Before the third-party device such as BlueCoat ProxySG can communicate with the Network Security appliance acting as an ICAP server, make sure that the following third-party device settings are configured so that the device can act as an ICAP client:
Enable the ICAP client on the proxy server.
Specify the IP address of the appliance running the ICAP service in the ICAP client configuration on the proxy server.
Enable the preview option for both request and the response modification modes in an ICAP proxy configuration. Otherwise, the Network Security appliance cannot handle files that exceed the configured maximum file size.
Enable the
X-Client-IPin the header so that the ICAP client can send the request to the ICAP server. The value of theX-Client-IPheader field is the source IP address of the encapsulated HTTP request.Enable the
X-Server-IPin the header so that the ICAP client can send the request to the ICAP server. The value of theX-Server-IPheader field is the destination IP address of the encapsulated HTTP request.Specify the ICAP URL so that the ICAP client can send the requests to the ICAP server
fe-nxservice. Specify thefe-nxservice URL in the following format:icap://<appliance_ICAP_server_IP_address>:1344/fe-nx
Import the server certificate and matching key and use the same certificate to create a secure ICAP profile to establish a secure ICAP connection.
(Optional) Enable feedback to users about the status of ICAP downloads. See Enabling ICAP feedback with the Return Patience page in ICAP client.