Complete the steps for managing the ICAP integration in the following order:
Note
ICAP for the evidence collector model of Intelligent Virtual Execution - Server can only be managed using the CLI.
Make sure the third-party device settings are configured so that the device can act as an ICAP client. For details, see ICAP client configuration prerequisites.
(Optional) Enable feedback about the progress of ICAP downloads from the proxy server.
Enable the ICAP service on the Intelligent Virtual Execution - Server appliance. For details, see Enabling or disabling ICAP service using CLI.
Note
The performance of the ICAP server on IVX depends on the number of files submitted. To avoid performance degradation, ensure unwanted or unsupported file types are filtered out at the ICAP client before submission.
Enable the request and response modification modes. For details, see Enabling or disabling ICAP request and response modification modes using CLI.
Configure the ICAP service settings so that the Intelligent Virtual Execution - Server appliance can run an ICAP server. For details, see Configuring the ICAP server port and SSL certificate using the CLI.
(Optional) Enable ICAP blocking. A Intelligent Virtual Execution - Server appliance operating as an ICAP server can block RESPMOD requests received from ICAP clients. For details, see Enabling or disabling ICAP blocking mode using the CLI. After enabling block mode, you can optionally configure the verdict timeout to control how long the appliance waits for an analysis result. See Configuring the Block Mode Verdict Timeout for details.