C icap
#C ICAP SOFTWARE#
On the Security Gateway, you must enable at least one of the supported Software Blades and the UserCheck.Ĭontrols the X-Headers: X-Client-IP, X-Server-IP, and X-Authenticated-User.
#C ICAP DOWNLOAD#
To avoid HTTP connection timeout when you upload or download large files, you can use the Data Trickling to pass some of the original HTTP payload to its destination, while the ICAP Server scans this HTTP payload.
#C ICAP INSTALL#
Install the Access Control Policy on the Security Gateway.ĭefault: "Blocked Message - Access Control".Add the new message for the UserCheck Block page.You must enter the same name as you configured in the ICAP Client configuration file.Select the Access Control related policy and click OK.Objects menu > Object Explorer > More object types > UserCheck > New Drop.If you change the default value, you must configure your value in the SmartConsole: Plain-text string (string length is up to 32 characters)Ĭontrols the name of UserCheck block page. "true" - ICAP Client also sends an HTTP response with content-type " text/html"."false" - ICAP Client does not send an HTTP response with content-type " text/html".
#C ICAP FULL#
If traffic matches a filter, full ICAP functionality is activated on that port.īest Practice - Add only applicable ports.Ĭontrols whether ICAP Client sends HTTP responses with content-type " text/html": ICAP filtering (HTTP methods) works on every port you define in this section. You must explicitly add every port, on which you transfer HTTP packets. This is in addition to the HTTP services that are defined by default in SmartConsole (such as: HTTP for TCP port 80 and HTTPS for TCP port 443). As a result, ICAP functionality is not activated on all HTTP requests.Ĭontrols on which port to process the HTTP packets. If this section is empty, there is no filter for HTTP requests. Some parameters accept only integer values. Some parameters accept only string values (notice the double-quotes). Each section contains the applicable parameters. The ICAP Client configuration file on Check Point Security Gateway ( $FWDIR/conf/icap_client_blade_configuration.C) contains a number of sections.