Deployment

The recommended deployment uses a forward proxy: a Squid web proxy server connected to a Forcepoint protector using ICAP. Squid serves as a proxy for all HTTP, HTTPS, and FTP transactions. It is configured with rules that route data to the Forcepoint ICAP server.

The Forcepoint DLP protector receives all traffic directed to it from the Squid server for scanning, and, in enforcement mode, returns a response indicating whether to block or allow the transaction. In monitoring mode, the response is always allow.