Skip to main content

Welcome to our updated site!

Skyhigh Security

Set up Inline DLP for Gmail

IMPORTANT: Before setting up Gmail Inline DLP, you must open a support ticket, and request assistance in pre-configuring your tenant.

 

Step 1: Create a Gmail Instance in Skyhigh CASB 

  1. Log in to Skyhigh CASB.
  2. Go to Settings > Service Management.
    service management.png
  3. Click Add Service Instance.
    clipboard_e045e47b05b2f09d55d48c310b898174e.png
  4. Select Gmail, enter a name for this new instance, and click Done.
  5. To configure the instance, click Configure.
    clipboard_ee05e4a3ea589ed5a1c92a63f0679c9fe.png
  6. Activate the Data Loss Prevention (DLP) to ensure compliance checkbox, and under Email DLP Mode, select Inline Only.
    inline Only.png
  7. Review the prerequisites, and activate I have reviewed all prerequisites checkbox.
    gmail.png
  8. Make sure the following are complete:
    • Domains. Populate with all public domains configured with the Google Suite tenant.
    • Take a note of the Skyhigh CASB Email Service Domain. You will need this later.
    • Select the checkbox confirming you've configured Gmail, as you need this in the next step. 
      clipboard_e05345a472c017d6dbaf63f1200c48420.png
  9. Review the settings, and click Done.
    clipboard_e8486a9ce6fa817a8f9d9676a79bac84b.png

Step 2: Configure Gmail to Route Email to Skyhigh CASB 

  1. Log in to Google Suite admin (https://admin.google.com), and go to Apps.
    1.png
  2. Select Google Workspace.
    2.png
  3. Select Gmail
    3.png
  4. Scroll down and select Hosts.
    4.png
  5. On the Hosts tab, click ADD ROUTE.
    clipboard_e0035b5f8fcde7e80716a1b9313246920.png
  6. Enter the following details for the new mail route:
    • Enter a name
    • Enter the single host as captured earlier (Skyhigh CASB Email Service Domain).
    • Enter port 25.
    • Disable MX lookup and Require secure transport TLS.

NOTE: Do not enable Require secure transport (TLS) because it requires communication between the email servers initiated with TLS. Skyhigh CASB uses START-TLS instead, which initiates communication with standard SMTP. Then upgrade to TLS after the connection is set up.

 

clipboard_e4774ba51396bde8c0b4e91b273f84157.png

clipboard_ee68a61ea3d2df5e989076913db93500a.png

  1. Select the Settings for Gmail tab, and click Compliance.
    7inline new.png
  2. Under the Content compliance section, click CONFIGURE .
    8inline.png

  3. Configure the rule as follows:
    • Enter a name for the rule (for example, Skyhigh CASB DLP).
    • Select Outbound.
    • Select Internal - sending to enable scanning for internal emails, sent from GMail to the Skyhigh CASB PoP. Click ADD.
      9inline.png
    • Advanced content match. Full headers, Not contains text, "X-SHN-DLP-SCAN: success".
      clipboard_ee59f2675d29b239dda7634383b19f9b5.png
    • Change Route and select the host created earlier.
      clipboard_ef955a00ec569e6c1847844a5abfb5b57.png
    • More options:
      • Select Users and Groups as the account type to affect.
      • IMPORTANT: If this is a production environment, apply this rule to a test user/group so all mailboxes are not impacted.
        9d.png

IMPORTANT: Do not save the configuration yet.

 

  • To enable DLP for specific users or mail groups, configure the following:
    • Under Envelope filter, select Only affect specific envelope senders.
      clipboard_e6488d8150961fe828c5700692a6cb825.png
    • Select Group membership (only sent mail) to enable DLP for mail groups.
    • Click Select groups, and select the required mail groups.
      clipboard_e3c1f4540066798257b44c02911e8f0ea.png
    • Click Save.
      clipboard_e645d8135e148f50ef5fc331d0d0fd402.png
  1. Under the Settings for Gmail, select Routing.
    10 inline.png
  2. Find the SMTP relay service and click CONFIGURE.
    11.png
  3. Configure the SMTP relay service rule as follows:
    • Enter a name for the rule (for example,  Skyhigh CASB DLP).
    • Allowed Senders. Set to Only addresses in my domains.
    • Authentication. Select Only accept mail from the specified IP addresses and enter the following based on the environment. 
    • You must add each IP address to the list as in the following Gmail rule:
Skyhigh CASB Source IP Addresses
United States Canada EU GOV
  • 35.169.47.31
  • 54.164.132.26
  • 52.6.177.238
  • 35.170.110.227
  • 13.59.69.222
  • 3.14.37.51
  • 18.217.82.134
  • 52.53.40.121
  • 52.53.131.105
  • 52.8.140.255
  • 18.234.18.255
  • 54.227.184.154
  • 3.105.168.205
  • 52.65.168.11
  • 54.79.123.149
  • 3.106.109.130
  • 52.62.169.21
  • 13.55.31.182
  • 54.66.99.155
  • 3.104.39.150
  • 52.64.188.221
  • 3.106.94.86
  • 65.0.160.113
  • 65.2.86.69
  • 65.1.17.176
  • 65.1.151.216
  • 65.0.241.149
  • 3.7.148.104
  • 35.182.84.200
  • 15.222.68.144
  • 15.222.50.218
  • 35.183.159.113
  • 3.120.8.62
  • 35.157.197.205
  • 3.120.122.0
  • 3.66.100.238
  • 35.157.28.15
  • 13.53.250.187
  • 13.50.23.23
  • 13.48.175.172
  • 13.48.141.247
  • 13.48.146.72
  • 54.154.11.112
  • 52.208.188.45
  • 52.214.141.239
  • 34.248.12.100
  • 34.242.65.202
  • 52.61.94.253
  • 15.200.38.217
  • 18.252.127.142
  • 18.252.136.33
  1. Encryption: Set Require TLS encryption and click SAVE.
    11inline.png
  2. Once saved, you can view the compliance and SMTP relay configurations.
    Save.png
  3. Under the Settings for Gmail tab, select Spam, Phishing and Malware.
    Spam.png
  4. Under Email allowlist, click the Edit icon.
    Email allow list.png
  5. Add the IP addresses that were added in the Step 12 based on your environment separated by commas.
  6. Click SAVE.
    IP allowlist.png
  7. Once saved, you can view the following message.
    last.png

Step 3: Configure a DLP Rule 

  1. In Skyhigh CASB, go to Policy> DLP Policies, and add a new rule applied to Gmail. An example is shown below.
    • Type: API
    • Active: ON
    • Services: Gmail instance you created earlier
    • Action: Block email
      clipboard_e397a78d3abecb388069f5947c614b977.png
      exceptions.png
      policy data.png

​​​​​NOTE: The only actions supported are Generate Incident or Block Email.

 

Step 4: Test the Configuration

  1. Log in to Gmail using a user account, and send an email with content that will trigger the configured DLP rule.
    sent.png
  2. Confirm that the email is NOT received by the recipient.
  3. Confirm that a policy incident is created and the action blocked the email.
    blocked.png

  • Was this article helpful?