Hi, we have Policy Optimizer enabled and looking at the data there appears to be 'seen' apps that are not actually allowed by the rule:
I'm thinking someone edited the rule (from perhaps 'any' to 'sip') but cannot confirm in the logs (rule is also set to application-default). Can anyone otherwise explain this?
I'm not really up to speed about 9.0.X and policy optimizer functionality, thought it seems like the apps on the right were apps that have been seen at some point in the rule. I might be wrong, but can you post how the rule is constructed?
From looking at a FW rule I have that's running 9.0.X I see this. It's an Any-Any rule. On the right are the Apps it's seen, so I'm assuming the SIP app in your screenshot is either because it's allowed in the rule or because you've done something to "push it to the right."
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The Live Community thanks you for your participation!