Disable ICAP scanning, and manage the types of requests that you want the appliance to handle.
Option definitions
Option
Definition
Apply Policy
By default, Allow Policy Push is enabled. Deselecting Allow Policy Push doesn't apply the configuration or policy changes you have made and this allows you to review the changes. After reviewing the configuration or policy changes, select Allow Policy Push.
Web Settings
The Trellix DLP Network Prevent appliance analyzes traffic from Web Gateway through the secure and unencrypted port.
Disable all unused services.
If you choose to disable one of the channels, Trellix DLP Network Prevent only accepts connections from the enabled channel.
Services — If both channels are selected, both the secure and unencrypted ICAP ports are open.
Secure ICAP (port 11344) — ICAP traffic is encrypted over a TLS connection using the appliance's default certificate. Enabled by default.
Use the encrypted channel for your ICAP traffic.
Unencrypted ICAP (port 1344) — The ICAP communication is in plain text. Enabled by default.
If neither channel is selected, the REQMOD and RESPMOD options are unavailable.
Methods — Specify the type of requests that you want the Trellix DLP Network Prevent appliance to analyze.
REQMOD — Enables scanning of ICAP Request Modification (REQMOD) requests to identify potential data loss incidents in content uploaded to the internet by employees. Enabled by default. You might want to disable REQMOD if you only want to analyze RESPMOD requests.
RESPMOD — Enable scanning of ICAP Response Modification (RESPMOD) requests to identify potential data loss incidents in content downloaded from your organization's web servers by external users. Disabled by default.
Only enable RESPMOD if you have web servers that external users can download information from that you want to analyze.
Permitted Hosts
Accept request from any host — Trellix DLP Network Prevent accepts requests from any computer.
Accept request from these hosts only — When selected, you can type the details of permitted hosts that Trellix DLP Network Prevent can receive requests from. Enter the details of the host using its IP address with subnet, domain name, or wildcard domain name.
You can create groups of permitted hosts using subnets or wildcard domains. To add more than one subnet, you must create separate entries for each.
Data Loss Prevention (DLP) > Trellix Data Loss Prevention 11.13.x Product Guide > Working with Trellix DLP Network policies > Using policies to define how Trellix DLP Network works
Data Loss Prevention (DLP) > Trellix Data Loss Prevention 11.12.x Product Guide - June 2025 > Working with Trellix DLP Network policies > Using policies to define how Trellix DLP Network works
Data Loss Prevention (DLP) > Trellix Data Loss Prevention 11.12.x Product Guide - June 2025 > Appendix > Policy Catalog settings > DLP Appliance Management