Error: "No ICAP server is available" and can't access any web sites in a Edge SWG (ProxySG)
search cancel

Error: "No ICAP server is available" and can't access any web sites in a Edge SWG (ProxySG)

book

Article ID: 368369

calendar_today

Updated On:

Products

ISG Proxy ProxySG Software - SGOS CAS-VA

Issue/Introduction

ICAP Error (icap_error) on the browser, An error occurred while performing an ICAP operation: Server unavailable: No ICAP server is available to process the request.

ICAP Error (icap_error)

An error occurred while performing an ICAP operation: Server unavailable: No ICAP server is available to process request.

There could be a network problem, the ICAP service may be misconfigured, or the ICAP server may have reported an error.

Environment

CAS-VA (CAS-VA) , ProxySG Software - SGOS (ProxySG Software - SGOS), ISG , Symantec Content analysis

Cause

  • The ICAP server might be experiencing downtime, or there could be connectivity issues between the ProxySG and the ICAP server. Furthermore, your ICAP policy is set to (fail_closed) i.e. Deny client requests if any errors occur during ICAP processing or the ICAP server is not available. 
  • The Anti-Virus (AV) license is invalid or expired on Symantec CAS or security-related subscriptions on Edge SWG (ProxySG) expired.

 

Resolution

1- If there is a license issue on either Symantec CAS or Edge SWG (ProxySG), solve it before proceeding any further with troubleshooting. 

2- If you enable the Web Content layer or rule scanning on the ProxySG appliance before configuring ICAP servers and services, users will lose web access. Set up ICAP services and servers before enabling AV scanning. Then, verify connectivity between the ProxySG and the ICAP server by Bluecoat packet captures for troubleshooting Edge SWG and Advanced Secure Gateway (broadcom.com)

3 - Based on your company's security posture, you might consider changing the ICAP policy to 'Continue without malware scanning" (fail_open) ". With this setting, users can still access the Internet even if the ICAP service is down. However, this will expose the network to potential malware downloads during ICAP server downtime. Desktop virus scanners, if deployed, can offer some protection against malware.