RSA DLP policy with transmission attributes does not work on Cisco Ironport ESA
3 years ago
Originally Published: 2015-11-28
Article Number
000049931
Applies To
RSA Product Set: DLP
RSA Product/Service Type: Policy
Platform: Cisco Ironport ESA
Issue
After configuring a policy in Enterprise Manager with transmission attributes, the policy is pushed to the Cisco Ironport but does not get triggered when sensitive emails are sent that should have been caught by the policy.
This issue occurs when there are transmission attributes with multiple values separated by commas as the delimiter.
Resolution
Cisco Ironport parses the list of values in transmission attributes considering semicolon as the separator/delimiter as opposed to the comma, which is used for DLP network devices.

Use semicolon as the separator/delimiter for the transmission attribute values and save the policy.

For example: the recipient list in the transmission attributes for Ironport policies should look like the example below.
To Recipient: *@emc.com;*@rsa.com;*@cisco.com