リモートコンテンツ検査用のICAP
Citrix ADCアプライアンス上のICAP
ICAPリクエスト変更 (REQMOD) の仕組み
-
リクエストの変更バージョンを送り返し、アプライアンスは変更されたリクエストをバックエンドオリジンサーバーに送信するか、変更されたリクエストを別のICAPサーバーにパイプライン化します。
-
適応が必要ないことを示すメッセージで応答します。
-
エラーを返し、アプライアンスはエラーメッセージをユーザーに送信します。
ICAP 応答修正 (RESPMOD) の仕組み
-
応答の修正バージョンを送信し、アプライアンスは応答をユーザーに送信するか、応答を別のICAPサーバーにパイプライン化します。
-
適応が必要ないことを示すメッセージで応答します。
-
エラーを返し、アプライアンスはエラーメッセージをユーザーに送信します。
ICAP ライセンス
コンテンツ変換サービスのICAPを構成する
コンテンツ検査を有効にするには
enable ns feature contentInspection LoadBalancing
ICAP プロファイルを追加
ICAP.RESが使用されます。この式は、HTTP_CALLOUTのHTTP.RES式に似た ICAP応答を評価します。
add ns icapProfile <name> [-preview ( ENABLED | DISABLED )][-previewLength <positive_integer>] -uri <string> [-hostHeader <string>] [-userAgent <string>] -Mode ( REQMOD | RESPMOD )[-queryParams <string>] [-connectionKeepAlive ( ENABLED | DISABLED )][-allow204 ( ENABLED | DISABLED )] [-insertICAPHeaders <string>][-insertHTTPRequest <string>] [-reqTimeout <positive_integer>][-reqTimeoutAction <reqTimeoutAction>] [-logAction <string>]
add icapprofile reqmod-profile -mode RESPMOD -uri “/req_scan” -hostHeader “Webroot.reqsca” -useragent “NS_SWG-Proxy”
add ns icapProfile icap_prof1 -uri "/example" -Mode REQMOD -reqtimeout 4 -reqtimeoutaction BYPASS
> add icapProfile reqmode-profile -uri '/example' -mode REQMOD -insertHTTPRequest q{HTTP.REQ.METHOD + " " + HTTP.REQ.URL + " HTTP/1.1\r\n" + "Host: " + HTTP.REQ.HOSTNAME + "\r\n\r\n"}
ICAP コンテンツ検査アクションを記録する
add audit messageaction icap_log_expr INFORMATIONAL icap.res.full_header
set icapProfile reqmode-profile -logAction messageaction
ICAP サービスを TCP または SSL_TCP サービスとして追加する
add service <name> <IP> <serviceType> <port>
add service icapsv1 10.10.10.10 SSL_TCP 1345
add service icapsv2 10.10.10.11 SSL_TCP 1345
TCPまたはSSL_TCPベースの負荷分散仮想サーバーを追加する
add lb vserver <name> <serviceType> <port>
add lb vserver vicap TCP 0.0.0.0.0 –persistenceType NONE -cltTimeout 9000
add lb vserver vicap SSL_TCP 0.0.0.0 0 –persistenceType NONE -cltTimeout 9000
ICAP サービスを負荷分散仮想サーバーにバインドする
bind lb vserver <name> <serviceName>
bind lb vserver vicap icapsv1
コンテンツ検査アクションを追加
ifserverdownパラメータを設定できます。
add contentInspection action <name> -type ICAP -serverName <string> -icapProfileName <string>
add ContentInspection action <name> -type ICAP -serverip <ip> - serverport <port> -icapProfileName <string>
\<-serverip> オプションにサービス名を指定できます。コンテンツ検査アクションを追加すると、ポート1344の指定されたIPアドレスに対してTCPサービスが自動的に作成され、ICAP通信に使用されます。
add ContentInspection action ci_act_lb -type ICAP -serverName vicap -icapProfileName icap_reqmod
add ContentInspection action ci_act_svc -type ICAP -serverName icapsv1 -icapProfileName icap_reqmod
add ContentInspection action ci_act_svc -type ICAP -serverip 1.1.1.1 - serverport 1344 -icapProfileName icap_reqmod
コンテンツ検査ポリシーを追加する
add contentInspection policy <name> -rule <expression> -action <string>
add ContentInspection policy ci_pol_basic –rule true –action ci_act_svc
add ContentInspection policy ci_pol_HTTP –rule HTTP.REQ.URL.CONTAINS(“html”) –action ci_act_svc
コンテンツ検査ポリシーをコンテンツスイッチまたは負荷分散仮想サーバーにバインドする
セキュリティで保護された ICAP サービスの構成
-
SSL ベースの TCP サービスを追加します。
-
SSL ベースの TCP サービスを、TCP または SSL_TCP タイプの負荷分散仮想サーバーにバインドします。
-
SSL ベースの TCP サービスまたは負荷分散仮想サーバーをコンテンツ検査アクションにバインドします。
SSLベースのTCPサービスを負荷分散仮想サーバーに追加する
-
SSL ベースの TCP サービスを追加します。
-
SSL ベースの TCP サービスを、TCP または SSL_TCP タイプの負荷分散仮想サーバーにバインドします。
SSLベースのTCPサービスを負荷分散仮想サーバーに追加する
add service <name> <IP> <serviceType> <port>
add service icapsv2 10.102.29.200 SSL_TCP 1344 –gslb NONE –maxclient 0 –maxReq 0 –cip DISABLED –usip NO –useproxport YES –sp ON –cltTimeout 9000 –svrTimeout 9000 –CKA NO –TCPB NO –CMP NO
SSL ベースの TCP サービスを SSL_TCP または TCP 負荷分散仮想サーバーにバインドする
bind lb vserver <name> <serviceName>
bind lb vserver vicap icapsv2
SSL ベースの TCP サービスまたは負荷分散仮想サーバーをコンテンツ検査アクションにバインドする
add contentInspection action <name> -type ICAP -serverName <string> -icapProfileName <string>
add ContentInspection action ci_act_svc -type ICAP -serverName icapsv2 -icapProfileName icap_reqmod
add ContentInspection action ci_act_svc -type ICAP -serverName vicap -icapProfileName icap_reqmod
GUI を使用して ICAP プロトコルを構成する
-
負荷分散 > サービスに移動し 、 追加をクリックします。
-
「ポリシーの選択」 ページで、「 コンテンツ検査」を選択します。[続行] をクリックします。
-
アクションの名前を入力します。
-
[作成] をクリックします。
-
[Bind] をクリックします。
-
[完了] をクリックします。
GUI を使用してセキュリティで保護された ICAP プロトコルを構成する
-
負荷分散 > サービスに移動し 、 追加をクリックします。
-
「ポリシーの選択」 ページで、「 コンテンツ検査」を選択します。[続行] をクリックします。
-
アクションの名前を入力します。
-
「 サーバー名 」フィールドに、作成済みのTCP_SSLサービスの名前を入力します。
-
[作成] をクリックします。
-
[Bind] をクリックします。
-
[完了] をクリックします。
リモートコンテンツ検査の監査ログサポート
<Source IP> <Destination IP> <Domain> <ICAP server IP><ICAP Mode> <Service URI> <ICAP response> <Policy action>
Apr 18 14:45:41 <local0.info> 10.106.97.104 04/18/2018:14:45:41 GMT 0-PPE-0 : default CI ICAP_LOG 788 0 : Source 10.102.1.98:39048 - Destination 10.106.97.89:8011 - Domain 10.106.97.89 - Content-Type application/x-www-form-urlencoded - ICAP Server 10.106.97.99:1344 - Mode REQMOD - Service /example - Response 204 - Action FORWARD
Apr 18 12:34:08 <local0.info> 10.106.97.104 04/18/2018:12:34:08 GMT 0-PPE-0 : default CI ICAP_LOG 71 0 : Source 10.106.97.105:18552 - Destination 10.106.97.99:80 - Domain NA - Content-Type NA - ICAP Server 10.106.97.99:1344 - Mode RESPMOD - Service /example - Response 400 - Action Internal Error