Full-stack NBAR support!

AI007
Meraki Employee

What is TA?
Traffic Analysis (TA) is a central feature of Meraki products that allows us to classify packet flows and use that classification in a variety of features. All of these features rely heavily on accurate traffic classification.
Traditional TA: 200+ IDs
NBAR: 1500+ IDs

What is NBAR?
Network-Based Application Recognition (NBAR) is an advanced application recognition engine developed by Cisco that utilizes several classification techniques and has the ability to easily update its classification rules. It supports 1,500+ applications and sub-classifications with less than 1% unknown and less than 1% unclassified encrypted traffic. Meraki platforms that support NBAR provide granular and enhanced capabilities in regard to client tracking and application enforcement.

 

Why is Meraki upgrading the traditional Traffic Analytics engine?
Given the exponential growth of IoT, mobile, and desktop applications as shown below, the existing 200+ IDs are proving difficult to maintain. The future of traffic classification is beyond static port numbers and protocols. Hence, NBAR provides global signatures for the current applications (less than 1% unknown).

Screen Shot 2021-03-09 at 12.36.19 PM.png

Source

 

What are the feature integrations? 
Application Tracking

  • Network-wide > Traffic analytics
  • Network-wide > Clients > Application details

Firewall rules

  • Security & SD-WAN > Firewall > Enforce Layer 7 deny rules
  • Wireless > Firewall and traffic shaping > Enforce Layer 7 deny rules

Traffic shaping rules

  • Security & SD-WAN > SD-WAN & traffic shaping > Traffic shaping rules > Enforce L7 traffic shaping policy
  • Wireless > Firewall and traffic shaping > Enforce L7 traffic shaping policy

SD-WAN policy

  • Security & SD-WAN > SD-WAN & traffic shaping > SD-WAN policies > VPN traffic > Enforce L7 SD-WAN policy

Group policy rules

  • Network-wide > Group policies > Layer 7 firewall > Enforce Layer 7 deny rules
  • Network-wide > Group policies > Traffic shaping > Enforce L7 traffic shaping policy

 

Are there future enhancements and integrations for the next-gen traffic analytics?

Yes, this is only the beginning. 

 

For more information regarding the NBAR integration, please refer to the following documentation:

https://documentation.meraki.com/General_Administration/Cross-Platform_Content/Network-Based_Applica...