Forum Discussion
Metascan ICAP
Hello Geeks,
I am trying to integrate metascan icap server with f5 to scan http uploads and allow/block based on that, unfortunately metascan is able to scan but unable to send the response back in required format, as i understand detected/clean info should be in one of the response headers.
In this case, it's in content.
So ideally can we have an irule which looks for certain string in content from icap server and take action ?(allow/block)
Any help is appreciated.
Thanks
1 Reply
- Mandrake
Nimbostratus
Following is the response from ICAP server:
ICAP/1.0 201 Created Date: Tue, 25 Mar 2014 14:28:27 GMT ISTag: "09201403250945" Encapsulated: res-hdr=0, res-body=107 Server: Metascan/3700 Connection: close
HTTP/1.1 403 Forbidden Date: Tue, 25 Mar 2014 14:28:27 GMT Pragma: no-cache Content-Type: text/html
.
...File blocked ..
C:\Users\Administrator\Desktop\icap test\eicar.com - Copy.txt has been blocked by your administrator.s security policy because a threat (EICAR_Test) was detected by Metascan.
..Your administrator is using OPSWAT’s Metascan technology to scan downloads with multiple anti-malware engines. See additional ways Metascan can be used by trying the Metascan Client demo for scanning endpoint processes and files or the Metascan Online file scanning service.
.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com