| Description | This article describes how to identify and troubleshoot ICAP communication issues where file scanning requests sent to FortiProxy remain incomplete or time out. |
| Scope | FortiProxy. |
| Solution |
In affected scenarios, malicious test files (for example, EICAR) are detected successfully, while clean files such as CSV, PDF, or XLS do not return a response and appear to hang on the ICAP client.
Important note:
If FortiProxy correctly detects and blocks EICAR files, this confirms that:
This behavior indicates an ICAP client interoperability issue, not a FortiProxy antivirus or ICAP configuration issue. ICAP transaction flow with preview mode enabled:
This indicates that the ICAP client does not properly handle the ICAP 100 Continue response.
Workaround:
Disable ICAP preview mode on the client:
If supported by the ICAP client implementation, disable preview mode so the client sends the entire file body in a single ICAP transaction.
This allows FortiProxy to complete content inspection and return a final verdict without relying on preview continuation handling. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.