2. From the left menu, Apps > Google Workspace > Gmail > > click ADD ROUTE

    1. Name: (Anything)

    2. Host Name: 2r2xfv8u7uz5.fips.qbns.mail-manager-smtp.amazonaws.com

    3. Port: 25

    1. Under Settings for Gmail, scroll down and click .

    1. Navigate to Content Compliance > click ADD ANOTHER RULE. NOTE: If you have not created any Compliance rule previously, the button might be displayed as CONFIGURE.

    1. Enter a name for the compliance rule, such as "Nightfall DLP".

    2. Navigate to Email messages to affect:

      1. Select Outbound

    1. In step 2 of the content compliance rule, select:

      • If ALL of the following match the message

    2. Add two expressions in step 2 of content compliance rule. Click ADD.

    1. Set the following settings within the "Add setting" dialog box:

      1. Change Simple Content Match > Advanced Content match.

      2. Location: Select Sender header

    1. Click SAVE.

    1. Add a second Expression under the same area by clicking Add.

      1. Change Simple Content Match > Advanced Content match.

      2. Location: Select Full headers

    1. In step 3, select Modify message.

    2. Under the Headers section, select the Add X-Gm-Original-To header check box.

    3. Select the Add custom headers check box. The Custom headers section is displayed once you select this check box.

    There are two fields; Header key and Header value.

    1. From the other tab for the Nightfall Console for , copy/paste:

      1. Messaging Modification: Authentication field value > paste into Header Key

      2. Messaging Modification: Nightfall UUID field value > paste into Header value

    1. Scroll down to the Route section

      1. select Change Route

      2. click the dropdown

    1. Scroll to the Encryption (onward delivery only) section

      • select Require secure transport (TLS).

    2. Click SAVE.

    Click Save.
    Select Internal - Sending
    Match type: Select Matches Regex
  • Regexp: Copy from Nightfall Gmail > Monitoring Content Compliance Rule header:

    1. For a single domain:

      • .*@<your-domain>\.<suffix>$

    2. For more than one domain:

      • (.*@<your-domain>\.<suffix>$|.**@<your-domain>\.<suffix>$)

  • Regexp: Adjust the regular expression to match your organization name. See example below.

  • Match type: Select Not Contains text

  • Content: From Nightfall Gmail > Full Header > copy/paste the Header field:

    • "x-nightfall-scanned"

  • Click SAVE.

  • Click ADD under Custom headers to add a new custom header.

    Click SAVE.

    select the routing rule created in the Content Compliance Rule section (step 5).

    Prerequisites

    All Compliance Rule headers and expression are available in Gmail (Manage) > Installation.

    Keep this screen open to copy/paste the headers and expressions into Gmail throughout the process.

    Content Compliance

    Step 1: Setup Host and Route

    Step 2: Setup "Email Messages to Affect"

    The list of Organization Units (OUs) is visible on the left of the screen (see image below).

    You can directly configure the compliance rules and routing rules on your production OU (OU at the top most level) by selecting the same.

    NOTE: Nightfall recommends to initially configure the rules on a subset OU (one of the nested OUs), for testing/monitoring purposes. Once the configuration is working as expected on the nested OU, you can configure the compliance rules on the production OU.

    If you select only the Outbound check box, only those emails that are routed out of your organization to external domains, are scanned. If you wish to scan internal emails (emails that are sent between the employees of your organization). you must select the Internal - Sending check box.

    Step 3: Add Expressions

    For example, if your organization name is Contoso.com, you can create the regular expression as .*@contoso\.com$

    If you are using multiple domains to send emails from your organization and you need to scan outgoing emails from all those domains for sensitive data, you can use a regular expression to specify multiple domains as illustrated in installation instructions in the Nightfall console. For example, (.@domain-name.extension$|.@domain-name.extension$)

    The condition expression is created as follows. This expression ensures that all the emails that are not yet scanned by Nightfall are scanned.

    Step 4: Modify Message and Add Custom Headers

    Modify Message and Add Custom Headers
    Admin
    Hosts
    Compliance
    Nightfall Gmail
    this documentation