ICAP client configuration prerequisites

Prev Next

Before the third-party device such as BlueCoat ProxySG can communicate with the Intelligent Virtual Execution - Server appliance acting as an ICAP server, make sure that the following third-party device settings are configured so that the device can act as an ICAP client:

  • Enable the ICAP client on the proxy server.

  • Enable the cluster on IVX and assign the broker role to one of the nodes. Configure the node with the broker role as the ICAP server.

  • Specify the IP address of the appliance running the ICAP service in the ICAP client configuration on the proxy server.

  • Enable the preview option for the response modification mode in an ICAP proxy configuration. Otherwise, the Intelligent Virtual Execution - Server appliance cannot handle files that exceed the configured maximum file size.

  • Enable the X-Client-IP in the header so that the ICAP client can send the request to the ICAP server. The value of the X-Client-IP header field is the source IP address of the encapsulated HTTP request.

  • Enable the X-Server-IP in the header so that the ICAP client can send the request to the ICAP server. The value of the X-Server-IP header field is the destination IP address of the encapsulated HTTP request.

  • Specify the ICAP URL so that the ICAP client can send the requests to the ICAP server ivx_scan service. Specify the ivx_scan service URL in the following format:

    icap://<appliance_ICAP_server_IP_address>:1344/ivx_scan
  • Import the server certificate and matching key and use the same certificate to create a secure ICAP profile to establish a secure ICAP connection.

  • (Optional) Enable feedback to users about the status of ICAP downloads.