Configuring Intelligent Application Bypass
Caution | Not all deployments require IAB, and those that do might use it in a limited fashion. Do not enable IAB unless you have expert knowledge of your network traffic, especially application traffic, and system performance, including the causes of predictable performance issues. Before you run IAB in bypass mode, make sure that trusting the specified traffic does not expose you to risk. |
Before you begin
For Classic devices, you must have the Control license.
Procedure
Step 1 | In the access control policy editor, click Advanced Settings from the More drop-down arrow at the end of the packet flow line. Then, click Edit () next to Intelligent Application Bypass Settings. |
Step 2 | Configure IAB options:
You must specify at least one inspection performance threshold and one flow bypass threshold; both must be exceeded for IAB to trust traffic. If you enter more than one threshold of each type, only one of each type must be exceeded. For detailed information, see IAB Options. |
Step 3 | Click OK to save IAB settings. |
Step 4 | Click Save to save the policy. |
What to do next
-
Because some packets must be allowed to pass before an application can be detected, you must configure your system to examine those packets.
See Best Practices for Handling Packets That Pass Before Traffic Identification and Specify a Policy to Handle Packets That Pass Before Traffic Identification.
-
Deploy configuration changes.