Description | This article discusses the differences between parent and child signatures in SD-WAN application matching when using application groups and then outlines configuration strategies. |
Scope | FortiGate with SD-WAN. |
Solution |
Why SD‑WAN rules treat parent/child applications differently from Traffic Shaping:
Background:
Applications in App Control can be identified either at the parent or child level:
This distinction matters because Traffic Shaping and SD‑WAN rules handle parent/child matches in different ways.
Example Application Hierarchy:
Design Goal: Apply the following policies:
Traffic Shaping Behavior. Traffic shapers can evaluate child apps separately:
Traffic Shaping keeps child‑level granularity even if the parent is also present in the ruleset.
SD‑WAN Rule Behavior:
SD‑WAN classification works differently:
When the parent (Microsoft Teams) is matched, SD‑WAN does not try to identify children afterward.
Config Example:
Rule 1 – Teams Audio.
Rule 2 – Teams Video.
Rule 3 – Other Teams traffic.
Result of testing:
Key Takeaways:
|
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.