Forum Discussion
suttonsc
Apr 04, 2019Employee
There is a timeout happening causing the response to be classified as a violation/virus.
It's difficult to know what specifically is contributing to the timeout without packet captures and debug logs. In that case I recommend opening a support case.
However, there are three control parameters for ICAP connections that can be adjusted to help:
icap_server_max_response_time - default value 120s
icap_server_max_send_time - default value 25s trying to send packet
icap_server_max_connections - default value 10 connections
These can all be set using "/usr/share/ts/bin/add_del_internal".
Example:
/usr/share/ts/bin/add_del_internal add icap_server_max_response_time 240