You must define if your Network Prevent is analyzing the incoming or the outgoing traffic.
This is essential to this configuration, since you must define your icap url with this parameter.
Usually, you will monitor the outgoing traffic, since you want to know if sensible data is leaving the company.
For this, you will use Network Prevent in REQUEST MODE. So, the final icap url would be like this:
ipca://servername.domain:port/reqmod
If you need to monitor incoming traffic, then you will have to add another monitor server for Prevent Web, and use the icap url in this mode:
ipca://servername.domain:port/respmod
Regards,
LG