Trellix DLP Network Prevent – SaaS works with ICAP-compliant web proxies to protect web traffic.
To fully integrate an ICAP client with a Trellix DLP Network Prevent appliance, the ICAP client must be able to:
Split requests from responses (REQMOD vs. RESPMOD). For example, in some environments it might be preferable for Trellix DLP Network Prevent – SaaS to process only web requests going to public sites, rather than processing every bit of HTTP traffic on the network.
Add an X-Authenticated-User ICAP request header to provide the Trellix DLP Network Prevent – SaaS appliance with the end user making the request for policy evaluation purposes.
Add X-Client-IP and X-Server-IP request header to provide the Trellix DLP Network Prevent – SaaS appliance with source and destination IP addresses for reporting purposes.