- CheckMates
- :
- Products
- :
- Quantum
- :
- Management
- :
- Re: ICAP Protocol
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
ICAP Protocol
Hi.
R80 support ICAP protocol?
- Tags:
- documentation
- install
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Can you define your specific requirements?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I have a client who needs to send the log to a Trustwave SIEM integration so this must be done through the ICAP protocol.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Generally ICAP is used to offload content analysis to another system. To send Check Point log messages to another system, one would generally use syslog or OpSec.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Does R80 support ICAP protocol as an ICAP client? I am looking at having a file analysis engine integrated with CheckPoint and would like to run an ICAP serve to receive the files.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
In read-only mode, yes: Check Point support for Internet Content Adaptation Protocol (ICAP) read-only client
If you want to modify content based on what the ICAP server says, this is not currently supported in R80.10.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I am using CheckPoint Security Gateway pay as you go service in AWS and I am not able to open the support solution. Can you shed some light on the configuration steps to do this? Much thanks.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
AWS PAYG includes standard support, which should allow access to that SK.
I recommend engaging with our Account Services team.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Dameon, just wondering if you can comment on sk111305. It appears that Internet Content Adaptation Protocol (ICAP) client with data modifications functionality can be added to Check Point R77.30 Security Gateway on Gaia OS.
This functionality would enable Check Point Security Gateway to interact with an ICAP server's response, to modify content and to block connections. We have a client that would like to do this (send ICAP to a DLP solution) and do not want to go to R80.10 yet. We still are getting mixed messages (it will work...it will not work) from Check Point.
Thanks
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
As it is not part of a mainstream release and is meant for specific environments, you will need to work with your local Check Point office.
They should be able to help you determine if the solution is suitable for your specific situation.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello Dameon, is icap client, on R80.20, read-write?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Yes.
Refer to: ICAP Client
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello Dameon, thank you for the information, another doubt: to use my cluster with a DLP 3rd Party I need to change my configuration to use my gateway as an HTTP proxy on transparent mode as a picture below ?
actual state
settings to use with external DLP
Is correct?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Don't believe this is required.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
ok, thank you Dameon, I will study that link.
