NBAR fail - we need to be able to add categories!

cmr
Kind of a big deal
Kind of a big deal

NBAR fail - we need to be able to add categories!

We have been upgrading our MXs to the 16.x release train to take advantage of the newer classification achieved using NBAR, however in our experience it seems worse as now ~90% of our traffic is classed as unknown.  At least before it would come up as Non-web TCP - [remote hostname] and be divided by the remote hostnames:

cmr_0-1631194328095.png

Here we can see two internal clients talking to one external host, however now, as seem below, this traffic and a load more is all lumped together...

cmr_1-1631194482907.png

 

Here we can see that almost all traffic is now unknown, you can see when we upgraded...

cmr_2-1631194697921.png

 

6 REPLIES 6
PhilipDAth
Kind of a big deal

Well, that sucks.

 

Does it make any difference if you change to "Security Appliance" clients?

cmr
Kind of a big deal
Kind of a big deal

I'd like to try that @PhilipDAth, but it is an MX only network...  However the Meraki support team are looking into it so hopefully it will improve soon 🤞

BlakeRichardson
Kind of a big deal

+1 on custom categories. I find MX is lacking behind the competition in this space. Content filtering on MX in general isn't very good IMO. 

 

We recently reivewed and rpelaced our firewall, and MX was one of the firewalls we reviewed but it lacks a decent content filtering system and reporting for use in education I found. 

 

 

Meraki CMNO, Ruckus WISE, Sonicwall CSSA, Allied Telesis CASE & CAI

What did you choose instead?

cmr
Kind of a big deal
Kind of a big deal

Well, since the last update we now have over 95% of traffic marked as unknown, progress of sorts!

 

cmr_0-1633040968940.png

 

Inderdeep
Kind of a big deal

@cmr : Well i saw similar issue for NBAR recognize apps in our Viptela SDWAN device. i think this is something NBAR database sync, Later it was resolved. 

Regards
Inderdeep Singh
www.thenetworkdna.com ( Awarded by Cisco IT Blogs award 2020)
Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels