New topicAllowing for Restricted Sets of Applications and Resources

With the use of two new groups: the Unknown Apps group and the Wild Card group, you can configure policy filters that improve application control. Defined signature rules allow fine-tuning of how to handle traffic for specific applications or traffic categories.

The Unknown Apps group allows you to take action on applications that the Deep Packet Inspection (DPI) sensor does not recognize. When the DPI sensor fails to classify a flow, the flow is automatically considered unknown and it is classified as part of the Unknown Apps group. You can assign standard actions (allow, deny, rate limit, etc) to flows belonging to the Unknown Apps group.

The Wild Card group makes it simple to allow access to restricted sets of applications and resources. When configuring filters for restrictive sets:
  1. Configure the Allowed application filters first.
  2. Configure a Deny filter specifying the Group = Wild Card and Name = All.
  3. Configure a Deny filter specifying Group = Unknown Apps and Name = All.