Skip to main content
Question

How can we apply DLP policies for data exfiltration for FTP, as mentioned in quarterly product release webinar

  • December 30, 2025
  • 1 reply
  • 50 views

amitkumarp
Netskope Partner

1 reply

  • Netskope Employee
  • January 5, 2026

Hi ​@amitkumarp 

Yes you can enforce DLP for data exfiltration over FTP by inspecting FTP uploads through Netskope SWG and attaching a DLP profile to that traffic.


How you can validate

  1. Route FTP through Netskope
    Make sure outbound FTP traffic is going through Netskope SWG (IPsec/GRE/explicit proxy) and visible in Web / Activity logs as FTP.
     

  2. Create/choose a DLP profile
    Use or create a DLP profile with the sensitive data types you want to protect (e.g. source code, PII, PCI, etc.).

  3. Create a Real‑time Protection (Web) policy

    • Scope to FTP (category/app or specific FTP domains).

    • Set Activity to Upload/Put (FTP upload).

    • Attach your DLP profile and set Action to Block (or Alert+Block).

  4. Test
    Upload a test file that matches your DLP profile via FTP and verify it is blocked and generates a DLP incident.