NBAR - Shaping rules

RaphaelL
Kind of a big deal
Kind of a big deal

NBAR - Shaping rules

Hi ,

 

I have read the document : https://documentation.meraki.com/General_Administration/Cross-Platform_Content/Next-gen_Traffic_Anal...

 

 

My networks and templates are set to : Network-wide > Configure > General > Traffic analysis and set "Traffic analysis" to "Detailed: collect destination hostnames." 

 

However when I try to create a shaping rule , I still get the default choice reported by TA : 

RaphaelL_0-1739299772350.png

 

 

It looks like NBAR is not enabled or leveraged by my shaping rule.

 

I'm running the latest MX version.

10 Replies 10
ww
Kind of a big deal
Kind of a big deal

The picture is not for the traffic shaping section 

RaphaelL
Kind of a big deal
Kind of a big deal

indeed but same menu / result : 

RaphaelL_0-1739301163718.png

 

ww
Kind of a big deal
Kind of a big deal

That is strange.  It should be working for traffic shaping rules.  

For vpn traffic-policies its still not available afaik

RaphaelL
Kind of a big deal
Kind of a big deal

Oh really !? Bummer..

 

Also the menu/output is present for my L7 firewall rules which kinda suggest that NBAR is not enabled/running. 

 

I'm running MX 19.1.7.1 , MS 17.1.4 and MR30.7 which is pretty much the latest version in every category. Might open a ticket on that one.

ww
Kind of a big deal
Kind of a big deal

Maybe somehow related to an old network using the same template?

RaphaelL
Kind of a big deal
Kind of a big deal

That's what I thought at first. I created a brand-new template + network for the purpose of testing this. 

So there is only 1 network bound , still can't get it to work. Maybe I have some shaddy backend option preventing me from doing this. At this point I don't know 😥

PhilipDAth
Kind of a big deal
Kind of a big deal

It's not one of those features that don't work in templates is it?

RaphaelL
Kind of a big deal
Kind of a big deal

I hope not... 😓

tnco
Here to help


Hi @RaphaelL 

The documentation states that there are limitations when using configuration templates. Are the same things observed outside of template networks?

 

https://documentation.meraki.com/General_Administration/Cross-Platform_Content/Next-gen_Traffic_Anal...

RaphaelL
Kind of a big deal
Kind of a big deal

Templates, and networks bound to them, will have rulesets that are significantly more limited in terms of the classifications performed via NBAR. Due to technical limitations, the expanded NBAR rule set is not currently supported. Supported hardware and firmware versions are still required for this functionality.

 

Ahhhhh the MX. Love it.

*sarcasm*

 

NBAR works just fine in a template with SD-Internet policies , but doesn't work with anything else ☠️

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco ID. If you don't yet have a Cisco ID, you can sign up.
Labels