A security engineer notices that traffic from a trusted internal application is being blocked by the firewall. The application communicates using a proprietary protocol over TCP port 8443. The engineer has already created a custom App-ID for this application but the traffic is still being blocked. What is the most likely reason?
Trap 1: The custom App-ID must be added to a security profile group.
Security profile groups bundle threat, URL and file inspection settings applied after a rule permits traffic; they do not determine whether the custom App-ID matches. The block stems from the App-ID not being recognised, so no permit rule fires. Profile groups are tempting because they are configured alongside rules, and would be correct once traffic is allowed and needs inspection.
Trap 2: The custom App-ID needs a vulnerability profile to be activated.
Vulnerability profiles act on traffic already permitted by a security policy; they cannot authorise a blocked session. The custom App-ID is failing to match, so the rule never permits the flow. Vulnerability profiles are tempting because they are attached to security rules, and would be correct if the traffic were permitted but needed threat inspection.
Trap 3: The security policy rule uses the destination port instead of…
A rule matching destination port 8443 with application any would still permit the traffic, so it cannot explain the block. The likely cause is the custom App-ID not matching because the application signature is incomplete or the session is identified as incomplete. Port-based rules are tempting as a fallback, and would be correct when App-ID is unavailable.
- A
The custom App-ID must be added to a security profile group.
Why it fails: Security profile groups bundle threat, URL and file inspection settings applied after a rule permits traffic; they do not determine whether the custom App-ID matches. The block stems from the App-ID not being recognised, so no permit rule fires. Profile groups are tempting because they are configured alongside rules, and would be correct once traffic is allowed and needs inspection.
- B
The custom App-ID needs a vulnerability profile to be activated.
Why it fails: Vulnerability profiles act on traffic already permitted by a security policy; they cannot authorise a blocked session. The custom App-ID is failing to match, so the rule never permits the flow. Vulnerability profiles are tempting because they are attached to security rules, and would be correct if the traffic were permitted but needed threat inspection.
- C
The security policy rule uses the destination port instead of App-ID.
Why it fails: A rule matching destination port 8443 with application any would still permit the traffic, so it cannot explain the block. The likely cause is the custom App-ID not matching because the application signature is incomplete or the session is identified as incomplete. Port-based rules are tempting as a fallback, and would be correct when App-ID is unavailable.
- D
An application override rule must be configured to associate the custom App-ID with the traffic.
A custom App-ID alone cannot classify traffic that no existing decoder recognises. An application override rule binds the proprietary protocol on TCP port 8443 to the custom App-ID, so the firewall stops attempting signature-based identification and applies the correct security policy, satisfying the requirement to permit this trusted internal application.