Configuration Rules with L7 Filters

The controller imposes the following L7 filter configuration rules:
  • Rule #1 – If L7 filter rules are configured, “AP filter” and “custom AP filter” in Roles is disabled and the corresponding checkbox options are hidden.

    This allows the Configuration Manager to configure the system for upstream filtering at the controller, if possible, with no mixed B@AC and B@AP configuration within a role - enforced by Rule # 3.

  • Rule # 2 – Access control options “Contain to VLAN (Virtual LAN)” and "Redirect" are not supported for L7 rules.

    For DPI to identify a flow, TCP packets (3- way handshake exchanges and initial payload packets) must be allowed to pass through the system. If after the traffic flow is classified and the system diverts the rest of the traffic flow to a different VLAN (and most likely to a different server), then the new server treats the packets as stray traffic. This is because the new server did not exchange a 3-way handshake with the client for the connection.

  • Rule # 3 – Configuration Manager (CM) checks overall configuration as configuration is entered.

    If CM detects mixed B@AC and B@AP rules in the same role, and the role has L7 filter rules, then the configuration is rejected.

  • Rule # 4 – For L2/L3/L4 rule configuration, if COS is configured, the GUI prompts users to set “AP filter”. But, if L7 rules are present, then the GUI will always disable the AP filter option. See Rule # 1).