<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Symantec (Bluecoat) SG ICAP and Sandblast (TEX) in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Symantec-Bluecoat-SG-ICAP-and-Sandblast-TEX/m-p/38025#M13962</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am getting an "unauthorized" message when clicking on the link &lt;A _jive_internal="true" class="" data-containerid="2057" data-containertype="14" data-objectid="2838" data-objecttype="102" href="https://community.checkpoint.com/docs/DOC-2838"&gt;https://community.checkpoint.com/docs/DOC-2838&lt;/A&gt; .&amp;nbsp; Is there another link available or a way to get access to this? &lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 06 Apr 2018 17:53:26 GMT</pubDate>
    <dc:creator>Bob_Delinsky</dc:creator>
    <dc:date>2018-04-06T17:53:26Z</dc:date>
    <item>
      <title>Symantec (Bluecoat) SG ICAP and Sandblast (TEX)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Symantec-Bluecoat-SG-ICAP-and-Sandblast-TEX/m-p/38004#M13941</link>
      <description>&lt;P&gt;&lt;STRONG&gt;ICAP integration for R77.30 and R80.10&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;IMG style="width: 236px; height: 251px;" class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/64084_pastedImage_1.png" border="0" /&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #993366; font-size: 22px;"&gt;&lt;STRONG&gt;&lt;SPAN style="text-align: left; text-transform: none; text-indent: 0px; letter-spacing: normal; font-family: Helvetica\ Neue, Helvetica, Arial, Lucida\ Grande, sans-serif; font-size: 20px; font-style: normal; font-variant: normal; text-decoration: none; word-spacing: 0px; display: inline !important; white-space: normal; float: none; -webkit-text-stroke-width: 0px; background-color: transparent;"&gt;Configuring ICAP Server&lt;/SPAN&gt; on Check Point Sandblast Appliance (TEX) or Gateway:&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif; font-size: 15px;"&gt;Enable ICAP server on TEX appliance see &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk111306&amp;amp;partition=Advanced&amp;amp;product=Security" target="_blank"&gt;SK&lt;/A&gt;&lt;SPAN style="text-align: left; color: #000000; text-transform: none; text-indent: 0px; letter-spacing: normal; font-style: normal; font-variant: normal; font-weight: 400; text-decoration: none; word-spacing: 0px; display: inline !important; white-space: normal; orphans: 2; float: none; -webkit-text-stroke-width: 0px; background-color: transparent;"&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk111306&amp;amp;partition=Advanced&amp;amp;product=Security" target="_blank"&gt;111306&lt;/A&gt; and configure thread rules in Smart DashBoard.&amp;nbsp;&lt;BR /&gt;Use hotfix 286 &lt;SPAN style="display: inline !important; float: none; background-color: transparent; color: #000000; font-family: arial,helvetica,sans-serif; font-size: 15px; font-style: normal; font-variant: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: left; text-decoration: none; text-indent: 0px; text-transform: none; -webkit-text-stroke-width: 0px; white-space: normal; word-spacing: 0px;"&gt;or higher&lt;/SPAN&gt; for R77.30.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="-webkit-text-stroke-width: 0px; color: #000000; white-space: normal; letter-spacing: normal; text-decoration: none; display: inline !important; font-size: 15px; font-style: normal; float: none; background-color: transparent; text-transform: none; word-spacing: 0px; font-variant: normal; text-indent: 0px; font-family: arial,helvetica,sans-serif; text-align: left;"&gt;&lt;STRONG&gt;Tip!&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="-webkit-text-stroke-width: 0px; color: #000000; white-space: normal; font-weight: 400; letter-spacing: normal; text-decoration: none; display: inline !important; font-size: 15px; font-style: normal; float: none; background-color: transparent; text-transform: none; word-spacing: 0px; font-variant: normal; text-indent: 0px; font-family: arial,helvetica,sans-serif; orphans: 2; text-align: left;"&gt;You can use more ICAP Server in "Web Content Layer" on Bluecoat SG for example CAS appliance and TEX appliance.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="min-height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="-webkit-text-stroke-width: 0px; color: #3366ff; white-space: normal; font-weight: bold; display: inline !important; letter-spacing: normal; text-decoration: none; font-size: 15px; font-style: normal; float: none; background-color: transparent; text-transform: none; word-spacing: 0px; font-variant: normal; text-indent: 0px; font-family: Helvetica Neue,Helvetica,Arial,Lucida Grande,sans-serif; orphans: 2; text-align: left;"&gt;&lt;SPAN style="display: inline !important; float: none; background-color: transparent; color: #3d3d3d; font-family: Helvetica Neue,Helvetica,Arial,Lucida Grande,sans-serif; font-size: 22px; font-style: normal; font-variant: normal; font-weight: bold; letter-spacing: normal; orphans: 2; text-align: left; text-decoration: none; text-indent: 0px; text-transform: none; -webkit-text-stroke-width: 0px; white-space: normal; word-spacing: 0px;"&gt;Enable ICAP Server&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="-webkit-text-stroke-width: 0px; color: #000000; white-space: normal; font-weight: 400; letter-spacing: normal; text-decoration: none; display: inline !important; font-size: 15px; font-style: normal; float: none; background-color: transparent; text-transform: none; word-spacing: 0px; font-variant: normal; text-indent: 0px; font-family: arial,helvetica,sans-serif; orphans: 2; text-align: left;"&gt;&lt;SPAN style="text-align: left; color: #000000; text-transform: none; text-indent: 0px; letter-spacing: normal; font-variant: normal; text-decoration: none; word-spacing: 0px; display: inline !important; white-space: normal; orphans: 2; float: none; -webkit-text-stroke-width: 0px; background-color: transparent;"&gt;Start ICAP server on TEX appliance or gateway:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="-webkit-text-stroke-width: 0px; color: #000000; white-space: normal; font-weight: 400; letter-spacing: normal; text-decoration: none; display: inline !important; font-size: 15px; font-style: normal; float: none; background-color: transparent; text-transform: none; word-spacing: 0px; font-variant: normal; text-indent: 0px; font-family: arial,helvetica,sans-serif; orphans: 2; text-align: left;"&gt;&lt;SPAN style="text-align: left; color: #000000; text-transform: none; text-indent: 0px; letter-spacing: normal; font-variant: normal; text-decoration: none; word-spacing: 0px; display: inline !important; white-space: normal; orphans: 2; float: none; -webkit-text-stroke-width: 0px; background-color: transparent;"&gt;# &lt;STRONG&gt;icap_server start&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="-webkit-text-stroke-width: 0px; color: #000000; white-space: normal; font-weight: 400; letter-spacing: normal; text-decoration: none; display: inline !important; font-size: 22px; font-style: normal; float: none; background-color: transparent; text-transform: none; word-spacing: 0px; font-variant: normal; text-indent: 0px; font-family: arial, helvetica, sans-serif; text-align: left;"&gt;&lt;SPAN style="text-align: left; color: #000000; text-transform: none; text-indent: 0px; letter-spacing: normal; font-variant: normal; text-decoration: none; word-spacing: 0px; display: inline !important; white-space: normal; float: none; -webkit-text-stroke-width: 0px; background-color: transparent;"&gt;&lt;STRONG&gt;Enable ICAP Logs&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="-webkit-text-stroke-width: 0px; color: #000000; white-space: normal; font-weight: 400; letter-spacing: normal; text-decoration: none; display: inline !important; font-size: 15px; font-style: normal; float: none; background-color: transparent; text-transform: none; word-spacing: 0px; font-variant: normal; text-indent: 0px; font-family: arial,helvetica,sans-serif; orphans: 2; text-align: left;"&gt;# &lt;STRONG&gt;tecli advanced remote emulator logs enable&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/STRONG&gt; &amp;lt;&amp;lt;&amp;lt; Hotfix 286 or higher automatically activates logging. &lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="-webkit-text-stroke-width: 0px; color: #000000; white-space: normal; font-weight: 400; letter-spacing: normal; text-decoration: none; display: inline !important; font-size: 15px; font-style: normal; float: none; background-color: transparent; text-transform: none; word-spacing: 0px; font-variant: normal; text-indent: 0px; font-family: arial,helvetica,sans-serif; orphans: 2; text-align: left;"&gt;&lt;SPAN style="-webkit-text-stroke-width: 0px; color: #000000; white-space: normal; letter-spacing: normal; text-decoration: none; display: inline !important; font-size: 22px; float: none; background-color: transparent; text-transform: none; word-spacing: 0px; font-variant: normal; text-indent: 0px; orphans: 2; text-align: left;"&gt;&lt;STRONG&gt;Enable firewall rule to connect ICAP Server (TEX Appliance)&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 15px;"&gt;Source: Symantec SG&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 15px;"&gt;Destination: "&lt;SPAN style="color: #3366ff;"&gt;&lt;STRONG&gt;ip-address of sandblast appliance&lt;/STRONG&gt;&lt;/SPAN&gt;"&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 15px;"&gt;Port:&amp;nbsp;&lt;SPAN style="display: inline !important; float: none; background-color: transparent; color: #3366ff; font-family: Helvetica Neue,Helvetica,Arial,Lucida Grande,sans-serif; font-size: 15px; font-style: normal; font-variant: normal; font-weight: bold; letter-spacing: normal; orphans: 2; text-align: left; text-decoration: none; text-indent: 0px; text-transform: none; -webkit-text-stroke-width: 0px; white-space: normal; word-spacing: 0px;"&gt;1344&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="-webkit-text-stroke-width: 0px; color: #3366ff; white-space: normal; font-weight: bold; display: inline !important; letter-spacing: normal; text-decoration: none; font-size: 15px; font-style: normal; float: none; background-color: transparent; text-transform: none; word-spacing: 0px; font-variant: normal; text-indent: 0px; font-family: Helvetica Neue,Helvetica,Arial,Lucida Grande,sans-serif; orphans: 2; text-align: left;"&gt;&lt;SPAN style="-webkit-text-stroke-width: 0px; color: #000000; white-space: normal; font-weight: 400; letter-spacing: normal; text-decoration: none; display: inline !important; font-size: 15px; font-style: normal; float: none; background-color: transparent; text-transform: none; word-spacing: 0px; font-variant: normal; text-indent: 0px; font-family: arial,helvetica,sans-serif; orphans: 2; text-align: left;"&gt;&lt;SPAN style="-webkit-text-stroke-width: 0px; color: #000000; white-space: normal; letter-spacing: normal; text-decoration: none; display: inline !important; font-size: 22px; float: none; background-color: transparent; text-transform: none; word-spacing: 0px; font-variant: normal; text-indent: 0px; orphans: 2; text-align: left;"&gt;&lt;STRONG&gt;Configure Thread Rules&lt;BR /&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="display: inline !important; float: none; background-color: transparent; color: #3366ff; font-family: Helvetica\ Neue, Helvetica, Arial, Lucida\ Grande, sans-serif; font-style: normal; font-variant: normal; letter-spacing: normal; text-align: left; text-decoration: none; text-indent: 0px; text-transform: none; -webkit-text-stroke-width: 0px; white-space: normal; word-spacing: 0px;"&gt;&lt;SPAN style="-webkit-text-stroke-width: 0px; color: #000000; white-space: normal; font-weight: 400; letter-spacing: normal; text-decoration: none; display: inline !important; font-style: normal; float: none; background-color: transparent; text-transform: none; word-spacing: 0px; font-variant: normal; text-indent: 0px; font-family: arial, helvetica, sans-serif; text-align: left;"&gt;&lt;SPAN style="text-align: left; color: #000000; text-transform: none; text-indent: 0px; letter-spacing: normal; font-variant: normal; text-decoration: none; word-spacing: 0px; display: inline !important; white-space: normal; orphans: 2; float: none; -webkit-text-stroke-width: 0px; background-color: transparent;"&gt;Configure Thread rules in SmartDashboard&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H2&gt;&lt;SPAN style="color: #ffffff;"&gt;.&lt;/SPAN&gt;&lt;/H2&gt;
&lt;P&gt;&lt;SPAN style="-webkit-text-stroke-width: 0px; color: #993366; white-space: normal; letter-spacing: normal; text-decoration: none; display: inline !important; font-size: 20px; font-style: normal; float: none; background-color: transparent; text-transform: none; word-spacing: 0px; font-variant: normal; text-indent: 0px; font-family: Helvetica\ Neue, Helvetica, Arial, Lucida\ Grande, sans-serif; text-align: left;"&gt;&lt;STRONG&gt;Configuring ICAP on Symantec SWG:&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H3&gt;&lt;SPAN style="font-size: 22px;"&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ICAP Servers Request&lt;BR /&gt;&lt;/SPAN&gt;&lt;/H3&gt;
&lt;OL&gt;
&lt;LI&gt;Go to &lt;STRONG&gt;&lt;SPAN&gt;Configuration&amp;nbsp; &amp;gt; content Analysis &amp;gt; ICAP&lt;/SPAN&gt;&lt;/STRONG&gt; and click on &lt;STRONG&gt;New&lt;/STRONG&gt;.&lt;/LI&gt;
&lt;LI&gt;Enter a &lt;STRONG&gt;Name "&lt;SPAN style="color: #339966;"&gt;sandblast_server&lt;/SPAN&gt;"&lt;/STRONG&gt; for the server.&lt;BR /&gt;&lt;IMG style="width: auto; height: auto;" class="image-12 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/64099_pastedImage_12.png" border="0" /&gt;&lt;/LI&gt;
&lt;LI&gt;Go to &lt;STRONG&gt;&lt;SPAN&gt;Configuration&amp;nbsp; &amp;gt; content Analysis &amp;gt; ICAP&lt;/SPAN&gt;&lt;/STRONG&gt; and click on &lt;STRONG&gt;Edit "&lt;SPAN style="color: #339966;"&gt;sandblast_server&lt;/SPAN&gt;"&lt;BR /&gt;&lt;IMG style="width: auto; height: auto;" class="image-9 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/64096_pastedImage_9.png" border="0" /&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;Enter the &lt;STRONG&gt;Service URL&amp;nbsp;&lt;/STRONG&gt; “&lt;SPAN style="color: #3366ff;"&gt;&lt;STRONG&gt;icap://ip-address of sandblast appliance/sandblast&lt;/STRONG&gt;&lt;/SPAN&gt;”&lt;/LI&gt;
&lt;LI&gt;Set the &lt;STRONG&gt;Maximum nummber of connection: &lt;SPAN style="color: #3366ff;"&gt;100&lt;/SPAN&gt;&lt;/STRONG&gt; &lt;SPAN style="color: #000000;"&gt;&amp;lt;&amp;lt;&amp;lt; You can configure this on sandblast appliance in config files. Set the same value. If you overstay the value you become an ICAP error!&lt;/SPAN&gt;&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN style="color: #000000;"&gt;Set &lt;STRONG&gt;Method supported:&lt;/STRONG&gt; &lt;SPAN style="color: #3366ff;"&gt;&lt;STRONG&gt;&lt;SPAN style="color: #ff0000;"&gt;request&lt;/SPAN&gt; modification&lt;/STRONG&gt; &lt;SPAN style="color: #000000;"&gt;&amp;lt;&amp;lt;&amp;lt; Use request mod.&lt;/SPAN&gt;&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN style="color: #000000;"&gt;Set &lt;STRONG&gt;Send: &lt;SPAN style="color: #3366ff;"&gt;Client address/ Server address/ Auth user&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 22px;"&gt;&lt;STRONG&gt;ICAP Servers Response&lt;/STRONG&gt;&lt;BR /&gt;&lt;/SPAN&gt;
&lt;OL&gt;
&lt;LI&gt;Go to &lt;STRONG&gt;&lt;SPAN&gt;Configuration&amp;nbsp; &amp;gt; content Analysis &amp;gt; ICAP&lt;/SPAN&gt;&lt;/STRONG&gt; and click on &lt;STRONG&gt;New&lt;/STRONG&gt;.&lt;/LI&gt;
&lt;LI&gt;Enter a &lt;STRONG&gt;Name "&lt;SPAN style="color: #ff00ff;"&gt;sandblast_server_response&lt;/SPAN&gt;"&lt;/STRONG&gt; for the server.&lt;BR /&gt;&lt;IMG style="width: auto; height: auto;" class="image-13 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/64100_pastedImage_13.png" border="0" /&gt;&lt;/LI&gt;
&lt;LI&gt;Go to &lt;STRONG&gt;&lt;SPAN&gt;Configuration&amp;nbsp; &amp;gt; content Analysis &amp;gt; ICAP&lt;/SPAN&gt;&lt;/STRONG&gt; and click on &lt;STRONG&gt;Edit "&lt;SPAN style="color: #ff00ff;"&gt;sandblast_server_response&lt;/SPAN&gt;"&lt;BR /&gt;&lt;IMG style="width: auto; height: auto;" class="jive-image image-10" src="https://community.checkpoint.com/legacyfs/online/checkpoint/64097_pastedImage_10.png" border="0" /&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;Enter the &lt;STRONG&gt;Service URL&amp;nbsp;&lt;/STRONG&gt; “&lt;SPAN style="color: #3366ff;"&gt;&lt;STRONG&gt;icap://ip-address of sandblast appliance/sandblast&lt;/STRONG&gt;&lt;/SPAN&gt;”&lt;/LI&gt;
&lt;LI&gt;Set the &lt;STRONG&gt;Maximum nummber of connection: &lt;SPAN style="color: #3366ff;"&gt;100&lt;/SPAN&gt;&lt;/STRONG&gt; &lt;SPAN style="color: #000000;"&gt;&amp;lt;&amp;lt;&amp;lt; You can configure this on sandblast appliance in config files. Set the same value. If you overstay the value you become an ICAP error!&lt;/SPAN&gt;&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN style="color: #000000;"&gt;Set &lt;STRONG&gt;Method supported:&lt;/STRONG&gt; &lt;SPAN style="color: #3366ff;"&gt;&lt;STRONG&gt;&lt;SPAN style="color: #ff0000;"&gt;response&lt;/SPAN&gt; modification&lt;/STRONG&gt; &lt;SPAN style="color: #000000;"&gt;&amp;lt;&amp;lt;&amp;lt; Use request mod.&lt;/SPAN&gt;&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN style="color: #000000;"&gt;Set &lt;STRONG&gt;Send: &lt;SPAN style="color: #3366ff;"&gt;Client address/ Server address/ Auth user&lt;BR /&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN style="color: #3366ff; font-size: 22px;"&gt;&lt;STRONG&gt;&lt;BR /&gt;&lt;SPAN style="color: #000000;"&gt;ICAP Servers Response&lt;/SPAN&gt; &lt;SPAN style="color: #000000;"&gt;Analysis&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;/SPAN&gt;
&lt;OL&gt;
&lt;LI&gt;Go to &lt;STRONG&gt;&lt;SPAN&gt;Configuration&amp;nbsp; &amp;gt; Policy &amp;gt; Visual Policy Manager&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Add &lt;STRONG&gt;Web Content Layer&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;&lt;STRONG&gt;Enter the new &amp;gt; Performe Response Analysis&lt;BR /&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;STRONG&gt;&lt;IMG class="image-6 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/64089_pastedImage_37.png" border="0" /&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Add Available Service:&lt;SPAN style="color: #ff00ff;"&gt;&lt;STRONG&gt;sandblast_server_response&lt;/STRONG&gt;&lt;/SPAN&gt; &amp;lt;&amp;lt;&amp;lt; Response Service&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;&lt;STRONG&gt;Enter the new &amp;gt; Performe Request Analysis&lt;BR /&gt;&lt;IMG style="width: auto; height: auto;" class="image-11 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/64098_pastedImage_11.png" border="0" /&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Add Available Service:&lt;SPAN style="color: #339966;"&gt;&lt;STRONG&gt;sandblast_server&lt;/STRONG&gt;&lt;/SPAN&gt; &amp;lt;&amp;lt;&amp;lt; Request Service&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;See Web Conten Layer Rule&lt;STRONG&gt;&lt;BR /&gt;&lt;IMG style="width: auto; height: auto;" class="jive-image image-8" src="https://community.checkpoint.com/legacyfs/online/checkpoint/64092_pastedImage_41.png" border="0" /&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;SPAN style="color: #3366ff; font-size: 22px;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;&lt;A class="" href="https://community.checkpoint.com/people/h.ank2614aef2-c5d1-3f73-bbbd-45c59b9e2728" data-objecttype="3" target="_blank"&gt;Heiko&lt;/A&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;/LI&gt;
&lt;/OL&gt;</description>
      <pubDate>Wed, 20 Mar 2019 20:14:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Symantec-Bluecoat-SG-ICAP-and-Sandblast-TEX/m-p/38004#M13941</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2019-03-20T20:14:22Z</dc:date>
    </item>
    <item>
      <title>Re: Symantec (Bluecoat) SG ICAP and Sandblast (TEX)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Symantec-Bluecoat-SG-ICAP-and-Sandblast-TEX/m-p/38005#M13942</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Nice!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is this also possible with F5? &lt;BR /&gt;Do you have a documentation for F5?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Mar 2018 12:32:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Symantec-Bluecoat-SG-ICAP-and-Sandblast-TEX/m-p/38005#M13942</guid>
      <dc:creator>Alice_Shields</dc:creator>
      <dc:date>2018-03-26T12:32:04Z</dc:date>
    </item>
    <item>
      <title>Re: Symantec (Bluecoat) SG ICAP and Sandblast (TEX)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Symantec-Bluecoat-SG-ICAP-and-Sandblast-TEX/m-p/38006#M13943</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;DIV&gt;Hi Heiko,&lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;Do I need to add two services?&lt;BR /&gt;- Response Service&lt;BR /&gt;- Request Service&lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;Or is it also possible to use only the "Request Service".&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Mar 2018 12:42:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Symantec-Bluecoat-SG-ICAP-and-Sandblast-TEX/m-p/38006#M13943</guid>
      <dc:creator>Jill_Sanders</dc:creator>
      <dc:date>2018-03-26T12:42:38Z</dc:date>
    </item>
    <item>
      <title>Re: Symantec (Bluecoat) SG ICAP and Sandblast (TEX)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Symantec-Bluecoat-SG-ICAP-and-Sandblast-TEX/m-p/38007#M13944</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Comming soon!&lt;/P&gt;&lt;P&gt;I am currently writing a documentation for Trustwave SWG and F5 LTM. The F5 ICAP configuration is a bit more complex. Therefore, this will be a longer article. But it works without any problems. Further information can be found at F5 under the following link:&amp;nbsp; &lt;A href="https://support.f5.com/kb/en-us/products/big-ip_ltm/manuals/product/ltm-implementations-11-3-0/12.html"&gt;Configuring Content Adaptation for HTTP Requests&lt;/A&gt;.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Mar 2018 12:55:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Symantec-Bluecoat-SG-ICAP-and-Sandblast-TEX/m-p/38007#M13944</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2018-03-26T12:55:07Z</dc:date>
    </item>
    <item>
      <title>Re: Symantec (Bluecoat) SG ICAP and Sandblast (TEX)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Symantec-Bluecoat-SG-ICAP-and-Sandblast-TEX/m-p/38008#M13945</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think Response mode makes more sense, because the Sandblast Appliance can check the documents (DOC, PDF,...).&lt;/P&gt;&lt;P&gt;But in principle this also works.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" class="" data-containerid="-1" data-containertype="-1" data-objectid="55229" data-objecttype="3" href="https://community.checkpoint.com/people/h.ank2614aef2-c5d1-3f73-bbbd-45c59b9e2728"&gt;Heiko&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Mar 2018 12:57:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Symantec-Bluecoat-SG-ICAP-and-Sandblast-TEX/m-p/38008#M13945</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2018-03-26T12:57:23Z</dc:date>
    </item>
    <item>
      <title>Re: Symantec (Bluecoat) SG ICAP and Sandblast (TEX)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Symantec-Bluecoat-SG-ICAP-and-Sandblast-TEX/m-p/38009#M13946</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you publish this for F5?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you publish this for F5?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advanced!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Pablo&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Mar 2018 18:17:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Symantec-Bluecoat-SG-ICAP-and-Sandblast-TEX/m-p/38009#M13946</guid>
      <dc:creator>Pablo_Montega</dc:creator>
      <dc:date>2018-03-26T18:17:10Z</dc:date>
    </item>
    <item>
      <title>Re: Symantec (Bluecoat) SG ICAP and Sandblast (TEX)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Symantec-Bluecoat-SG-ICAP-and-Sandblast-TEX/m-p/38010#M13947</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I will publish this in the next days.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Mar 2018 18:29:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Symantec-Bluecoat-SG-ICAP-and-Sandblast-TEX/m-p/38010#M13947</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2018-03-26T18:29:13Z</dc:date>
    </item>
    <item>
      <title>Re: Symantec (Bluecoat) SG ICAP and Sandblast (TEX)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Symantec-Bluecoat-SG-ICAP-and-Sandblast-TEX/m-p/38011#M13948</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is there a documentation for other manufacturers?&lt;/P&gt;&lt;P&gt;E. g. Ironport, Squit, ...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Mar 2018 18:46:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Symantec-Bluecoat-SG-ICAP-and-Sandblast-TEX/m-p/38011#M13948</guid>
      <dc:creator>Dr__Chris_Murph</dc:creator>
      <dc:date>2018-03-26T18:46:39Z</dc:date>
    </item>
    <item>
      <title>Re: Symantec (Bluecoat) SG ICAP and Sandblast (TEX)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Symantec-Bluecoat-SG-ICAP-and-Sandblast-TEX/m-p/38012#M13949</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I Chris,&amp;nbsp;Thomas Werner from Check Point has a very nice POC implementation guide with many examples for ICAP integration.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Mar 2018 19:07:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Symantec-Bluecoat-SG-ICAP-and-Sandblast-TEX/m-p/38012#M13949</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2018-03-26T19:07:33Z</dc:date>
    </item>
    <item>
      <title>Re: Symantec (Bluecoat) SG ICAP and Sandblast (TEX)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Symantec-Bluecoat-SG-ICAP-and-Sandblast-TEX/m-p/38013#M13950</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is it possible to user more Symantec SG „Web Content Layer“&amp;nbsp;one for the CAS appliance and one for sandblast appliance?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Mar 2018 19:29:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Symantec-Bluecoat-SG-ICAP-and-Sandblast-TEX/m-p/38013#M13950</guid>
      <dc:creator>Ulf_Wegner</dc:creator>
      <dc:date>2018-03-26T19:29:53Z</dc:date>
    </item>
    <item>
      <title>Re: Symantec (Bluecoat) SG ICAP and Sandblast (TEX)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Symantec-Bluecoat-SG-ICAP-and-Sandblast-TEX/m-p/38014#M13951</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, it is possible to use several ICAP services in one "web content layer". I think we should discuss this in a Symantec forum.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Mar 2018 20:30:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Symantec-Bluecoat-SG-ICAP-and-Sandblast-TEX/m-p/38014#M13951</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2018-03-26T20:30:54Z</dc:date>
    </item>
    <item>
      <title>Re: Symantec (Bluecoat) SG ICAP and Sandblast (TEX)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Symantec-Bluecoat-SG-ICAP-and-Sandblast-TEX/m-p/38015#M13952</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is it possible to use one layer or do I need two layers "web content layer" and " web access layer"?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Mar 2018 11:55:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Symantec-Bluecoat-SG-ICAP-and-Sandblast-TEX/m-p/38015#M13952</guid>
      <dc:creator>Armin_Weiler</dc:creator>
      <dc:date>2018-03-27T11:55:18Z</dc:date>
    </item>
    <item>
      <title>Re: Symantec (Bluecoat) SG ICAP and Sandblast (TEX)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Symantec-Bluecoat-SG-ICAP-and-Sandblast-TEX/m-p/38016#M13953</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think you need two layers - the web access layer will allow your connections and the content layer is responsible for the ICAP req/resp modifications. I'm not sure if you can combine actions from access and content layers (It's been a while since I've used a Proxy SG).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Mar 2018 13:55:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Symantec-Bluecoat-SG-ICAP-and-Sandblast-TEX/m-p/38016#M13953</guid>
      <dc:creator>StuartGreen</dc:creator>
      <dc:date>2018-03-27T13:55:40Z</dc:date>
    </item>
    <item>
      <title>Re: Symantec (Bluecoat) SG ICAP and Sandblast (TEX)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Symantec-Bluecoat-SG-ICAP-and-Sandblast-TEX/m-p/38017#M13954</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US" style="color: #1f497d; mso-ansi-language: EN-US;"&gt;This is really great info. We also look for the same kind of solution for our McAfee customers, where for example the TIE server sends files for emulation to TEX, based on the ThreatPrevention API for example. &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US" style="color: #1f497d; mso-ansi-language: EN-US;"&gt;Did you, or anyone else try to build something like this ? &lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Mar 2018 14:42:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Symantec-Bluecoat-SG-ICAP-and-Sandblast-TEX/m-p/38017#M13954</guid>
      <dc:creator>Jeroen_Vreugden</dc:creator>
      <dc:date>2018-03-27T14:42:17Z</dc:date>
    </item>
    <item>
      <title>Re: Symantec (Bluecoat) SG ICAP and Sandblast (TEX)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Symantec-Bluecoat-SG-ICAP-and-Sandblast-TEX/m-p/38018#M13955</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Heiko,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;this is not needed anymore:&lt;/P&gt;&lt;P style="color: #333333; background-color: #ffffff; border: 0px;"&gt;&lt;SPAN style="color: #000000; background-color: transparent; border: 0px; text-decoration: none; font-size: 22px;"&gt;&lt;SPAN style="color: #000000; background-color: transparent; border: 0px; font-weight: inherit; text-decoration: none; font-size: 22px;"&gt;&lt;STRONG style="border: 0px; font-weight: bold; font-size: 22px;"&gt;Enable ICAP Logs&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="color: #333333; background-color: #ffffff; border: 0px;"&gt;&lt;SPAN style="color: #000000; background-color: transparent; border: 0px; text-decoration: none;"&gt;#&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG style="border: 0px; font-weight: bold;"&gt;tecli advanced remote emulator logs enable&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="color: #333333; background-color: #ffffff; border: 0px;"&gt;&lt;/P&gt;&lt;P style="color: #333333; background-color: #ffffff; border: 0px;"&gt;&lt;SPAN style="color: #000000; background-color: transparent; border: 0px; text-decoration: none;"&gt;The included ICAP server (since JHF286) will create logs automatically.&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="color: #333333; background-color: #ffffff; border: 0px;"&gt;&lt;/P&gt;&lt;P style="color: #333333; background-color: #ffffff; border: 0px;"&gt;&lt;SPAN style="color: #000000; background-color: transparent; border: 0px; text-decoration: none;"&gt;Regards Thomas&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Mar 2018 16:30:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Symantec-Bluecoat-SG-ICAP-and-Sandblast-TEX/m-p/38018#M13955</guid>
      <dc:creator>Thomas_Werner</dc:creator>
      <dc:date>2018-03-27T16:30:00Z</dc:date>
    </item>
    <item>
      <title>Re: Symantec (Bluecoat) SG ICAP and Sandblast (TEX)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Symantec-Bluecoat-SG-ICAP-and-Sandblast-TEX/m-p/38019#M13956</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;THX Thomas&lt;/P&gt;&lt;P&gt;I'll change that tomorrow.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" class="" data-containerid="-1" data-containertype="-1" data-objectid="55229" data-objecttype="3" href="https://community.checkpoint.com/people/h.ank2614aef2-c5d1-3f73-bbbd-45c59b9e2728"&gt;Heiko&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Mar 2018 16:37:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Symantec-Bluecoat-SG-ICAP-and-Sandblast-TEX/m-p/38019#M13956</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2018-03-27T16:37:43Z</dc:date>
    </item>
    <item>
      <title>Re: Symantec (Bluecoat) SG ICAP and Sandblast (TEX)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Symantec-Bluecoat-SG-ICAP-and-Sandblast-TEX/m-p/38020#M13957</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jeroen,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;it is possible with McAfee WebGateway.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I already installed it at a customer environment.&lt;/P&gt;&lt;P&gt;Maybe Thomas Werner from Check Point can send you the POC Guide. He described the integration of the McAfee SWG here.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Heiko&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Mar 2018 18:49:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Symantec-Bluecoat-SG-ICAP-and-Sandblast-TEX/m-p/38020#M13957</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2018-03-27T18:49:35Z</dc:date>
    </item>
    <item>
      <title>Re: Symantec (Bluecoat) SG ICAP and Sandblast (TEX)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Symantec-Bluecoat-SG-ICAP-and-Sandblast-TEX/m-p/38021#M13958</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It is possible! You can combine actions from access and content layers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;gt; web access layer for ICAP requests&lt;/P&gt;&lt;P&gt;&amp;gt; web content layer for ICAP response&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Heiko&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Mar 2018 19:07:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Symantec-Bluecoat-SG-ICAP-and-Sandblast-TEX/m-p/38021#M13958</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2018-03-27T19:07:00Z</dc:date>
    </item>
    <item>
      <title>Re: Symantec (Bluecoat) SG ICAP and Sandblast (TEX)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Symantec-Bluecoat-SG-ICAP-and-Sandblast-TEX/m-p/38022#M13959</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So I followed Heikos initiative and posted a sample config for McAfee Web Gateway&amp;nbsp;&lt;A href="https://community.checkpoint.com/docs/DOC-2814-mcafee-web-gateway-icap-and-sandblast-appliance-tex" target="_blank"&gt;https://community.checkpoint.com/docs/DOC-2814-mcafee-web-gateway-icap-and-sandblast-appliance-tex&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards Thomas&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Jun 2019 09:22:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Symantec-Bluecoat-SG-ICAP-and-Sandblast-TEX/m-p/38022#M13959</guid>
      <dc:creator>Thomas_Werner</dc:creator>
      <dc:date>2019-06-21T09:22:47Z</dc:date>
    </item>
    <item>
      <title>Re: Symantec (Bluecoat) SG ICAP and Sandblast (TEX)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Symantec-Bluecoat-SG-ICAP-and-Sandblast-TEX/m-p/38023#M13960</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jeroen,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;without deeper knowledge of the McAfee TIE Server it looks like TIE2ATD integration is proprietary, so there is no way to leverage our API here:&lt;/P&gt;&lt;P&gt;&lt;A class="link-titled" href="https://community.mcafee.com/t5/Documents/How-to-integrate-McAfee-Threat-Intelligence-Exchange-with-McAfee/ta-p/552799" title="https://community.mcafee.com/t5/Documents/How-to-integrate-McAfee-Threat-Intelligence-Exchange-with-McAfee/ta-p/552799" rel="nofollow noopener noreferrer" target="_blank"&gt;McAfee Support Community - How to integrate McAfee Threat Intelligence Exchan... - McAfee Support Community&lt;/A&gt;&amp;nbsp;&amp;nbsp;(check Video at 3:30)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But you can attach our Sandbox to McAfee Web Gateway and also within your mail flow via MTA. Here is the MWG ICAP config:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;A href="https://community.checkpoint.com/docs/DOC-2814-mcafee-web-gateway-icap-and-sandblast-appliance-tex" target="_blank"&gt;https://community.checkpoint.com/docs/DOC-2814-mcafee-web-gateway-icap-and-sandblast-appliance-tex&lt;/A&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Afterwards you can share our Threat Intelligence via our McAfee DXL integration:&lt;/P&gt;&lt;P&gt;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk116678" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk116678" rel="nofollow noopener noreferrer" target="_blank"&gt;LEA/DXL Connector for McAfee ePO Integration&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards Thomas&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Jun 2019 09:22:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Symantec-Bluecoat-SG-ICAP-and-Sandblast-TEX/m-p/38023#M13960</guid>
      <dc:creator>Thomas_Werner</dc:creator>
      <dc:date>2019-06-21T09:22:50Z</dc:date>
    </item>
  </channel>
</rss>

