<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: sandblast icap on R80.20 in Endpoint</title>
    <link>https://community.checkpoint.com/t5/Endpoint/sandblast-icap-on-R80-20/m-p/63639#M3289</link>
    <description>&lt;P&gt;Hi &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/28088"&gt;@chico&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Use the&lt;SPAN&gt;&amp;nbsp;s&lt;/SPAN&gt;ervice URL&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;i&lt;SPAN&gt;&lt;STRONG&gt;cap://&amp;lt;ip-address of sandblast appliance&amp;gt;/sandblast&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;or&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt;icap://&amp;lt;ip-address of sandblast appliance&amp;gt;:1344/sandblast&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;BC&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 25 Sep 2019 10:15:49 GMT</pubDate>
    <dc:creator>Black_Cyborg</dc:creator>
    <dc:date>2019-09-25T10:15:49Z</dc:date>
    <item>
      <title>sandblast icap on R80.20</title>
      <link>https://community.checkpoint.com/t5/Endpoint/sandblast-icap-on-R80-20/m-p/63632#M3288</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I configured the ICAP server on checkpoint R80.20, we use a F5 BIG-IP as a client ICAP. I configured the icap_uri value as mentionend on the checkpoint documentation "/sandblast" but with this value I get the error log&lt;/P&gt;&lt;P&gt;"24/Sep/2019:17:12:58 +0200, ICAPserver ICAPclient REQMOD sanblast 404&lt;/P&gt;&lt;P&gt;After configured the icap_uri value "avscan" the scan work pretty well&lt;/P&gt;&lt;P&gt;24/Sep/2019:16:55:24 +0200, ICAPserver ICAPclient REQMOD avscan?allow204=on&amp;amp;sizelimit=off&amp;amp;mode=simple 200&lt;/P&gt;&lt;P&gt;Tue Sep 24 16:55:24 2019, 492/3921324944, VIRUS DETECTED: Unknown , http client ip: x.x.x.x, http user: -&lt;/P&gt;&lt;P&gt;So someone could tell me why the value "sanblast" seems doesn't work ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Sep 2019 07:50:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/sandblast-icap-on-R80-20/m-p/63632#M3288</guid>
      <dc:creator>chico</dc:creator>
      <dc:date>2019-09-25T07:50:59Z</dc:date>
    </item>
    <item>
      <title>Re: sandblast icap on R80.20</title>
      <link>https://community.checkpoint.com/t5/Endpoint/sandblast-icap-on-R80-20/m-p/63639#M3289</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/28088"&gt;@chico&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Use the&lt;SPAN&gt;&amp;nbsp;s&lt;/SPAN&gt;ervice URL&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;i&lt;SPAN&gt;&lt;STRONG&gt;cap://&amp;lt;ip-address of sandblast appliance&amp;gt;/sandblast&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;or&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt;icap://&amp;lt;ip-address of sandblast appliance&amp;gt;:1344/sandblast&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;BC&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Sep 2019 10:15:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/sandblast-icap-on-R80-20/m-p/63639#M3289</guid>
      <dc:creator>Black_Cyborg</dc:creator>
      <dc:date>2019-09-25T10:15:49Z</dc:date>
    </item>
    <item>
      <title>Re: sandblast icap on R80.20</title>
      <link>https://community.checkpoint.com/t5/Endpoint/sandblast-icap-on-R80-20/m-p/63640#M3290</link>
      <description>&lt;P&gt;Or look at this article from&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/21670"&gt;@HeikoAnkenbrand&lt;/a&gt;&amp;nbsp;:&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/SandBlast-Network/ICAP-and-Sandblast-Appliance/td-p/40640" target="_self"&gt;ICAP and Sandblast Appliance&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Sep 2019 10:19:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/sandblast-icap-on-R80-20/m-p/63640#M3290</guid>
      <dc:creator>Black_Cyborg</dc:creator>
      <dc:date>2019-09-25T10:19:19Z</dc:date>
    </item>
    <item>
      <title>Re: sandblast icap on R80.20</title>
      <link>https://community.checkpoint.com/t5/Endpoint/sandblast-icap-on-R80-20/m-p/63641#M3291</link>
      <description>&lt;P&gt;read here&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Sep 2019 10:32:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/sandblast-icap-on-R80-20/m-p/63641#M3291</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2019-09-25T10:32:55Z</dc:date>
    </item>
    <item>
      <title>Re: sandblast icap on R80.20</title>
      <link>https://community.checkpoint.com/t5/Endpoint/sandblast-icap-on-R80-20/m-p/63647#M3292</link>
      <description>&lt;P&gt;Do you have Threat Emulation blade enabled and working? It seems that you can't use sandblast at all. Be sure to have a threat policy that applies Threat Emulation to ICAP traffic.&lt;/P&gt;&lt;P&gt;I have done some integrations but only over the TE appliances with ICAP, there are no secrets but to enable ICAP on the appliance and checking if it's working:&lt;/P&gt;&lt;P&gt;In my case the URL to point is&amp;nbsp;icap://ip/sandblast&lt;/P&gt;&lt;P&gt;#icap_server start&lt;BR /&gt;#netstat -na | grep 1344&lt;BR /&gt;#ps ax | crep c-icap&lt;/P&gt;&lt;P&gt;Hope it helps,&lt;/P&gt;</description>
      <pubDate>Wed, 25 Sep 2019 12:18:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/sandblast-icap-on-R80-20/m-p/63647#M3292</guid>
      <dc:creator>FedericoMeiners</dc:creator>
      <dc:date>2019-09-25T12:18:29Z</dc:date>
    </item>
    <item>
      <title>Re: sandblast icap on R80.20</title>
      <link>https://community.checkpoint.com/t5/Endpoint/sandblast-icap-on-R80-20/m-p/63785#M3293</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for your reply, I made a mistake on the icap url...I wrote "sanblast" instead of "sandblast".&amp;nbsp;&lt;/P&gt;&lt;P&gt;But I don't understand how it's work...&lt;/P&gt;&lt;P&gt;I' m checking the checkpoint ICAP server on my lab and if I upload a eicar document, the checkpoint accept the eicar file.&lt;/P&gt;&lt;P&gt;I configured a ICAP profil ont the threat prevention layer with this options.&lt;/P&gt;&lt;P&gt;- If the threat emulation is activate ont the ICAP profil, the eicar test file is accept by checkpoint&lt;/P&gt;&lt;P&gt;-If I the threat emulation is not activate on the ICAP profil the eicar test document is prevent by the anti-virus blade&amp;nbsp; as shown as the attached picture.&lt;/P&gt;&lt;P&gt;I don't underand how it's works..&lt;/P&gt;&lt;P&gt;If someone can explain me the difference ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Miguel&lt;/P&gt;</description>
      <pubDate>Fri, 27 Sep 2019 09:40:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/sandblast-icap-on-R80-20/m-p/63785#M3293</guid>
      <dc:creator>chico</dc:creator>
      <dc:date>2019-09-27T09:40:56Z</dc:date>
    </item>
  </channel>
</rss>

