Describes Manage Secure ICAP in Cisco Secure Access and explains Prerequisites. It summarizes the behavior, configuration context, and operational considerations presented throughout the topic.
This feature is released under controlled availability. If you wish to enable this feature, contact Secure Access Support for assistance.
You can forward the payload of Realtime DLP violations to on-premises DLP solutions using the secure Internet Content Adaptation Protocol (ICAP). Through ICAP, Secure Access DLP sends the payload that triggers a Realtime rule violation to an on-premises DLP.
To add Secure ICAP integration, define the ICAP server information in Secure Access as described in the Secure ICAP Integration topic.
Once you have established an ICAP connection, by default the payload of all active Realtime DLP rule violations will be sent over ICAP. You can disable this on a rule-by-rule basis; refer to Add a Real Time Rule to the Data Loss Prevention Policy for more information.
Prerequisites
-
Full Admin user role. For more information, see Manage Accounts.
-
You must have the ICAP server endpoint URI.
-
You must have the SSL certificate for the ICAP server.
-
Upload your own signed root CA certificate to Cisco Secure Access through the page. The ICAP option is unavailable for configuration until this certificate is uploaded.
-
To prevent abuse of the API connection, we recommend you allow only the following IP addresses to your firewall:
-
3.234.7.118
-
54.90.48.200
-
54.153.85.86
-
184.72.63.136
-
50.18.191.74
-
-
In addition, EU customers should add the following IP addresses to that list:
-
3.120.233.38
-
3.65.158.141
-
18.168.8.192
-
18.132.93.175
-