The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Enabling or disabling the ICAP request and response modification modes

Prev Next

A third-party device acting as an ICAP client can forward HTTP requests and responses to an ICAP server for processing. A appliance acting as an ICAP server receives the file objects from the ICAP client and extracts the objects for analysis. The ICAP service supports ICAP messages in request modification (REQMOD) mode and in response modification (RESPMOD) mode:

  • In request modification mode, an ICAP client can send the appliance ICAP-encapsulated HTTP requests.

  • In response modification mode, an ICAP client can send the appliance ICAP-encapsulated HTTP responses.

The ICAP-enabled appliance performs content transformation on the ICAP REQMOD or RESPMOD request sent by the ICAP client and sends back responses with appropriate action to take on the encapsulated HTTP request or response.

REQMOD support and RESPMOD support are enabled by default.

Note

The ICAP feature on the appliance does not support malware file analysis in the following scenario only: A user uploads a file to a Web server using the HTTP POST method and the ICAP Client transmits the file data to theTrellix appliance (ICAP server) using the ICAP REQMOD method.

When REQMOD or RESPMOD is disabled for the ICAP service, the Network Security appliance sends the ICAP client a 204 response code.

You can enable or disable the REQMOD and the RESPMOD for the ICAP service by using the Network Security appliance Web UI or CLI:

  • icap-service respmod enable — This command enables the processing of response modification for ICAP data.

  • no icap-service respmod enable — This command disables the processing of response modification for ICAP data.