Before the third-party device such as BlueCoat ProxySG can communicate with the Intelligent Virtual Execution - Server appliance acting as an ICAP server, make sure that the following third-party device settings are configured so that the device can act as an ICAP client:
Enable the ICAP client on the proxy server.
Enable the cluster on IVX and assign the broker role to one of the nodes. Configure the node with the broker role as the ICAP server.
Specify the IP address of the appliance running the ICAP service in the ICAP client configuration on the proxy server.
Enable the preview option for the response modification mode in an ICAP proxy configuration. Otherwise, the Intelligent Virtual Execution - Server appliance cannot handle files that exceed the configured maximum file size.
Enable the
X-Client-IPin the header so that the ICAP client can send the request to the ICAP server. The value of theX-Client-IPheader field is the source IP address of the encapsulated HTTP request.Enable the
X-Server-IPin the header so that the ICAP client can send the request to the ICAP server. The value of theX-Server-IPheader field is the destination IP address of the encapsulated HTTP request.Specify the ICAP URL so that the ICAP client can send the requests to the ICAP server ivx_scan service. Specify the ivx_scan service URL in the following format:
icap://<appliance_ICAP_server_IP_address>:1344/ivx_scan
Import the server certificate and matching key and use the same certificate to create a secure ICAP profile to establish a secure ICAP connection.
(Optional) Enable feedback to users about the status of ICAP downloads. See Enabling ICAP feedback with the Return Patience page in ICAP client.