X-MFE-PREVENT: SCANFAIL ICAP header behavior

Prev Next

Trellix DLP Network Prevent adds the X-MFE-PREVENT: SCANFAIL header in its ICAP response when it detects unscannable content or for ICAP requests that exceed the maximum configured file size for scan.

Trellix DLP Network Prevent categorizes content as unscannable when it can't be analyzed. Examples of unscannable content include corrupt files, files that exceed the maximum analysis size or time, and files that exceed maximum depth if there are nested files. The appliance allows an ICAP request with unscannable content and sends a 2xx ICAP response back to the web proxy server. In addition, the appliance adds the X-MFE-PREVENT: SCANFAIL header in its ICAP response when it detects unscannable content.

By default, the Trellix DLP Network Prevent appliance sends a 4xx ICAP response back to the web proxy server for ICAP requests that exceed the maximum configured file size for scan. You can configure the Trellix DLP Network Prevent appliance to allow these ICAP requests with a 2xx response. When the configuration is enabled, the appliance sends the 2xx ICAP response back to the web proxy server and also adds the X-MFE-PREVENT: SCANFAIL header with information about the cause of the ICAP response. For information about how to configure to allow ICAP requests that exceed the maximum configured file size for scan with a 2xx response, see KB91550.