|
App-ID graphically displays the applications that are traversing the network, who is using them, and their potential security risk, which in turn, empowers administrators to quickly deploy application-, application function-, and port-based enablement policies in a systematic and controlled manner. Policies may range from open (allow), to moderate (enabling certain applications or functions, then scan, or shape, schedule, etc.), to closed (deny). Examples may include:
- Allow or deny
- Allow based on schedule, users, or groups
- Apply traffic shaping through QoS
- Allow certain application functions such as file transfer within instant messaging
- Allow, but scan for viruses and other threats
- Decrypt and inspect
- Apply policy-based forwarding
- Any combination of the above
Mixing next-generation policy criteria such as applications, application functions, users, groups and regions with traditional policy criteria such as source, destination and IP address allows organizations to deploy the appropriate policy for the requirement at hand.
|