Forum Discussion
Upload not send to ICAP ASM V10.2.4
We are running BIG-IP 10.2.4 Build 817.61 Engineering Hotfix HF7
I'm using an ASM policy (match on a specific uri) to send uploads to the icap service. The traffic is hitting the policy, but with tcpdump is notice no requests are send to the icap service. It is configured in option>antivirus protection. In V11 there's a seperate option in a specific policy to activate it, but this is absent in 10.2. I've read you just have to configure it in poliyc>blocking>settings and tick alle the boxes for "Virus detected".
Am i missing something? I think i do, but do not know what it is.
- Khay_164420Historic F5 Account
Hi Robert,
Have you check this link: https://support.f5.com/kb/en-us/products/big-ip_asm/manuals/product/config_guide_asm_10_2_0/asm_sys_mgmt.html?sr=155814941037564
Also, if you are not using the McAfee AV, you should change the value of the virus_header_name.
Regards,
- robert_83958NimbostratusI'm using bluecoat, so changed the header name to X-Error-details,X-Virus-Details and uri to /av_scan. Just created a new policy and now it sends the file to the icap service, got it once to show it in violations but now it fails to block it. It doesn't show up in the violations. strange! I've got other policies in place, so i'm using wildcards etc.. on parameters/cookies etc..
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com