Application Control

Application Control

HTTP/S traffic no longer consists of simple HTML websites. The Internet has become an important part of the modern world and provides a wide variety of different web-based applications. However, some of these applications are not business related and can have unwanted side effects, including:

  • Opening backdoors into your network

  • Distracting people from work

  • Consuming business-critical bandwidth

Application Control provides the application ruleset that lets you expand the scope of the firewall engine to include application type as a matching criteria. The addition of application context to the traditional stateful packet inspection capabilities of the CloudGen Firewall gives you full, context-aware control, even for SSL-encrypted traffic. Application Control comes with a set of predefined application objects that contain detection patterns to give you control over the latest web applications, web services, and social media. To give you more granular control, it also detects embedded features (or sub-applications) within applications. For example, you can create policies that permit the general usage of social networks (such as Facebook or Twitter), but forbid embedded applications (such as chat, image uploading, or posting). Application Control is fully integrated into the firewall service. Application traffic can be dropped, throttled, prioritized, or just reported.

Modern browsers may use HTTP2, SPDY, or the QUIC protocol on UDP 443 instead of HTTP or HTTPS.

Note that the CloudGen Firewall fully supports HTTP/2 data streams. The following firewall features now cover the HTTP/2 standard:

  • Application Control

  • URL filtering

  • Virus scanning

  • Content detection

  • Archive scanning

  • Google account control

  • Search string logging

  • Safe search

Note that ATP currently only supports "Deliver first, then scan" for HTTP/2.

However, if you want to use the SPDY or QUIC protocol on UDP 443, block UDP 443 on the firewall. The browsers will then automatically fall back to HTTP or HTTPS.

The applications patterns and definitions are stored in the application pattern database. The database is continuously updated through your Energize Updates subscription. You can also add your own custom applications.

Understanding Application Types

In Application Control, "application" refers to a traffic classification — identified by network endpoint (IP/port at Layer 3/4), HTTP host/URL pattern (Layer 7), or DPI protocol signature — not a reference to a specific executable on a host. Understanding how the firewall categorizes application traffic is useful when configuring Application Control across different firmware versions.

For more information, see Firmware Version dependent Behavior of Application Control.

 

Application Types and their Relationship

On the CloudGen Firewall, the following 4 categories for "apps" can be distinguished:

  1. Custom network apps (matched by Layer 3/4 attributes: protocol, IP address, and port range)

  2. Custom web apps (matched by hostname)

app_control_custom_application_object_types.png
  1. Built-in web apps

app_control_built_in_web_apps.png
  1. Pace2 apps (including protocols)

app_control_protocols.png

 

Executable binaries (e.g., .exe, javaClass, shell scripts) are handled at the file content type level by the DPI system.

app_control_exe_files.png

 

You can check all the preset groups of applications in their extended meaning at CONFIGURATION > Config Tree > Services > Firewall > Forwarding Firewall Rules > Firewall Objects > Applications, node Applications.

Application in these categories are identified by individual IDs stored in the application pattern database. Application Objects are user-defined collections of applications with custom Include and Exlude lists.

For more information on Application Objects, see How to Create an Application Object.

If you want to use a specific set beyond the combination of predefined applications, you can create a Custom Application Objects.

For more information on Custom Application Objects, see How to Create a Custom Application Object.

Firmware 10.5.0 contains important changes to the handling and behavior if Application Objects. See Firmware Version dependent Behavior of Application Control for details.

 

Application Ruleset and Application Control

Application Control uses a dedicated ruleset to detect and control application traffic. You can create application rules to drop, throttle, prioritize, or report detected applications and sub-applications. To detect the latest applications, traffic patterns are compared to predefined application objects containing detection patterns. You can also customize application definitions based on previously analyzed network traffic. To classify applications and threats, all application objects are categorized based on their properties, risk rating, bandwidth, and potential vulnerabilities. If Application Control and SSL Inspection is enabled in the Forwarding Firewall rule that handles the application traffic, the traffic is sent to the application ruleset and processed as follows:

  1. SSL-encrypted traffic is decrypted.

  2. Application rules are processed from top to bottom to determine if they match the traffic. If no rule matches, the default application policy is applied.

  3. If a matching application rule is found, the detected application is handled according to the rule settings. The application can be reported, or it can be restricted by time, bandwidth (QoS), user information, or content.

  4. SSL traffic is re-encrypted.

  5. The traffic is forwarded to its destination.

For more information, see How to Enable Application Control.

Application Control Features

TLS Inspection

TLS Inspection decrypts TLS connections, making encrypted traffic visible to Application Control features such as Virus Scanning, ATP, and sub-application detection. For example, you can permit general Facebook usage while blocking Facebook Chat. Without TLS Inspection, URL categorizationand application matching for HTTPS rely solely on the SNO from the TLS Client Hello; sub-application detection is not available. TLS Inspection also enforces TLS security by blocking outdated ciphers or rejecting using outdated TLS versions, and can handle TLS validation errors for outbound connections based on the TLS error policy of the matching access rule.

For more information, see TLS Inspection in the Firewall.

URL Filtering

Websites are categorized based on the Barracuda Web Filter URL category database. Depending on the policy assigned to the category, access can be allowed, blocked, or temporarily allowed. You can create an allow list (blocking everything except selected sites) or a block list (blocking known unwanted content). If a site is not in the database, a custom URL policy can be defined. The URL Filter operates on the domain level and does not control subdomains or sub-directories.

For more information, see URL Filtering in the Firewall.

Virus Scanning

Network traffic is transparently scanned for malicious content as it passes through the firewall. The Virus Scanner uses the Avira AV engine. If a user downloads a file containing malware, the firewall discards the infected file and redirects the user to a warning page. Scanning behavior and file types to scan are configurable.

For more information, see Virus Scanning and ATP in the Firewall.

Advanced Threat Protection (ATP)

ATP protects against zero-day exploits and other malware not recognized by the IPS or Virus Scanner. Two scanning policies are available: scan after download and quarantine the user if a threat is detected, or scan first and release to the user only once confirmed safe.

For more information, see Virus Scanning and ATP in the Firewall and Advanced Threat Protection (ATP).

File Content Scan

The firewall can filter transmitted files by file type, file name, or MIME type, giving administrators granular control over which files may traverse the firewall.

For more information, see File Content Filtering in the Firewall.

User Agent Filtering

User Agent policies control access to web resources based on the user agent string, enabling policies based on browser/OS combinations or custom patterns.

For more information, see User Agent Filtering in the Firewall.

Mail Security

The source IP address of incoming SMTP(S) connections is checked against a DNSBL; the email header and subject are modified if the sender is listed.

For more information, see Mail Security in the Firewall.

SafeSearch

Enforces SafeSearch on Google, Bing, Yahoo, YouTube, and DuckDuckGo.

For more information, see How to Enforce SafeSearch in the Firewall.

Google Accounts

Blocks all Google accounts (personal and Google Workspace) except those in allow-listed Google Workspace domains.

For more information, see How to Configure Google Accounts Filtering in the Firewall.

Application Control with HTTP Proxies

Application Control can be used in combination with HTTP(S) proxies. Depending on proxy configuration and type, sub-application detection may not be available.

For more information, see Using Application Control Features with HTTP(S) Proxies.


We value your feedback.
If you have questions, suggestions, or feedback on our documentation, contact the Campus Product Documentation team.
For general product inquiries or technical support, please contact the global Barracuda Support team.