Internet Content Adaptation Protocol (ICAP) is a lightweight HTTP-based remote procedure call protocol used to offload specific Internet-based content to dedicated servers. For example, you can offload the malware scanning function to a dedicated server to ensure optimal performance. ICAP is used to implement virus scanning, content translation, and content filtering in transparent HTTP proxy caches.
You can configure a Network Security appliance to operate as an ICAP server. An ICAP server performs content transformation on the requests and sends back responses with appropriate action to take on the request or response. An ICAP-enabled Network Security ICAP Integration appliance performs signature and callback detection and malware analysis on ICAP-encapsulated data from a proxy server running an ICAP client.
The ICAP service is disabled by default and must be explicitly enabled and configured. You can enable and configure the ICAP service on the following:
All virtual models except NX 1500V
The NX 2500, NX 2550, NX 3500, NX 4500, NX 5500, and NX 6500 physical models in MVX integrated or sensor mode
An ICAP-enabled Network Security appliance receives HTTP requests and responses that the ICAP client forwards over ICAP on one of the appliance management interfaces. A secure ICAP connection must be established between the Network Security appliance and the ICAP client. By default, the ICAP service supports two types of modes—request modification (REQMOD) and response modification (RESPMOD). The ICAP service can be configured to block REQMOD and RESPMOD requests received from ICAP clients. When blocking is enabled, detection of a potential threat causes the appliance to block the requested data and instead serve the client browser a HTTP comfort page.