> Source: [sk123412](https://support.checkpoint.com/results/sk/sk123412)

# sk123412 - ICAP Server support for Threat Prevention

| Property | Value |
|----------|-------|
| Solution ID | sk123412 |
| Date Created | 2018-05-01 |
| Last Modified | 2025-12-07 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20, R81.10 (EOS), R81 (EOS) |
| OS | Gaia |

## Solution

**Availability:**

* This feature is now available on Security Gateway and Security Management, versions R80.20 and higher.

<!-- -->

* For R80.10 Security Gateway with [R80.10 Jumbo HFA](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk116380)- **Take_167** and higher, refer to [sk122853 - R80.20 Management Threat Prevention new features supported with R80.10 Jumbo Hotfix](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk122853).

<!-- -->

* If you have R80.10 with R80.10 Jumbo HFA - **Take_142** installed, [contact Check Point Support](https://www.checkpoint.com/support-services/contact-support/) to get a Hotfix which adds this feature on top of Take_142.
* ICAP is not supported in Autonomous Threat Prevention.

ICAP Server can work with the Threat Emulation and Anti-Virus blades only. Threat Extraction is also supported in R81 and higher. Any other Software Blades in a Threat Prevention profile will be ignored.

To activate the ICAP Server in a Security Gateway object in SmartConsole, you must first enable the Threat Emulation Software Blade and/or Anti-Virus Software Blade in that Security Gateway object.

Upon ICAP Server activation, an auto-generated rule is created in the Threat Prevention rule base, as in MTA. This rule is installed on all Security Gateways with active ICAP Server.

**Notes:**

* ICAP Server has only one rule that must be located in an upper rule (alongside with MTA) of the Threat Prevention policy.
* ICAP Server supports only Anti-Virus deep-scan. Any additional functionality, such as MD5 hash, URL reputation, and signature based protection, is not supported for this flow.
* There are no network based rules or exceptions that are related to ICAP rule / profile.
* VSX is not supported. Supported in VSXNext starting from R82 Jumbo Hotfix Take 44.

For additional details on how to configure the ICAP client and ICAP server, see the [Threat Prevention Administration Guide](https://support.checkpoint.com/product/417#f-commonsource=C.%20Documentation) for your version.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
