Step 1: Enabling BWM on WAN interface.
Step 2: Creating Match Object.
Step 3: Creating Bandwidth Object.
Step 4: Creating Action Object.
Step 5: Creating App Rule policy to enforce the match and action objects to it.
Step 6: Enabling App Control Service on the respective zone.
Step 1: Enabling BWM on WAN interface
1. Navigate to Firewall Settings | BWM.
2. Set Bandwidth Management Type as "Advanced" & click on "accept" on top.
-kA1VN0000000KOc0AM-0EMVN00000EoNjE.png)
3. Navigate to the Network | Interfaces page.
4. Click on the Configure button of WAN interface. In this example the X1 interface.
-kA1VN0000000KOc0AM-0EMVN00000EoNjB.png)
5. Click on the Advanced tab and do one or both of the following:
-kA1VN0000000KOc0AM-0EMVN00000EoNjP.png)
6. Click on OK to save.
Step 2: Creating Match Object
1. Navigate to Firewall | Match Objects.-kA1VN0000000KOc0AM-0EMVN00000EoNjO.png)
2. Click on Add New Match Object button and enter the following:
-kA1VN0000000KOc0AM-0EMVN00000EoNj9.png)
3. Click OK to create the match object.
Â
Step 3: Creating Bandwidth Object
1. Navigate to Firewall | Bandwidth Objects.
-kA1VN0000000KOc0AM-0EMVN00000EoNiz.png)
2. Click on Add button and enter the following:
-kA1VN0000000KOc0AM-0EMVN00000EoNjD.png)
3. Click OK to save the bandwidth object.
Â
Step 4: Creating Action Object
1. Navigate to Firewall | Action Objects.
-kA1VN0000000KOc0AM-0EMVN00000EoNjL.png)
2. Click Add New Action Object button and enter the following:
-kA1VN0000000KOc0AM-0EMVN00000EoNj1.png)
3. Click OK to save the new action.
Â
Note:
Step 5: Creating App Rule policy to enforce the match and action objects to it
1. Navigate to Firewall | App Rules.
-kA1VN0000000KOc0AM-0EMVN00000EoNjK.png)
2. Click Add New Policy and enter the following:
-kA1VN0000000KOc0AM-0EMVN00000EoNjQ.png)
3. Click OK to save the newly created policy.
Â
Step 6: Enabling App Control Service on the respective zone
1. Navigate to Network | Zones.
-kA1VN0000000KOc0AM-0EMVN00000EoNjH.png)
2. Click on the configure button under the zone where you want enable App Control. (In this article, LAN zone is considered, App Control can be enabled on all other zones also)
3. Check the option Enable App Control Service and click on OK to save the change.
-kA1VN0000000KOc0AM-0EMVN00000EoNjF.png)
After clicking on OK, you can notice that the LAN zone will have a check mark for App Control as shown below.
Â
Â
How to Test:
Users attempting to exceed the bandwidth limits defined in this Application Firewall Action for Bittorrent will be limited and a log message similar to the following will be generated: