Application Control for Tunneled Traffic

To classify a flow, the DPI engine must examine both client and server packets. The controller enforces policy for downstream traffic and the AP enforces policy for upstream traffic. For tunnel traffic, the DPI engine must examine the packets at the controller. Enforce this by clearing the AP Filtering checkbox on the Policy Rules tab.

Click to expand in new window
Configuring Policy Rules for Downstream Traffic at the Controller
Graphics/controller_policy_downstream.png