Description

This article explains a common reason why Application Policy-Based Routing (APBR) may fail to match certain applications.

Symptoms

  • Traffic does not match the expected application in APBR policies.
  • Policies using dynamic applications or advanced policy-based routing do not take effect as expected.
  • Traffic may follow the default route instead of the intended APBR path.

Solution

When using dynamic applications in security policies or advanced policy-based routing (APBR), the device relies on AppID signatures to identify applications.

If the required AppID signature database is not installed or up to date, the system cannot correctly identify the application. As a result, the traffic will not match the intended APBR rule.

 

Ensure that the AppID signature database is downloaded and installed on the device.

request services application-identification download

request services application-identification install

After installation, verify that the signatures are up to date and re-test the traffic flow.

Modification History

2024-11-10 : Article Created