Check Point Security Gateway

Prerequisites

This documentation is based on Check Point Security Gateway R81 and is the minimum configuration required to integrate Check Point and MetaDefender ICAP Server. For more information, please contact Check Point Support.

Integration Steps

  • Access the command line in Expert mode
  • Review and agree to the ICAP user-disclaimer
Command
Copy
  • Backup the default ICAP configuration file
Command
Copy
  • Configure the ICAP Client parameters in the configuration file
Command
Copy
  • Save the configuration
Command
Copy

Sample ICAP Client configuration file

The sample configuration provided below is for reference only and must be modified according to the network environment and ICAP funcitonality . The configuration will enable REQMOD with GET, PUT and POST methods for port 8080 and 8443 traffic. The variable src_ip_ranges has also been configured for network-level filtering. Please refer to the Check Point documentation for more information on the ICAP client configuration file.

Text
Copy

Additional Configuration

To include X-Headers in ICAP requests, you must enable Identity Awareness in the Check Point Security Gateway UI, General Properties, Network Security tab:

To enable inspection of SSL-encrypted traffic, import the SSL certificate using the Check Point Security Gateway UI: HTTPS Inspection.

Type to search, ESC to discard
Type to search, ESC to discard
Type to search, ESC to discard
  Last updated