The Security Gateway as an ICAP Server
Check Point ICAP Server
The ICAP Server functionality in a Check Point Firewall that enables it to interact with an ICAP Client requests, send the files for inspection, and return the verdict. can work with multiple ICAP Clients.
Check Point ICAP Server supports the Threat Emulation
Software Blade on a Check Point Firewall that monitors the behavior of files in a sandbox to determine whether or not they are malicious. Acronym: TE., Anti-Virus
Software Blade on a Check Point Firewall that uses real-time virus signatures and anomaly-based protections from ThreatCloud to detect and block malware at the Check Point Firewall before users are affected. Acronym: AV. and Threat Extraction
Software Blade on a Check Point Firewall that removes malicious content from files. Acronym: TEX. blades.
To activate the ICAP Server on a Security Gateway object in SmartConsole
Check Point GUI application used to manage a Check Point environment - configure Security Policies, configure devices, monitor products and events, install updates, and so on., you must first enable Threat Emulation and/or Anti-Virus and/or Threat Extraction on that Security Gateway object.
If you enable ICAP Server on the Security Gateway and not enable the Threat Emulation Anti-Virus, or Threat Extraction blades, the ICAP Server runs but without inspection.
The ICAP Server operates according to the relevant settings defined for Threat Emulation, Threat Extraction and Anti-Virus in the selected Threat Prevention profile and engine settings.
If you enable the ICAP Server on a Check Point Cluster
Two or more Check Point Firewalls that work together in a redundant configuration - High Availability, or Load Sharing. object, You must configure your ICAP Clients to communicate with the applicable Virtual IP Address of the Check Point Cluster.
Limitations
-
ICAP Server supports Anti-Virus deep-scan, but does not support any additional functionality, such as MD5 hash, URL reputation, and signature-based protection.
-
ICAP Server functionality is not supported in ClusterXL Load Sharing mode.
-
Traditional VSX
Virtual System Extension. Check Point virtual networking solution, hosted on a computer or cluster with virtual abstractions of Check Point Firewalls and other network devices. These Virtual Devices provide the same functionality as their physical counterparts. does not support ICAP Server. -
Scalable Platforms do not support ICAP Server.
ICAP Server Actions
Check Point ICAP Server has 3 possible actions:
|
ICAP Action |
Description and Example |
|---|---|
|
Block |
For example: A Check Point UserCheck |
|
Continue / Not modified |
A default gateway or a proxy server can forward the HTTP Request / Response to its original destination. |
|
Flie modification |
Applicable when Threat Extraction is activated. The ICAP Server modifies the HTTP/HTTPS content and sends the modified content to the ICAP Client. |