Configure Traffic Policy for Application Intelligence Solutions

Required Licenses:
■   Application Filtering Intelligence — Application Filtering Intelligence with Application Visualization capability.
■   Application Metadata Intelligence — Application Metadata Intelligence with Application Visualization capability.
■   NetFlow/IPFIX — NetFlow/IPFIX generation for IPv4 and IPv6. This allows to export only the standard elements and not application metadata.
■   NetVUE
■   NetVUE PLUS
■   SecureVUE
■   SecureVUE PLUS
■   Zero Trust Architecture

Note:  These licenses are valid for a year. After the expiration date, the system does not allow you to add new configuration or make any configuration updates but allows traffic flow for two weeks.

Supported Devices: , GigaVUE‑HC1, GigaVUE‑HC1-Plus, GigaVUE‑HC3, GigaVUE-HCT.

When you create a Traffic Policy for an Application Intelligence solution, you describe your intent for the monitored traffic, such as which applications to observe, which to pass or drop, and which to export as metadata, and GigaVUE‑FM automatically builds the required map levels for you. You attach one or more Application Intelligence functions to sources (for example, network ports or vPorts) and Traffic Policy applies them as a unified, application‑aware pipeline.

■   Application Visualization (App Viz)—Identifies which applications are present in the traffic and how much bandwidth they consume, showing traffic statistics and top applications over time so you can understand the application mix before enforcing policies or exporting records.
■   Application Filtering Intelligence (AFI)—Filters traffic by application, application family, or tags so you can pass critical applications and drop or divert irrelevant ones, ensuring that only policy‑relevant traffic reaches your tools.
■   Application Metadata Intelligence (AMI)—Generates and exports detailed flow and application metadata (for example, NetFlow/IPFIX/CEF) for selected applications to external collectors and observability tools, providing rich context for performance analysis and threat detection.

Together, AppViz, AFI, and AMI let you use Traffic Policy to start with simple visibility, then layer on application‑aware filtering and metadata export as your monitoring and compliance needs evolve.

If you need a broader conceptual overview of how Application Intelligence solutions work, refer to Application Intelligence Solutions.

How Traffic Policy Choose Deployment Type for Application Intelligence Solutions

Intent-Based Map: When you create a Traffic Policy for the Application Intelligence solution. In this case, you do not design the individual maps yourself. Instead, you describe what you want the Application Intelligence solution to do with the traffic, and GigaVUE-FM builds the required map levels for you.

o   When you create a Traffic Policy for an Application Intelligence solution:
•   You choose one or more Application Intelligence functions such as:
•   Application Visualization (AppViz) – see which applications are present.
•   Application Filtering Intelligence (AFI) – pass or drop selected applications.
•   Application Metadata Intelligence (AMI) – export flow and metadata records.
•   NetFlow - generate Layer 2-4 flow data.

Note:  This configuration is applicable only when using NetFlow License on Gen 3 cards.

o   You attach these Application Intelligence functions to sources, for example, network ports or vPorts, by defining Application Intelligence intents:
•   For example, monitor all applications on the traffic arriving at specific source ports or vPorts, then filter traffic based on applications, and export metadata for selected applications.
o   Based on this intent, Traffic Policy chooses the underlying map types automatically:
•   If you only include an Application, for example, Application Visualization, without Application Ruleset, GigaVUE-FM creates regular maps with GSOP, where possible. This keeps performance close to classic regular maps.
•   If you include Application Ruleset such as GigaSMART rules or AFI rules, GigaVUE-FM creates a first level and second level map pair:
•   The first level map sends L2–L4 hardwarefiltered traffic from the source to a vPort.
•   The second level map takes traffic from the vPort, applies the Application Ruleset, for example, GigaSMART rules or AFI rules, and then runs the Application Intelligence functions (AFI/AMI).
o   If you chain multiple Application Intelligence solutions that cannot run in one GigaSMART operation, GigaVUE-FM inserts transit-level maps between vPorts:
•   Each transit level map performs one GigaSMART operation and forwards traffic to the next vPort.
•   From these vPorts, GigaVUE-FM can create multiple prioritized second-level maps to branch traffic to different tools or exporters.

Application Intelligence – Rules and Notes

Keep in mind the following rules and notes when you use Application Intelligence in a Traffic Policy:

■   You can deploy only one Application Intelligence solution (Application Visualization, Application Filtering Intelligence, and/or Application Metadata Intelligence) on a Gen 3 GigaSMART card or V Series node.
■   When you back up and restore configurations that include traffic policies for Application Intelligence, you must back up both the devices and GigaVUE-FM, then restore the backed‑up data on both.
■   Application Intelligence in a Traffic Policy supports both asymmetric (unidirectional) and symmetric (bidirectional) traffic. However, for the most accurate classification and metadata, use symmetric traffic whenever possible.
■   After you deploy or update a Traffic Policy that uses Application Intelligence, GigaVUE-FM can take up to 10 minutes to fully populate the Application Intelligence dashboards.
■   On Gen 2 GigaSMART cards, when both AMI and AFI licenses are installed, packets that do not have a complete 5‑tuple are dropped and are not forwarded to AMI for attribute extraction.
■   The AFI license is optional for AMI. If you enable AMI without explicitly configuring AFI for that traffic, an AFI pass‑all (“No‑Rule‑Match” pass) behavior is enabled by default so that AMI still receives the traffic.
■   In the second‑level maps of Application Intelligence, you cannot use pattern‑matching (regex/gsrule) rules and AFI application filter rules together in the same Application Ruleset.
■   Application Intelligence does not detect or classify ARP requests on either Gen 2 or Gen 3 devices. Packets that do not meet an Adaptive Packet Filtering (APF) match are dropped and not processed further by Application Intelligence.
■   You can configure up to 120 user‑defined applications per GigaVUE-FM instance. These user‑defined applications can be used across one or more Application Intelligence sessions or traffic policies.
■   You can configure a maximum of 8 rules per application. You can configure a maximum of 3 protocols per rule.
■   When the AMI session table/cache size is set to 10M, support for long-duration TLS flows depends on the traffic profile and the enabled attributes. The recommended limit is 10K CPS with 5M active flows for GTP traffic and 14K CPS with 7M active flows for non-GTP traffic. If these limits are exceeded, some exported flow records might not include attributes such as TLS SNI. In some traffic conditions, Flow-ID reset can also occur.

Refer to the following sections for instructions on how to configure Traffic Policy for Application Intelligence solutions with real time examples:

■   Use Case: Reduce Tool Overload
■   Use Case: Enhance Context for Incident Response
■   Use Case: Maintain Visibility Whilst Filtering Traffic