The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Enabling or disabling the ICAP service

Prev Next

Enabling and configuring the ICAP service on a Network Security appliance enables the appliance to act as an ICAP server, performing signature and callback detection and malware analysis on ICAP-encapsulated data from a proxy server running an ICAP client. The appliance generates ICAP alerts based on traffic sent over ICAP, and you can view the analysis results on the Hosts tab and the Alerts tab in the appliance Web UI.

Note

The ICAP service is disabled by default.

You can enable or disable the ICAP service by using the appliance Web UI or CLI: