Internet Content Adaptation Protocol (ICAP) is a lightweight HTTP-based remote procedure call protocol used to offload specific Internet-based content to dedicated servers. For example, you can offload the malware scanning function to a dedicated server to ensure optimal performance. ICAP is used to implement virus scanning, content translation, and content filtering in transparent HTTP proxy caches.
You can configure a Intelligent Virtual Execution - Server appliance to operate as an ICAP server. An ICAP server performs content transformation on the requests and sends back responses with appropriate action to take on the request or response. An ICAP-enabled Intelligent Virtual Execution - Server ICAP Integration appliance performs signature and callback detection and malware analysis on ICAP-encapsulated data from a proxy server running an ICAP client.
The ICAP service is disabled by default and must be explicitly enabled and configured.
An ICAP-enabled Intelligent Virtual Execution - Server appliance receives HTTP requests and responses that the ICAP client forwards over ICAP on one of the appliance management interfaces. A secure ICAP connection must be established between the Intelligent Virtual Execution - Server appliance and the ICAP client. By default, the ICAP service supports two types of modes—request modification (REQMOD) and response modification (RESPMOD).
Note
REQMOD support is available starting from version 10.0.4.
The ICAP service can be configured to block REQMOD and RESPMOD requests received from ICAP clients. When blocking is enabled, detection of a potential threat causes the appliance to block the requested data and instead serve the client browser a HTTP comfort page.