Enabling and configuring the ICAP service on a Network Security appliance enables the appliance to act as an ICAP server, performing signature and callback detection and malware analysis on ICAP-encapsulated data from a proxy server running an ICAP client. The appliance generates ICAP alerts based on traffic sent over ICAP, and you can view the analysis results on the Hosts tab and the Alerts tab in the appliance Web UI.
Note
The ICAP service is disabled by default.
You can enable or disable the ICAP service by using the appliance Web UI or CLI: