User guide

iGuard/inSight User Guide
Release 7.0.0.4
141
Drop Element excludes all data associated with an element.
For example, your network may have a large cache of video files that you know are not a security threat
because you have controlled them with configuration management software. You can set up a filter that will
pass over any of these secure files, saving time and resources for analyzing data at risk.
Drop Session excludes an entire session from the data stream.
For example, your employees may be authorized to send or receive any SMTP content as long as it is moving
through your company's mail server. You can eliminate these sessions, which will improve the performance of
the capture engine.
Standard Content Capture Filters
Some content types transmitted through the Application layer may need not be analyzed by the
capture engine. If they are not eliminated from the data flow, they can slow iGuard's performance
unnecessarily. A set of standard content capture filters are provided to keep the capture engine
from processing them.
Note: Unlike network capture filters, the order of the list of content capture filters is not
significant.
Ignore Flow Headers
This filter excludes flow headers.
Ignore Small JPG Images
This filter excludes JPG images smaller than 4 MB. This eliminates insignificant images from the data stream.
Ignore Binary Traffic
This filter excludes all binary files.
Ignore Crypto Traffic
This filter excludes encrypted traffic.
Ignore P2P Traffic
This filter excludes all peer-to-peer traffic.
Ignore HTTP Headers
This filter excludes HTTP headers.
Ignore BMP and GIF Images