Description | This article describes the behavior with FortiProxy ICAP integration when both REQMOD (request) and RESPMOD (response) modes are enabled. The configured methods will affect both modes. |
Scope | FortiProxy. |
Solution |
When using FortiProxy as an ICAP Client, response and request processing modes can be configured independently on the ICAP profile.
However, in the GUI, the methods to be scanned can only be selected when request processing is enabled.
As an example, let's use the EICAR virus file for testing.
The download of the file will use the GET method, but if only POST and PUT are selected on the GUI for the request, both methods (request, response) will bypass the scan for GET methods.
Here are some captures in the ICAP Server:
ICAP client (FortiProxy) only forwarded the ICAP encapsulated POST method to the ICAP Server. In this case, the EICAR virus file was downloaded successfully.
ICAP Server responds with 403 Forbidden and encapsulates the HTML response body to the client.
From the client's perspective, this is what it is visible in the browser.
The method selection will affect both request and response, even if not visible on the GUI, which is the case when request processing is disabled (as seen before):
|
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.