Fortinet white logo
Fortinet white logo

CLI Reference

config icap local-server

config icap local-server

Configure ICAP local server.

config icap local-server
    Description: Configure ICAP local server.
    edit <icap-server-id>
        set status [disable|enable]
        set secure-connection [disable|enable]
        set status-ipv6 [disable|enable]
        set icap-incoming-port {integer}
        set icap-incoming-ssl-port {integer}
        set interface {string}
        set incoming-ip {ipv4-address-any}
        set incoming-ipv6 {ipv6-address}
        set ssl-cert <name1>, <name2>, ...
        set strict-scheme-check [disable|enable]
        set message-preview [disable|enable]
        set srcaddr {string}
        set timeout {integer}
        config icap-service
            Description: Set up services for local ICAP server.
            edit <service-id>
                set name {string}
                set dlp-profile {string}
                set av-profile {string}
                set webfilter-profile {string}
                set image-analyzer-profile {string}
                set profile-protocol-options {string}
                set extension-headers {option1}, {option2}, ...
            next
        end
    next
end

config icap local-server

Parameter

Description

Type

Size

Default

icap-server-id

ICAP local server id.

integer

Minimum value: 0 Maximum value: 65535

0

status

Enable/disable status for icap server network profile.

option

-

enable

Option

Description

disable

Disable the status for ipv4 in network-profile.

enable

Enable the status for ipv4 in network-profile.

secure-connection

Enable/disable status for secured icap server network profile.

option

-

disable

Option

Description

disable

Disable the status for ipv4 ssl in network-profile.

enable

Enable the status for ipv4 ssl in network-profile.

status-ipv6

Enable/disable status for icap server service ipv6.

option

-

disable

Option

Description

disable

Disable the status for ipv6 in network-profile.

enable

Enable the status for ipv6 in network-profile.

icap-incoming-port

Accept incoming ICAP requests on a port.

integer

Minimum value: 1 Maximum value: 65535

1344

icap-incoming-ssl-port

Accept incoming secured ICAP requests on a port.

integer

Minimum value: 1 Maximum value: 65535

11344

interface

Interface name

string

Maximum length: 15

incoming-ip

Restrict the ICAP server to only accept sessions from this IP address. An interface must have this IP address.

ipv4-address-any

Not Specified

0.0.0.0

incoming-ipv6

Restrict the ICAP server to only accept sessions from this IPv6 address. An interface must have this IPv6 address.

ipv6-address

Not Specified

::

ssl-cert <name>

SSL certificate for SSL interception.

Certificate list.

string

Maximum length: 79

strict-scheme-check

Enable/disable strict check of scheme.

option

-

enable

Option

Description

disable

Disable strict check of scheme.

enable

Enable strict check of scheme.

message-preview

Enable/disable message preview support. Max preview data length is 4096 bytes.

option

-

enable

Option

Description

disable

Disable message preview support.

enable

Enable message preview support.

srcaddr

Source address name.

string

Maximum length: 79

timeout

ICAP server idle timeout in seconds.

integer

Minimum value: 30 Maximum value: 3600

300

config icap-service

Parameter

Description

Type

Size

Default

service-id

ID of the ICAP server service.

integer

Minimum value: 0 Maximum value: 65535

0

name

Name of ICAP service profile.

string

Maximum length: 35

dlp-profile

Name of an existing DLP profile.

string

Maximum length: 35

av-profile

Name of an existing Antivirus profile.

string

Maximum length: 35

webfilter-profile

Name of an existing Web filter profile.

string

Maximum length: 35

image-analyzer-profile

Name of an existing Image analyzer profile.

string

Maximum length: 35

profile-protocol-options

Name of an existing Protocol options profile.

string

Maximum length: 35

default

extension-headers

Configuare the extension headers of icap server response.

option

-

Option

Description

X-Virus-id

Enable X-Virus-ID ICAP extension header.

X-Infection-Found

Enable X-Infection-Found ICAP extension header.

X-Violation-Found

Enable X-Violation-Found ICAP extension header.

config icap local-server

config icap local-server

Configure ICAP local server.

config icap local-server
    Description: Configure ICAP local server.
    edit <icap-server-id>
        set status [disable|enable]
        set secure-connection [disable|enable]
        set status-ipv6 [disable|enable]
        set icap-incoming-port {integer}
        set icap-incoming-ssl-port {integer}
        set interface {string}
        set incoming-ip {ipv4-address-any}
        set incoming-ipv6 {ipv6-address}
        set ssl-cert <name1>, <name2>, ...
        set strict-scheme-check [disable|enable]
        set message-preview [disable|enable]
        set srcaddr {string}
        set timeout {integer}
        config icap-service
            Description: Set up services for local ICAP server.
            edit <service-id>
                set name {string}
                set dlp-profile {string}
                set av-profile {string}
                set webfilter-profile {string}
                set image-analyzer-profile {string}
                set profile-protocol-options {string}
                set extension-headers {option1}, {option2}, ...
            next
        end
    next
end

config icap local-server

Parameter

Description

Type

Size

Default

icap-server-id

ICAP local server id.

integer

Minimum value: 0 Maximum value: 65535

0

status

Enable/disable status for icap server network profile.

option

-

enable

Option

Description

disable

Disable the status for ipv4 in network-profile.

enable

Enable the status for ipv4 in network-profile.

secure-connection

Enable/disable status for secured icap server network profile.

option

-

disable

Option

Description

disable

Disable the status for ipv4 ssl in network-profile.

enable

Enable the status for ipv4 ssl in network-profile.

status-ipv6

Enable/disable status for icap server service ipv6.

option

-

disable

Option

Description

disable

Disable the status for ipv6 in network-profile.

enable

Enable the status for ipv6 in network-profile.

icap-incoming-port

Accept incoming ICAP requests on a port.

integer

Minimum value: 1 Maximum value: 65535

1344

icap-incoming-ssl-port

Accept incoming secured ICAP requests on a port.

integer

Minimum value: 1 Maximum value: 65535

11344

interface

Interface name

string

Maximum length: 15

incoming-ip

Restrict the ICAP server to only accept sessions from this IP address. An interface must have this IP address.

ipv4-address-any

Not Specified

0.0.0.0

incoming-ipv6

Restrict the ICAP server to only accept sessions from this IPv6 address. An interface must have this IPv6 address.

ipv6-address

Not Specified

::

ssl-cert <name>

SSL certificate for SSL interception.

Certificate list.

string

Maximum length: 79

strict-scheme-check

Enable/disable strict check of scheme.

option

-

enable

Option

Description

disable

Disable strict check of scheme.

enable

Enable strict check of scheme.

message-preview

Enable/disable message preview support. Max preview data length is 4096 bytes.

option

-

enable

Option

Description

disable

Disable message preview support.

enable

Enable message preview support.

srcaddr

Source address name.

string

Maximum length: 79

timeout

ICAP server idle timeout in seconds.

integer

Minimum value: 30 Maximum value: 3600

300

config icap-service

Parameter

Description

Type

Size

Default

service-id

ID of the ICAP server service.

integer

Minimum value: 0 Maximum value: 65535

0

name

Name of ICAP service profile.

string

Maximum length: 35

dlp-profile

Name of an existing DLP profile.

string

Maximum length: 35

av-profile

Name of an existing Antivirus profile.

string

Maximum length: 35

webfilter-profile

Name of an existing Web filter profile.

string

Maximum length: 35

image-analyzer-profile

Name of an existing Image analyzer profile.

string

Maximum length: 35

profile-protocol-options

Name of an existing Protocol options profile.

string

Maximum length: 35

default

extension-headers

Configuare the extension headers of icap server response.

option

-

Option

Description

X-Virus-id

Enable X-Virus-ID ICAP extension header.

X-Infection-Found

Enable X-Infection-Found ICAP extension header.

X-Violation-Found

Enable X-Violation-Found ICAP extension header.