Create a new ICAP Configuration

About this task

Use ICAP configuration to define:
  • Server connection information necessary for Secure Proxy to establish a connection with the ICAP server
  • File/Request properties for files/requests to be scanned by a third-party anti-virus software

    ICAP Server configuration defined here can be pushed to multiple engines and be used to connect to ICAP Server per engine basis for a given SFTP/HTTP/Connect:Direct Adapter. For more information on ICAP configuration field definitions, see ICAP Configuration Field Definitions.

Procedure

  1. From the Advanced tab, click Action>New ICAP Configuration.
  2. Click the Basic tab and specify values for the following ICAP server connection details:
    • ICAP Server Name
    • ICAP Server Host
    • ICAP Server Port
  3. Click the Security tab, and then click Use Secure Connection to enable security. Use this screen to define secure connection requirements for this connection. Specify values for the following:
    • Security Setting
    • Trust Store
    • CA/Trusted Certificates
    • Key Store

    • Key/System Certificate

    • Selected Ciphers

  4. Click Advanced tab and define additional ICAP server requirements for this connection. Specify values for the following:
    • Maximum allowed file/request size
    • Maximum allowed ICAP sessions
    • Connection retry limit
    • ICAP response timeout
    • In case of ICAP server connection failures
      • Session fails
      • Send file/request unscanned to backend
    • ICAP server provider
    • ICAP Server Service Name
    • Preview Scanning
  5. Click Scan by Extension tab to define file extension types to be considered for anti-virus scanning.
    Note: This feature is only available for SFTP and CD based ICAP anti-virus scanning.
  6. Click Rename Unscanned Files tab to enable applying an extension to unscanned files. This feature is only available for SFTP and HTTP based ICAP anti-virus scanning.
  7. Click Properties tab to add user-defined properties for ICAP support. The following pre-defined properties are provisioned in the system:
    • icap.connection.timeout.secs
    • icap.handshake.timeout.secs
    • icap.scan.buffer.size
    • icap.service.profile.name
    • num.preview.bytes
    • sftp.client.temp.ext.names
    • icap.http.unscanned.header.key
    • icap.http.unscanned.header.value
  8. Click Save.