- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
03-05-2026 08:03 AM
Hello,
Thanks
Satheesh
03-05-2026 09:21 AM
Hi @SatheeshAnirudhan ,
Kudos to you for trying L7 rules! That is the best practice. As you have found, this can be very challenging. The process that has worked very well for me is as follows:
I put these 3 rules in order in the security policy. The catch-all rule is used to identify the traffic that doesn't match the 1st 2 rules. You can (1) mouse over the catch-all rule and use Log Viewer or you can use (2) Apps Seen column hyperlink to the Policy Optimizer to determine which traffic is not hitting the 1st 2 rules. You modify rule 1 or 2 to include the new apps. Repeat the process until you do not have any more hits on rule 3.
Thanks,
Tom
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!

