Cisco Secure Access Help

PDF

Cisco Secure Access Help

Manage Secure ICAP

Want to summarize with AI?

Log in

Describes Manage Secure ICAP in Cisco Secure Access and explains Prerequisites. It summarizes the behavior, configuration context, and operational considerations presented throughout the topic.


Note

This feature is released under controlled availability. If you wish to enable this feature, contact Secure Access Support for assistance.

You can forward the payload of Realtime DLP violations to on-premises DLP solutions using the secure Internet Content Adaptation Protocol (ICAP). Through ICAP, Secure Access DLP sends the payload that triggers a Realtime rule violation to an on-premises DLP.

To add Secure ICAP integration, define the ICAP server information in Secure Access as described in the Secure ICAP Integration topic.

Once you have established an ICAP connection, by default the payload of all active Realtime DLP rule violations will be sent over ICAP. You can disable this on a rule-by-rule basis; refer to Add a Real Time Rule to the Data Loss Prevention Policy for more information.

Prerequisites

  • Full Admin user role. For more information, see Manage Accounts.

  • You must have the ICAP server endpoint URI.

  • You must have the SSL certificate for the ICAP server.

  • Upload your own signed root CA certificate to Cisco Secure Access through the Secure > Certificates > Internet destinations page. The ICAP option is unavailable for configuration until this certificate is uploaded.

  • To prevent abuse of the API connection, we recommend you allow only the following IP addresses to your firewall:

    • 3.234.7.118

    • 54.90.48.200

    • 54.153.85.86

    • 184.72.63.136

    • 50.18.191.74

  • In addition, EU customers should add the following IP addresses to that list:

    • 3.120.233.38

    • 3.65.158.141

    • 18.168.8.192

    • 18.132.93.175


Secure ICAP Integration

Secure ICAP integration allows you to extend your existing on premises data loss prevention infrastructure to cloud traffic inspected by Secure Access.

Procedure

  1. Navigate to Admin > Authentication.

  2. Expand the Secure ICAP section and enable the Secure ICAP Server Certificate feature.

    Secure ICAP page displaying the option to enable the Secure ICAP Server Certificate feature.
    Note
    This toggle is unavailable until you upload your own signed root CA certificate to Cisco Secure Access through the Secure > Certificates > Internet destinations page.
  3. Click Add Secure ICAP Endpoint.

  4. Enter the ICAP Server Endpoint URI. (For example, icaps://k8s-dlprealt-cicapser-3ea8931f8c-c051176b1c4f93fc.elb.us-west-1.amazonaws.com:11344/echo).


    Secure ICAP page with a field to enter ICAP Server Endpoint URI
  5. Provide the ICAP server Certificate that will be used when the ICAP server requests client authentication. Use one of the following methods:

    • Drag and drop the certificate from your local system to the designated place on the screen.

      -or-

    • Click Or select file, navigate to the certificate on your local system, and select the file to upload.


    Secure ICAP page with an option to add a certificate for client authentication
  6. Click Save.

    The display reflects when the connection is successfully established.


    Secure ICAP section displaying information about successful connection establishment
    Note
    After you configure ICAP settings and establish the ICAP connection, if you remove the signed root CA certificate, the ICAP setting will show as enabled and established, but ICAP events will not be sent to the remote ICAP server.

Modify an ICAP Server Connection

Procedure

  1. Navigate to Admin > Authentication.

  2. Click EDIT next to the displayed ICAP server connection information.


    Secure ICAP section with an option to update ICAP server connection information
  3. Enter new values for the ICAP Server Endpoint URI, the server Certificate, or both. (See Steps 3 and 4 of Secure ICAP Integration ).

  4. Click SAVE.

  5. The system will attempt to reestablish the connection to the ICAP server with the new parameters and report success or failure.


Disconnect from an ICAP Server

Procedure

  1. Navigate to Admin > Authentication.

  2. Choose the ICAP server connection to disconnect and click REVOKE.


    Secure ICAP section with an option to disconnect the ICAP server connection
  3. Click DELETE to confirm your choice.


    Delete ICAP server popup asking confirmation to remove ICAP server from all policy instances
  4. The system will delete the URI and certificate for the connection; the connection will no longer be available for real time rules that have information sharing through ICAP enabled.