Hi, and welcome to our forums.
While other correctly pointed out this cannot be tagged as custom application; what you could do, in order to manipulate traffic from particular XXX vlan, is to create a .XXX sub-interface on the layer3 interface where trunked and tagged traffic is arriving, and add it to a separate new zone, than create traffic policies (whatever you need, blocking, allowing, alerting...) applied for that particular zone.
I believe my understanding is correct - you have trunk on some interface and some of the traffic is tagged, you wanted to manipulate it in a particular way (so you wanted to create a custom app) - this way, you will see all the traffic, and you can still create a custom app just based on the ports or the port ranges of the layer 4, without furhter complication.
Am I right and does this help? If not, can you try to explain what are you trying to achieve - perhaps we can solve it in a different way.
Best regards
Luciano
... View more