Application Patrol; Chapter 15 Application Patrol; Overview; What You Can Do In This Chapter - ZyXEL Communications USG FLEX H Series User Manual

Table of Contents

Advertisement

15.1 Overview

Application patrol provides a convenient way to manage the use of various applications on the
network. It manages general protocols (for example, HTTP and FTP) and instant messenger (IM), peer-to-
peer (P2P), Voice over IP (VoIP), and streaming (RSTP) applications. You can even control the use of a
particular application's individual features (like text messaging, voice, video conferencing, and file
transfers).

15.1.1 What You Can Do in this Chapter

• Use the App Patrol summary screen (see
profiles. You can also view license registration and signature information.
• Use the App Patrol Add/Edit screens (see
actions for application categories and for specific applications within the category.

15.1.2 What You Need to Know

If you want to use a service, make sure both the Security Policy and application patrol allow the
service's packets to go through the Zyxel Device.
Note: The Zyxel Device checks secure policies before it checks application patrol rules for
traffic going through the Zyxel Device.
Application patrol examines every TCP and UDP connection passing through the Zyxel Device and
identifies what application is using the connection. Then, you can specify whether or not the Zyxel
Device continues to route the connection. Traffic not recognized by the application patrol signatures is
ignored.
Application Profiles & Policies
An application patrol profile is a group of categories of application patrol signatures. For each profile,
you can specify the default action the Zyxel Device takes once a packet matches a signature (forward,
drop, or reject a service's connections and/or create a log alert).
Use policies to link profiles to traffic flows based on criteria such as source zone, destination zone, source
address, destination address, schedule, user.
Classification of Applications
There are two ways the Zyxel Device can identify the application. The first is called auto. The Zyxel
Device looks at the IP payload (OSI level-7 inspection) and attempts to match it with known patterns for
specific applications. Usually, this occurs at the beginning of a connection, when the payload is more
consistent across connections, and the Zyxel Device examines several packets to make sure the match
C

Application Patrol

Section 15.2 on page
Section 15.2.1 on page 235
USG FLEX H Series User's Guide
232
H A P T E R
233) to manage the application patrol
&
Section on page
15
236) to set

Advertisement

Table of Contents
loading

Table of Contents