The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

ICAP client configuration prerequisites

Prev Next

Before the third-party device such as BlueCoat ProxySG can communicate with the Network Security appliance acting as an ICAP server, make sure that the following third-party device settings are configured so that the device can act as an ICAP client:

  • Enable the ICAP client on the proxy server.

  • Specify the IP address of the appliance running the ICAP service in the ICAP client configuration on the proxy server.

  • Enable the preview option for both request and the response modification modes in an ICAP proxy configuration. Otherwise, the Network Security appliance cannot handle files that exceed the configured maximum file size.

  • Enable the X-Client-IP in the header so that the ICAP client can send the request to the ICAP server. The value of the X-Client-IP header field is the source IP address of the encapsulated HTTP request.

  • Enable the X-Server-IP in the header so that the ICAP client can send the request to the ICAP server. The value of the X-Server-IP header field is the destination IP address of the encapsulated HTTP request.

  • Specify the ICAP URL so that the ICAP client can send the requests to the ICAP server fe-nx service. Specify the fe-nx service URL in the following format:

    icap://<appliance_ICAP_server_IP_address>:1344/fe-nx
  • Import the server certificate and matching key and use the same certificate to create a secure ICAP profile to establish a secure ICAP connection.

  • (Optional) Enable feedback to users about the status of ICAP downloads. See Enabling ICAP feedback with the Return Patience page in ICAP client.