All Products
Search
Document Center

Smart Access Gateway:DPI overview

Last Updated:Apr 01, 2026

Smart Access Gateway (SAG) supports the deep packet inspection (DPI) feature. With DPI enabled, you can prioritize or restrict traffic for specific applications, enforce access control based on application identity, and monitor traffic distribution by application. DPI regulates network traffic routes and analyzes traffic distribution to provide a better user experience.

Supported devices

DPI is supported on the following devices:

DeviceMinimum version
SAG-10002.3.0
SAG-100WM

DPI is disabled by default. Enable it before creating policies or viewing monitoring data. For instructions, see Manage DPI.

How DPI works

DPI retrieves the payload of data packets to identify and re-organize application data at the application layer. This gives the system full visibility into each application's traffic, which it uses to enforce policies and display traffic distribution.

DPI supports three capabilities:

  • Application-aware quality of service (QoS) policies — prioritize or throttle traffic for specific applications

  • Application-aware access control lists (ACLs) — allow or block traffic based on application identity

  • Traffic monitoring — view the distribution of network traffic broken down by application

Specify applications in a policy

When creating a QoS policy or ACL, you must specify an application using one of these methods:

MethodDescription
Individual applicationDPI identifies the application and applies the policy to it alone.
Application groupDPI classifies applications into groups by shared characteristics. The policy applies to all applications in the group.

Get started with DPI

  1. Enable DPI on the SAG instance.

  2. Create policies based on your requirements:

Note

To view traffic monitoring data, enable the DPI-based monitoring feature on the SAG instance first. See Manage DPI.