Enable secure ICAP connections

Prev Next

Appliance port 11344 is the only port that receives SSL traffic for ICAP. For communication to happen in the SSL mode, you can enable the secure ICAP port. To use this mode, you also have to import the appliance certificate.

  1. Import the appliance certificate for ICAP connections by uploading the certificate to /home/admin/upload/cert.

    The appliance uses this certificate for ICAP and SMTP traffic. If you have already imported a certificate for SMTP traffic over TLS, you can skip this step.

    The certificate is automatically picked up from this location and imported by the appliance. When negotiating TLS for ICAPS, the appliance presents this certificate. Make sure you have a valid Common Name (CN), Subject Alternative Name, or both.

    Note

    The file transferred to the /home/admin/upload/cert folder disappears on successful ingestion, which means that the ingestion utility has picked the file and processed it for later use. The file usually disappears even before you can access the folder to check the upload. But, if the file is present in this folder after the upload is complete, it indicates an error. You can also check whether the installation succeeded or failed from /var/log/messages or the Client Events page.

  2. Enable secure ICAP:

    1. In ePO - SaaS, open Policy Catalog.

    2. Select the DLP Appliance Management <version> product, select the Trellix DLP Network Prevent Web Settings category, and open the policy you want to edit.

    3. Select the Secure ICAP (port 11344) and Unencrypted ICAP (port 1344) checkboxes.

    4. Click Save.

    To use only secure ICAP, deselect the Unencrypted ICAP (port 1344) checkbox and configure the web proxy to send traffic to only port 11344.