pfSense Support Subscription

Author Topic: ICAP Protocol Error  (Read 833 times)

0 Members and 1 Guest are viewing this topic.

Offline eligiable

  • Newbie
  • *
  • Posts: 6
  • Karma: +0/-0
    • View Profile
ICAP Protocol Error
« on: July 26, 2017, 02:11:20 am »
Hi There
I'm running pfSense since very long time, and now the subjected issue started since a month.

I've tried multiple options, but no luck, the following is my configuration:

pfSense Version 2.3.4-RELEASE-p1
Intel Core i5 - 3 GHz
4 GB RAM (and it's not even crossing 50%)
500 GB HDD

Squid 0.4.37 with C-ICAP and CalmAV enabled
- Transparent Proxy (only on HTTP)
- No Remote Cache

Kindly help me in this regard.
Thanx in Advance.

Offline Bismarck

  • Full Member
  • ***
  • Posts: 120
  • Karma: +21/-1
    • View Profile
Re: ICAP Protocol Error
« Reply #1 on: August 01, 2017, 12:16:31 am »
Same problem here, the issue started since a month as well.

Nothing to find in the logs, it just happens at random times.

2.3.4-RELEASE-p1 (amd64)
built on Fri Jul 14 14:52:43 CDT 2017
FreeBSD 10.3-RELEASE-p19

Squid Version 3.5.26, ClamAV 0.99.2_3, C-ICAP 0.4.4,2 +  SquidClamav 6.16

2x Intel(R) Xeon(R) CPU X5570 @ 2.93GHz
32 GB ECC RAM
600 GB HDD Raid 10

Temporary workaround is to set bypass=on, so at least the users don't get annoyed by the "ICAP Protocol Error" message.


Offline CheesePatrol

  • Newbie
  • *
  • Posts: 1
  • Karma: +0/-0
    • View Profile
Re: ICAP Protocol Error
« Reply #2 on: August 29, 2017, 11:09:04 pm »
Same here, randomly happened to me tonight.  Updating SquidAV seemed to have resolved the issue.  From some quick Googling, it looks like a number of people have experienced this issue but there isn't a real solution nor a reason why this occurs.

Offline ccdmas

  • Newbie
  • *
  • Posts: 6
  • Karma: +0/-0
    • View Profile
Re: ICAP Protocol Error
« Reply #3 on: September 04, 2017, 04:43:53 am »
Here's a "me too".

However, I can sort of duplicate the problem or pinpoint at least one cause of it. I recently changed the proxy configuration of our email security gateway from our previous proxy to squid on PfSense, and since then the issue happens at least every second day, and apparently when the email gateway updates it's AV definition files via the proxy.

Interestingly, restarting clamav or ICAP doesn't help solving the issue, the only way to get it up again is to restart squid as a whole.




Offline doktornotor

  • Hero Member
  • *****
  • Posts: 8553
  • Karma: +956/-278
  • Not a pfSense employee, they cannot fire me...
    • View Profile
Re: ICAP Protocol Error
« Reply #4 on: September 04, 2017, 05:46:02 am »
and apparently when the email gateway updates it's AV definition files via the proxy.

Ugh. You should NOT download antivirus defs via the proxy with ClamAV in the first place. It will trigger false positives and cause other issues.
Do NOT PM for help!

Offline ccdmas

  • Newbie
  • *
  • Posts: 6
  • Karma: +0/-0
    • View Profile
Re: ICAP Protocol Error
« Reply #5 on: September 04, 2017, 09:51:59 am »
Quite seriously: You need to see more of the real world out there. LOading AV defs through a http proxy is absolutely normal every day business everywhere. Are you saying to die until restart is acceptable behaviour? ::)

Offline kuberan

  • Newbie
  • *
  • Posts: 21
  • Karma: +0/-0
    • View Profile
Re: ICAP Protocol Error
« Reply #6 on: November 28, 2017, 09:48:58 am »
I also have the same issue, where do you turn on ByPass?