The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Configuring the ICAP server port and SSL certificate using the CLI

Prev Next

Follow these steps to configure the ICAP server port and SSL certificate using the CLI.

Prerequisites

To configure the ICAP server port and SSL certificate:
hostname (config) # write memory
  1. Go to CLI configuration mode.

    hostname > enable
    hostname # configure terminal
  2. Specify the TCP port for traffic sent over ICAP. Use the following command, where <port_number> is the TCP port number:

    hostname (config) # icap-service tcp port <port_number>

    By default, the ICAP server listens for traffic on port 1344.

  3. Specify the TCP port for a secure ICAP connection between the Network Security appliance and the ICAP client. Use the following command, where <port_number> is the TCP port number.

    hostname (config) # icap-service secure port <port_number>

    By default, a secure ICAP connection is on port 11344.

  4. Specify the management interface to receive traffic sent over ICAP on the Network Security appliance. Use one of the following commands:

    • hostname (config) # icap-service interface ether1
    • hostname (config) # icap-service interface ether2
  5. Specify the SSL certificate that is submitted by the ICAP server to connect to ICAP clients over secure ICAP connections. Use the following command, where <certificateName> is the name of the certificate:

    hostname (config) # icap-service secure certificate <certificateName>

    By default, the system-self-signed certificate is used to establish secure communication.

  6. Verify the configuration your changes:

    hostname (config) # show icap-service config
    ICAP Configuration:
      ICAP enabled               :  no
      Interface                  :  ether1
      Request Mod Enabled        :  yes
      Response Mod Enabled       :  yes
      Block-mode Enabled         :  no
      Response-page Enabled      :  yes
      TCP port                   :  1344
      Secure port                :  11344
      Secure Certificate         :  system-self-signed
      Max Connection             :  25
  7. Save your changes.