Web requirements

Prev Next

Trellix DLP Network Prevent works with ICAP-compliant web proxies to protect web traffic.

To fully integrate an ICAP client with a Trellix DLP Network Prevent appliance, the ICAP client must be able to:

  • Split requests from responses (REQMOD vs. RESPMOD). For example, in some environments it might be preferable for Trellix DLP Network Prevent to process only web requests going to public sites, rather than processing every bit of HTTP traffic on the network.

  • Add an X-Authenticated-User ICAP request header to provide the Trellix DLP Network Prevent appliance with the end user making the request for policy evaluation purposes.

  • Add X-Client-IP and X-Server-IP request header to provide the Trellix DLP Network Prevent appliance with source and destination IP addresses for reporting and evaluation purposes.