Custom application rules
are rules that you create to recognize (match) applications that are not in the
pre-defined set of application matches provided by ExtremeCloud Appliance. You create a custom
application rule by defining a regular expression to match against host names. The rule's match criteria
will be available as a match criteria for policy rules that you create in the future.
Actions and Limitations
When the Action filter for the application rule is set to Deny, the first few packets of a flow must be
allowed to pass through so that the deep-packet inspection (DPI) engine can examine the contents and
classify the packets. Once the packets are classified as Deny and the flow is blocked, the first few
packets have already passed through the system. For typical web traffic, the leak is minimal for a long
duration flow. However, for short duration flows, the Deny filter may not be effective.
Any flows that are not matched through classification are handled by the Default Action.
The Redirect action is only available for IPv4 traffic, not IPv6. The Allow, Deny, and Contain actions are
available for IPv6.
Related Links
Adding Custom Apps to the Application List
on page 134
Configuring L7 Application Rules
Create application rules when you need application-level (Layer 7) enforcement, for example, to limit or
block access to non-business related traffic.
You can create a new application rule anywhere in the list of policy rules and create any number of
application rules in one role.
To configure application rules:
1 Go to
Policy
>
Roles
>
Add
.
2 For application policy rules, select the
L7 Application Rules
drop-down.
3 Select in that row.
The Rules dialog displays.
From User
A packet header includes both a destination IPv4 address and a source IPv4 address.
Determine how to filter traffic that flows from the station to the network by defining the
destination or the source address as the filter. Options include: Destination (dest), Source
(src), and None.
To User
A packet header includes both a destination IPv4 address and a source IPv4 address.
Determine how to filter traffic that flows from the network to the station by defining the
destination or the source address as the filter. Options include: Destination (dest), Source
(src), and None.
Search
Type the application to search for. The Group and Application Name fields are automatically
populated when you select an application from the Search field.
Group
Internet applications are organized in groups based on the type or purpose of the
application. Once you select an Application Group, the Application Name drop-down is
populated with application names that are part of the specified group.
Application
Name
Names of applications that are a member of the specified group.
Access Control Determines access control action for the rule. Valid values are:
Configure
ExtremeCloud Appliance User Guide for version 4.36.03
133