IBM Verify

IBM Verify

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  ICAP sandblast mode

    Posted Tue September 03, 2024 03:46 PM

    Hi,

    I am looking for some help in configuring checkpoint AV server as ICAP in ISAM. I have configured the server but having issue with sending the request. I was told to use sandblast instead of echo while sending the request to icap server. I have checked the ISAM proxy file but couldn't find anything related to this.

    Could anyone guide me if ISAM does have sandblast or echo mode in sending the request for scanning

    Thanks,

    Mahi



    ------------------------------
    Mahi
    ------------------------------


  • 2.  RE: ICAP sandblast mode

    Posted Tue September 03, 2024 04:11 PM

    Mahi,

     

    ICAP is a protocol which is used to pass a HTTP request or response onto an ICAP enabled server for examination, and perhaps modification. 

     

    'sandblast' is not a part of the ICAP protocol, and appears to be an ICAP enabled server from checkpoint – which has nothing to do with ISVA/WebSEAL.  I believe that the person who told you to use 'sandblast' instead of 'echo' is confused, or you have misinterpreted what they were asking.

     

    I hope that this helps.

     

    Scott A. Exton
    Senior Software Engineer
    Chief Programmer - IBM Security Verify Access

    IBM Master Inventor

    cid4122760825*<a href=image002.png@01D85F83.85516C50">

     

     






  • 3.  RE: ICAP sandblast mode

    Posted Thu September 12, 2024 12:46 PM
    Edited by Mahi Thu September 12, 2024 12:47 PM

    Thanks Scott.

    I believe, ICAP doesn't have any URL restriction. So I have added /sandblast at the end of ICAP server which fix the issue.

    Thanks,

    Mahi



    ------------------------------
    Mahi
    ------------------------------