For a deep packet inspection centralized data policy to take effect, you apply it to a list of sites in the overlay network.
To apply a centralized policy in Cisco vManage, see Configure Centralized Policy Using Cisco vManage.
To apply a centralized policy in the CLI:
vSmart(config)# apply-policy site-list list-name data-policy policy-name (all | from-service | from-tunnel)
By default, data policy applies to all data traffic passing through the Cisco vSmart Controller: the policy evaluates all data traffic going from the local site (that is, from the service side of the router) into the
tunnel interface, and it evaluates all traffic entering to the local site through the tunnel interface. You can explicitly
configure this behavior by including the all option. To have the data policy apply only to policy exiting from the local site, include the from-service option. To have the policy apply only to incoming traffic, include the from-tunnel option.
You cannot apply the same type of policy to site lists that contain overlapping site IDs. That is, all data policies cannot
have overlapping site lists among themselves. If you accidentally misconfigure overlapping site lists, the attempt to commit
the configuration on the Cisco vSmart Controller fails.
As soon as you successfully activate the configuration by issuing a commit command, the Cisco vSmart Controller pushes the data policy to the Cisco vEdge devices located in the specified sites. To view the policy as configured on the Cisco vSmart Controller, use the show running-config command on the Cisco vSmart Controller:
vSmart# show running-config policy
vSmart# show running-config apply-policy
To view the policy that has been pushed to the Cisco vEdge device, use the show policy from-vsmart command on the Cisco vEdge device.
vEdge# show policy from-vsmart
View DPI Applications Using Cisco vManage
You can view the list of all the application-aware applications supported by the Cisco SD-WAN software on the router using the following steps:
-
In Cisco vManage, select the screen.
-
From the WAN-Edge pane, select the Device that supports DPI. The Cisco vManage Control Connections page displays.
-
In the left pane, select Real Time to view the device details.
-
From the Device Options drop-down, choose DPI Applications to view the list of applications running on the device.
-
From the Device Options drop-down, choose DPI Supported Applications to view the list of applications that are supported on the device.