Smart Access Gateway (SAG) supports the deep packet inspection (DPI) feature. With DPI enabled, you can prioritize or restrict traffic for specific applications, enforce access control based on application identity, and monitor traffic distribution by application. DPI regulates network traffic routes and analyzes traffic distribution to provide a better user experience.
Supported devices
DPI is supported on the following devices:
| Device | Minimum version |
|---|---|
| SAG-1000 | 2.3.0 |
| SAG-100WM | — |
DPI is disabled by default. Enable it before creating policies or viewing monitoring data. For instructions, see Manage DPI.
How DPI works
DPI retrieves the payload of data packets to identify and re-organize application data at the application layer. This gives the system full visibility into each application's traffic, which it uses to enforce policies and display traffic distribution.
DPI supports three capabilities:
Application-aware quality of service (QoS) policies — prioritize or throttle traffic for specific applications
Application-aware access control lists (ACLs) — allow or block traffic based on application identity
Traffic monitoring — view the distribution of network traffic broken down by application
Specify applications in a policy
When creating a QoS policy or ACL, you must specify an application using one of these methods:
| Method | Description |
|---|---|
| Individual application | DPI identifies the application and applies the policy to it alone. |
| Application group | DPI classifies applications into groups by shared characteristics. The policy applies to all applications in the group. |
Get started with DPI
Enable DPI on the SAG instance.
Create policies based on your requirements:
QoS policy — See What is a QoS policy?
ACL — See ACL overview
Traffic monitoring — See View traffic monitoring data of applications
To view traffic monitoring data, enable the DPI-based monitoring feature on the SAG instance first. See Manage DPI.