Administering Application Policies

This chapter contains the following sections:

Understanding the Categorize Applications Tab

The IWAN app operates with the Cisco NBAR2 Protocol Pack, which runs on routers within the IWAN network. NBAR2 categorizes network application traffic using the individual protocols in the Protocol Pack, in addition to any user-defined custom protocols. (“Protocols” define how NBAR2 categorizes a specific network application.) The IWAN app shows the applications defined by the NBAR2 Protocol Pack, grouped by application category.

The IWAN app 1.5.x releases operate with Protocol Pack 27.0.0 or 31.0.0. See the Protocol Pack documentation for details.

Use the Categorize Applications tab to view, edit, move, and add custom applications as shown in the following table:

 

Table 7-1 Categorize Applications Tab

No.
Task
Reference

1

View all of the installed applications in an alphabetized list or view the applications by category.

View a summary of all applications.

Search for a specific application.

Viewing Applications

2

Move applications into different categories.

Moving Applications to a Different Category

3

Edit application information.

Editing Application Information

4

Add new custom application to an existing category.

Adding a New Application

 

Deleting Cisco IWAN custom applications.

Deleting NBAR2 Custom Applications

note.gif

Noteblank.gif For a quick tutorial about what you can do on the Categorize Applications page, click Teach Me in the instructional text.


Tutorial Video

IWAN App Application Policy

Viewing Applications

Use this procedure to view applications by list, by category, or view a summary of all installed applications.

Procedure


Step 1blank.gif From the Cisco IWAN home page, click Administer Application Policy. The Application Policy page opens.

Step 2blank.gif Click the Categorize Applications tab. All of the installed applications are displayed in an alphabetized list.

Step 3blank.gif To view the applications by category, click the By Application Category / By Applications drop-down list, and select View By Application Category.

Not all categories are shown by default. To view all categories, click the Show link in the instructional text.

Step 4blank.gif To view all of the applications in a particular category, click the down arrow for a category.

Step 5blank.gif To view a summary of the total number of applications, popular applications, and custom applications, see the Applications Summary area.

Step 6blank.gif To search for a specific application, enter one of the following parameters in the Search field: application short name, long description, ports, traffic class.


 

Moving Applications to a Different Category

To share bandwidth, you can move the application into a different category.

Procedure


Step 1blank.gif From the Cisco IWAN home page, click Administer Application Policy. The Application Policy page opens.

Step 2blank.gif Click the Categorize Applications tab. All of the installed applications are displayed in an alphabetized list.

Step 3blank.gif To view all of the applications in a particular category, click the down arrow by a category.

Step 4blank.gif To move an application into a different category, drag-and-drop it into the appropriate category, and click Apply Changes.


 

Editing Application Information

Use this procedure to edit application information.

Procedure


Step 1blank.gif From the Cisco IWAN home page, click Administer Application Policy. The Application Policy page opens.

Step 2blank.gif Click the Categorize Applications tab. All of the installed applications are displayed in an alphabetized list.

Step 3blank.gif To view all of the applications in a particular category, click the down arrow for a category.

Step 4blank.gif To edit application information, click on the pencil icon next to the application. Information about the application appears.

Step 5blank.gif Click Edit. The Edit Application dialog box opens.

Step 6blank.gif Make your changes, and click Save.


 

Adding a New Application

Use this procedure to add a new custom application.

Procedure


Step 1blank.gif From the Cisco IWAN home page, click Administer Application Policy. The Application Policy page opens.

Step 2blank.gif Click the Categorize Applications tab. All of the installed applications are displayed in an alphabetized list.

Step 3blank.gif To add a new custom application, click the Add Application tab. The Add Application dialog box opens.

Step 4blank.gif Enter the following properties, and click Add :

 

Field
Description

Name

Name of the application.

Type

Options:

  • URL —Click the button, then enter the application URL in the URL field.
  • Server IP/Port —Click the button to display additional fields. Select a protocol option using the Protocol drop-down list, then, and then enter the IP, port, and protocol for the application to use.
  • DSCP —Differentiated services code point (DSCP). Click the button, then choose a value from the drop-down list.

Type

URL

Click the button, then enter the application URL in the URL field.

Server IP/Port

Click the button to display additional fields.

See Supported Server IP/Port Combinations.

DSCP

Differentiated services code point (DSCP). Click the button, then choose a value from the drop-down list.

Similar to

Click the field to display a list of available similar applications, and then choose an application.

Category

Choose a category from the drop-down list for the new application to reside.

Packet loss

(Optional) Specify a different value or keep the default value.

Delay

(Optional) Specify a different value or keep the default value.


 

Supported Server IP/Port Combinations

The following table provides examples of supported combinations for the Server IP/Port option.

 

Table 7-2 Example Combinations for Defining an Application

Combination
IP/Subnet field
(examples)
Protocol field
(examples)
Port/Range field
maximum 1000 ports in range
(examples)

IP address only

192.0.2.0

IP

 

Subnet only

192.0.2.0/16

IP

 

Port only

 

TCP

2000

Port range only

 

TCP

2001-3000

Subnet and port

192.0.2.0/16

TCP

2000

Subnet and port range

192.0.2.0/16

TCP

2001-3000

IP address and port range

192.0.2.0

TCP

2001-3000

Deleting NBAR2 Custom Applications

Use this procedure to delete NBAR2 custom applications.

Procedure


Step 1blank.gif From the Cisco IWAN home page, click Administer Application Policy. The Application Policy page opens.

Step 2blank.gif Click the Categorize Applications tab.

Step 3blank.gif To delete a custom application, do the following:

a.blank.gif In the left window, change the View By filter from Application Category to Applications.

b.blank.gif Click the Edit icon next to the application. The Edit Application dialog box opens.

c.blank.gif Click the Delete button in the Edit Application dialog box.

note.gif

Noteblank.gif The Delete button is available only for custom applications (not EasyQoS custom apps or default Protocol Pack applications).


d.blank.gif Click OK in the confirmation box. The application is removed from the user interface. (The deletion is finalized in a later step with the Apply Changes button.)

note.gif

Noteblank.gif If you change your mind, and do not want to delete the application, refresh the page. The application is restored with all of its configuration.


Step 4blank.gif To finalize the application deletion, click Apply Changes (top right corner).

note.gif

Noteblank.gif After you click Apply Changes, the application cannot be restored.


Step 5blank.gif To delete multiple applications at once, delete them from the user interface, and click Apply Changes. The Application Policy Summary page appears, listing all of the applications to be deleted.

Step 6blank.gif Review the information in the summary and then do one of the following:

  • Click the Apply Now radio button, and then click Continue.
  • Click the Schedule radio button, specify a date and time to delete the application, and then click Continue.


 

Understanding the Define Application Policies Tab

Use the Define Application Policy tab to define policies according to their relevance to the business.

Application Categories

Application policies are categorized as one of the following:

  • Business Relevant—Applications such as email, voice-and-video, file-sharing, backup-and-storage that are critical to the business.
  • Default—Applications such as epayement.
  • Business Irrelevant—Applications that are not relevant to the business such as social media and gaming applications.

Application Policy

Application policy defines the QoS and PfR policies for each of the application categories.

Cisco IWAN QoS defines how traffic egresses the network. It is critical that the classification, marking, and bandwidth allocations align to the service provider offering to ensure consistent QoS treatment end-to-end.

The IWAN app follows a 12-class model on the ingress to mark all incoming applications, and traffic ismarked again on the egress according to the service provider QoS profile attached to the WAN link.

note.gif

Noteblank.gif You can view the DSCP values and bandwidth allocated for each egress class, and edit the values in the service provider profiles through the Configure Hub Site and Settings > Service Providers tab.


To ensure proper QoS treatment, place the application categories in the right column. All categories placed in the Business Relevant column will be marked according to the traffic class for the corresponding applications. To view the traffic class for an application, open the Categorize Applications tab, then open the Category for the application, and click the edit button for the application. The following table shows how traffic classes map to specific DSCP values:

 

Table 7-3 Traffic Classes and DSCP Values

Traffic Class
DSCP Value

BROADCAST_VIDEO

CS5

BULK_DATA

AF11

INTERACTIVE_VIDEO

CS4

MULTIMEDIA_CONFERENCING

AF41

MULTIMEDIA_STREAMING

AF31

NETWORK_CONTROL

CS6

NETWORK_MANAGEMENT

CS2

SCAVENGER

CS1

SIGNALING

CS3

TRANSACTIONAL_DATA

AF21

VOIP_TELEPHONY

EF

All categories placed in Business Irrelevant are marked with a DSCP value of CS1, regardless of the traffic class attached to the application. Categories placed in the Default section keep their original incoming marking.

Optionally, set PfR path prioritization by enabling Application Performance for a category and selecting the Path Preference radio button. For each category, the WAN paths configured in the Service Providers tab (on the Configure Hub Site & Settings page) are shown in the category dropdown menu.

Optionally, Drop can be selected from the menu for the secondary path. If this option is selected, and the primary path goes out of policy, the PfR will drop the packets rather than failing over to the secondary path.

Optionally, multiple primary and secondary options can be selected. If the primary path goes out of policy, the SLA threshold for each application is monitored, and applications are dynamically moved to the secondary path.

To view or edit the SLA threshold values for an application, open the Categorize Applications tab, then open the Category for the application, and click the edit button for the application.

Operations in the Define Applications Tab

Use the Define Application Policy tab to do the following:

 

Table 7-4 Define Applications Tab

No.
Task
Reference

1

Move an application category to a different business group.

Understanding the Application Bandwidth Tab.

2

Modify application performance.

Modifying the Application Performance

Moving an Application Category to a Different Business Group

Use this procedure to move an application category to a different business group.

Procedure


Step 1blank.gif From the Cisco IWAN home page, click Administer Application Policy. The Application Policy page opens.

Step 2blank.gif Click the Define Application Policy tab. Applications are displayed in three categories: Business Relevant, Default, and Business Irrelevant.

Step 3blank.gif To move an application from one business group to another, use the drag-and-drop feature. For example, you can drag the epayment application from the Default group and drop it into the Business Irrelevant group.


 

Modifying the Application Performance

Use this procedure to modify the application performance parameters.

Procedure


Step 1blank.gif From the Cisco IWAN home page, click Administer Application Policy. The Application Policy page opens.

Step 2blank.gif Click the Define Application Policy tab. All of the applications are displayed in three categories: Business Relevant, Default, and Business Irrelevant.

Step 3blank.gif To modify the application performance, click the down arrow next to an application. The Application Performance dialog box opens as shown in the following figure.

 

366142.tif

Step 4blank.gif Do the following:

a.blank.gif Click the Application Performance button to enable or disable it.

b.blank.gif Choose the appropriate path preference radio button.

c.blank.gif Choose primary and secondary path from the drop-down list. The secondary path can be Drop.

Step 5blank.gif Select a path preference, with Path 1 being the preferred path for traffic in this category. For example, Int (Internet).

Step 6blank.gif After updating the path preference, click Save.

Note The Save option does not check for validations in conflict with future scheduled workflows. Please reevaluate scheduled jobs based on these changes and update scheduled jobs as required. If there is a conflict when the scheduled job is activated, it may fail at that time.


 

Understanding the Application Bandwidth Tab

Use the Application Bandwidth tab to view the bandwidth used across various applications. Based on this information you can choose to move applications into different categories. See Moving Applications to a Different Category.

Viewing the Application Bandwidth

Use this procedure to view the bandwidth used across different applications in a graphical format.

Before You Begin

Make sure you have done the following:

  • Added the Cisco APIC-EM controller IP address on the Prime application.
  • Added the Prime credentials in Cisco APIC-EM.

Procedure


Step 1blank.gif From the Cisco IWAN home page, click Administer Application Policy. The Application Policy page opens.

Step 2blank.gif Click the Application Bandwidth tab. The amount of bandwidth used per application category for each hub is displayed in a graphical format. You can also view the date and time the bandwidth is used the most.