Complete the steps for managing the ICAP integration in the following order:
Note
ICAP for the evidence collector model of Network Security can only be managed using the CLI.
Make sure the third-party device settings are configured so that the device can act as an ICAP client. For details, see ICAP client configuration prerequisites.
(Optional) Enable feedback about the progress of ICAP downloads from the proxy server. See Enabling feedback about ICAP traffic.
Enable the ICAP service on the Network Security appliance. For details, see Enabling or disabling ICAP service using the Web UI or Enabling or disabling ICAP service using the CLI.
Enable the request modification mode and response modification mode. For details, see Enabling or disabling ICAP request and response modification modes using the Web UI or Enabling or disabling ICAP request and response modification modes Using the CLI.
Configure the ICAP service settings so that the Network Security appliance can run an ICAP server. For details, seeConfiguring the ICAP server port and SSL certificate using the Web UI or Configuring the ICAP server port and SSL certificate using the CLI.
(Optional) Enable ICAP blocking. A Network Security appliance operating as an ICAP server can block REQMOD and RESPMOD requests received from ICAP clients. For details, see Enabling or disabling ICAP blocking mode using the Web UI or Enabling or disabling ICAP blocking mode using the CLI.
When ICAP blocking is enabled, detection of a potential threat causes the appliance to block the requested data and instead serve the client browser a HTTP comfort page. For details, see Enabling or Disabling the ICAP Blocking Comfort page using the CLI.
Use the Hosts tab and Alerts tab in the Web UI to view the infected ICAP alerts based on traffic sent over ICAP. For details, see Viewing ICAP alerts grouped by infected host in the Web UI or Viewing ICAP alert details grouped by alert in the Web UI.