The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

ICAP client configuration prerequisites

Prev Next

Before the third-party device such as BlueCoat ProxySG can communicate with the Intelligent Virtual Execution - Server appliance acting as an ICAP server, make sure that the following third-party device settings are configured so that the device can act as an ICAP client:

  • Enable the ICAP client on the proxy server.

  • Enable the cluster on IVX and assign the broker role to one of the nodes. Configure the node with the broker role as the ICAP server.

  • Specify the IP address of the appliance running the ICAP service in the ICAP client configuration on the proxy server.

  • Enable the preview option for the response modification mode in an ICAP proxy configuration. Otherwise, the Intelligent Virtual Execution - Server appliance cannot handle files that exceed the configured maximum file size.

  • Enable the X-Client-IP in the header so that the ICAP client can send the request to the ICAP server. The value of the X-Client-IP header field is the source IP address of the encapsulated HTTP request.

  • Enable the X-Server-IP in the header so that the ICAP client can send the request to the ICAP server. The value of the X-Server-IP header field is the destination IP address of the encapsulated HTTP request.

  • Specify the ICAP URL so that the ICAP client can send the requests to the ICAP server ivx_scan service. Specify the ivx_scan service URL in the following format:

    icap://<appliance_ICAP_server_IP_address>:1344/ivx_scan
  • Import the server certificate and matching key and use the same certificate to create a secure ICAP profile to establish a secure ICAP connection.

  • (Optional) Enable feedback to users about the status of ICAP downloads.