You can configure Web Gateway to forward HTTP traffic using ICAP to Trellix DLP Network Prevent for analysis. Trellix DLP Network Prevent returns a response to Web Gateway, allowing or denying the page.
Note
All versions of Web Gateway are supported, but these steps are applicable only for version 7.8.1. The steps can differ slightly for older or newer versions. For the detailed steps in the version of Web Gateway that you have installed, see the Web Gateway documentation.
In Web Gateway, select Policy.
Add the rule set:
Click the Rule Sets tab.
Select Add → Rule Set from Library.
From the ICAP Client rule set library, select ICAP Client, then click OK.
Click Unlock View, then click Yes.
Deselect Responses.
(Optional) If you want the generated incidents to contain the destination IP address, edit the REQMOD settings.
On the Rule Sets tab, expand the ICAP Client rule set and select ReqMod.
Select Add X-Server-IP header.
Follow these steps to set the appliance as an ICAP client:
Click the Lists tab, expand ICAP Server and select ReqMod Server.
Select 1 and click Edit.
Type the IP address or the fully qualified domain name of the Trellix DLP Network Prevent appliance, followed by the ICAP mode in the URI field. Optionally, you can add a port. If you add no port, the default port 1344 is configured.
The syntax for specifying this information is displayed above the field. For example, you can use one of these formats:
icap://xx.xxx.xxx.xx/reqmodicap://xx.xxx.xxx.xx:1346/reqmodicap://test-icap.micmwg.com/reqmodicap://test-icap.micmwg.com:1346/reqmodClick OK.
Enable the rule.
On the Rule Sets tab, select the ICAP Client rule.
Select Enable.
Click Save Changes.