The Network Security appliance acting as an ICAP server receives traffic sent over ICAP on either the ether1 or ether2 management interface on TCP port 1344 by default. A secure ICAP connection between the Network Security appliance and the ICAP client must be established on TCP port 11344 by default.
By default, the Network Security appliance acting as an ICAP server uses a system-self-signed certificate to establish secure communication. If you want to use another certificate, you must import the server certificate and matching key on the Network Security appliance and specify the same certificate as part of the ICAP service settings. For details about how to import a server SSL certificate, see the Trellix System Security Guide.
You can configure the ICAP server port and SSL certificate settings using the Network Security appliance Web UI or CLI: