Application Intelligence Field References

The following table lists all the fields utilized while configuring an Application Intelligence, Application Filtering Intelligence and Application Metadata Intelligence sessions.

 

Application Intelligence Session

Field

Description

Name

Enter a unique name for the Application Intelligence session.

Description

(Optional) Enter a description for the session.

Environment

Select Physical to configure the session for GigaVUE HC Series devices.

Node

Select the node on which you want to deploy the session.

Monitoring

Enables or disables Application Visualization (AppViz) for this session. Monitoring is enabled by default and can be disabled when not required to improve performance.

Export Interval

Displays the interval at which AppViz statistics are exported to GigaVUE-FM. The value is fixed at 300 seconds (5 minutes) and is not user-configurable from version 6.4 onwards.

Fast Mode

When enabled, uses light parsers to increase DPI performance for HTTP and DNS. Only a limited set of HTTP attributes is supported and GigaVUE-FM automatically exposes only the supported attributes. Fast mode can be enabled or disabled only when creating a new session.

GigaSMART Group

Select an existing GigaSMART group, or create a new group by specifying an Alias and selecting one or more engine ports in the Port List.

Application Session Filtering Buffer Size

Configures the buffer size used by Application Session Filtering in the GigaSMART group.

Metadata Export Buffer Size

Configures the buffer size used for exporting metadata in the GigaSMART group.

User Defined Applications

Associates a User Defined Applications profile with the session so that the DPI engine can classify proprietary or internal applications based on user-defined signatures.

IP Interface Type

Select IPv4 or IPv6 as the IP version for the AppViz export interface.

IP Address / IP Mask / Gateway / MTU

Configure the IP interface used to export application statistics. The destination IP address must use the same IP version as the selected interface.

Destination IP Address

Specifies the IP address of GigaVUE-FM (or other collector) that receives AppViz statistics. By default, the GigaVUE-FM management IP is displayed.

Source Ports

Select one or more network ports or port groups that provide the traffic to be monitored by the session. Ports already used as sources in intent-based orchestrated solutions are not listed.

L2–L4 Rules

Defines Layer 2–Layer 4 conditions for each Source Traffic block. For each rule, click Select Conditions, choose a qualifier (such as IP version, IP source/destination, VLAN, protocol, or port), set the value, and select Pass or Drop and Bidirectional or unidirectional.

+ (Add a Rule)

Adds another L2–L4 rule to the current Source Traffic block.

+ New Source Traffic

Adds another Source Traffic entry with its own source ports and L2–L4 rules.

Application Filtering Intelligence (AFI)

Application selection and destination traffic

Field

Description

Selected Applications

Lists the applications chosen from Total Applications on the Application Intelligence dashboard for creating an AFI policy. You can select one or more applications.

Pass

Marks the selected application to be passed to the tool ports configured in the associated Destination Traffic Priority block.

Drop

Marks the selected application to be dropped at the tool ports configured in the associated Destination Traffic Priority block.

Destination Traffic Priority

Represents a second-level AFI map that forwards filtered traffic to tool ports. You can configure up to five Destination Traffic Priorities per AFI solution and reorder them to change priority.

Tool Ports (Select ports …)

Select the tool ports or tool port groups that receive traffic for this Destination Traffic Priority. If the required port is not visible, use Port Editor to mark it as a Tool port.

Port Editor

Opens an inline editor to change the Type of a physical port to Tool, after which it appears in the tool port selection list.

Pass All

When enabled for a Destination Traffic Priority, passes all applications that do not match any explicit AFI rules in that priority. No-rule-match traffic can be monitored using map rule counters.

Advanced Rules

Opens the advanced rule configuration for the selected Destination Traffic Priority, allowing you to define non-application criteria (for example IP, VLAN, DSCP, pattern match) that must be met before traffic is passed or dropped.

+ Add New (Destination Traffic Priority)

Adds another Destination Traffic Priority (second-level map). A maximum of five priorities can be configured per AFI instance.

Filter to

Applies the AFI configuration and binds selected applications and rules to the Destination Traffic Priority.

AFI Settings

Field

Description

Bidirectional

Configures whether AFI maintains flow state and applies rules to both directions of a session. When disabled, each direction is treated independently. Enabled by default.

Timeout

Configures the idle timeout for AFI sessions. The default is 15 seconds; the valid range is 10–120 seconds. Flows that remain silent beyond this interval are flushed.

Buffer

Configures the number of initial packets that AFI buffers before applying filtering rules. The default is 20; the valid range is 3–20. Lower values may cause drops if more packets are needed for DPI classification.

Protocol

Selects the transport protocols for which AFI maintains sessions. Options include TCP only, UDP only, TCP-UDP, TCP UDP and SCTP, and SCTP only. Traffic that does not match the selected protocol set is dropped unless explicitly handled elsewhere.

Session Slicing

When enabled, allows you to mention the Packet Count. The Packet Count limits the number of packets passed per flow to a configurable value in the range 2–100. Useful when tools only need the first few packets, such as TLS handshakes.

Session Fields

Configures the protocol fields used to uniquely identify flows. The default 5tuple uses inner source and destination IP addresses, source and destination ports, and protocol; VLAN can optionally be included.

AFI Advanced Rules

Field

Description

Select Options

For each advanced rule, select a qualifier from the drop-down list, such as DSCP, ERSPAN ID, EtherType, GRE Key, GTP-U TEID, IP Fragmentation, IP Version, IPv4 Source/Destination, IPv6 Source/Destination, MAC Source/Destination, MPLS Label, Port Source/Destination, TCP Control, VLAN, VN-Tag VIF IDs, VXLAN ID, or Pattern Match.

Pattern Match Type

When Pattern Match is selected, choose String or Regex and provide the search pattern to match data in the packet payload.

Value

Enter the value appropriate for the selected qualifier (for example VLAN ID, IP address, DSCP number, or string/regular expression pattern).

Pass / Drop

Specifies whether packets matching this advanced rule are passed to the destination or dropped.

Application Metadata Intelligence (AMI)

Application and attribute selection

Field

Description

Selected Applications

Lists the applications chosen from Total Applications on the Application Intelligence dashboard for exporting metadata.

Attributes

For each selected application, enables you to select the attributes to be exported. Each exporter can export metadata for up to 256 applications, and up to 64 attributes per application.

Export / Export To

Marks the selected applications for export and associates them with the configured exporters.

Destination Traffic – Exporters

Field

Description

Tool Name

Configures an alias for the metadata collector (for example Splunk, NDR-1).

IP Interface

Selects the IP interface on the Gigamon device that connects to the collector.

Tool IP Address

Specifies the IP address of the tool that receives exported records.

Template

Selects a pre-defined tool template that defines applications, attributes, and export format, such as SplunkMetadataTemplate, SecurityPosture, RogueActivity, or UnmanagedAssets.

L4 Source Port

Specifies the source UDP port used by the exporter.

L4 Destination Port

Specifies the UDP destination port on the collector. When the export format is CEF, the default is 514; when the format is NetFlow, the default is 2055.

SNMP

Enables or disables processing of SNMP packets (UDP 161) on the exporter interface. All exporters sharing an IP interface must have SNMP configured consistently.

Application ID

When enabled, exports the Application Name for all applications identified by the DPI engine. Requires AMI/SVP/ZTA license.

Application List

Limits application metadata export to the selected applications or protocols on this exporter. Packet attributes (Collects) are still exported for all applications unless traffic is filtered using AFI or flow maps.

Format

Selects the export format: NetFlow or CEF.

Version

For NetFlow format, selects the NetFlow/IPFIX version: v5, v9, or IPFIX (IPFIX is the default).

Template Refresh Interval

Configures how often template records are exported for IPFIX. The default is 60 seconds; the valid range is 1–216000 seconds.

Record Type

Selects how network and application metadata are exported. Segregated exports separate records for network and application metadata. Cohesive exports a consolidated record comprising both. The default depends on the configured Flow Behavior (Unidirectional or Bidirectional).

Active Timeout

Configures the interval for exporting interim records for long-lived flows. The default is 60 seconds; the valid range is 1–604800 seconds.

Inactive Timeout

Configures the idle timeout for marking flows as inactive and exporting their records. The default is 15 seconds; the valid range is 1–604800 seconds.

Advanced Settings – Collects

Field

Description

Counter

Enables export of Bytes and Packets counters and configures the counter width (32- or 64-bit). NetFlow v5 supports only 32-bit counters.

IPv4 Collects

Enables export of IPv4 attributes such as Source Address, Destination Address, Protocol, DSCP, TOS, TTL, header length, payload length, and fragmentation details.

IPv6 Collects

Enables export of IPv6 attributes such as Source Address, Destination Address, Next Header, Flow Label, Traffic Class, DSCP, and fragmentation details.

Transport Collects

Enables export of transport-layer fields such as Source Port, Destination Port, TCP flags, TCP sequence and acknowledgment numbers, MSS, Aggregate Window Size, and Zero Window statistics.

ICMP Collects

Enables export of ICMP Type and Code for IPv4 and IPv6 ICMP traffic.

Data Link Collects

Enables export of Source MAC, Destination MAC, and ingress VLAN ID.

Timestamp Collects

Enables export of System Uptime First, System Uptime Last, Flow Start, and Flow End timestamps.

Flow Collects

Enables export of the flow end reason (for example TCP FIN, RST, or inactive timeout).

Interface Collects

Enables export of input and output interface index (2- or 4-byte widths) and input interface name, with configurable name width. Supported for standalone and legacy cluster deployments.

Application Metadata Settings

Field

Description

Events

Controls when records are exported for TCP flows. Transaction End exports records as soon as TCP connections terminate; None exports records based only on inactive timeout.

Flow Direction / Behavior

Selects Unidirectional or Bidirectional flow behavior. In Unidirectional mode, one record is exported per direction. In Bidirectional mode, a single record is exported for both directions of a flow.

Timeout

Configures the cache timeout for flows maintained in the AMI cache. The default is 300 seconds; the valid range is 1–604800 seconds.

Cache Size

Sets the maximum number of concurrent flows that can be tracked. Valid ranges depend on platform and generation; from 6.12 onwards, the maximum supported value is used as the default for new configurations.

Multi-Collect

When enabled, allows multiple values to be exported for attributes that can have more than one value (for example DNS host addresses). IPFIX supports up to five values per attribute; CEF has no limit.

Data Link

When enabled, exports Source and Destination MAC and VLAN ID and treats flows with identical 5-tuples and different VLAN IDs as the same flow.

Observation Domain ID

Configures a user-defined identifier in the range 0–255 that, combined with the GS engine slot, forms the 4-byte Observation Domain ID used by collectors to distinguish sessions.

DPI Packet Limit

Restricts the number of packets per session sent to the DPI engine to improve performance. Recommended values are between 20–50, since the first packets in a flow typically contain the most significant attributes.

Aggregate Mode

When enabled (Gen3 only), exports minimum, maximum, and mean RTT and TCP loss bytes per export interval for supported protocols such as TCP, HTTP, SSH, TELNET, ICMP, and ICMPv6.

Recurring Attributes

When enabled, exports TLS Server Name for the lifetime of new TLS flows. When disabled, the value is exported only once at the beginning of a flow. Configurable from the Traffic Policy workflow supported on GigaVUE HC Series Gen3 GigaSMART module.

.

De-duplication

Field

Description

De-duplication

When enabled for an Application Intelligence solution, inserts the GigaSMART De-duplication operation into the AFI and/or AMI path to remove duplicate packets before they reach the tools. Requires a De-duplication license.