DPI filters not being obeyed

DPI filters not being obeyed

DPI filters not being obeyed
DPI filters not being obeyed
2025-05-21 09:41:49 - last edited 2025-05-21 10:09:19
Model: OC400  
Hardware Version: V1
Firmware Version: 1.7.6 Build 20250507 Rel.54086

I have created 2 DPI Application Filter for my business network and from my tests I see that rules are not correctly followed.

 

DPI configuration:

 

First here is my DPI configuration. You can see all my VLANS area assined to 2 Application Filters.

 

 

The blocking filter: Personel_Filter

 

This is the default filter set for most VLANs on my network that filters the most of the stuff that doesn't belong company network and allows a related apps in Allowed_Class1, Allowed_Class2 and Allowed_Class3 rules etc.

 

 

The unrestricted filter: Yonetici_Filter

 

This filter only uses Allowed_Unrestricted_Class1 rule that allows all app traffic to pass through.

 

 

As you can see it flags all 2386 apps to QoS Class 1 which should allow the traffic.

 

My pc is set to VLAN that is assigned to the unrestricted filter: Yonetici_Filter

 

 

 

The problem

 

So basically I expect:

- All the PC and devices in other VLANs to get traffic blocked for apps like battlenet, steam, dropbox and discord.

- My PC that sits in specific VLAN (yonetici) with the unrestricted DPI filter (Yonetici_Filter) assigned should allow these apps.
 

In my tests though, I can see my own PCs traffic for apps like battlenet, steam, dropbox and discord is blocked.

 

 

When I click the details of the blocked apps, I can see my own PC is listed in details:

 

 

 

 

 

 

 

 

From my understanding rules from the restricting profile (Personel_Filter) is affecting my PC even though it should only be evaluated using Yonetici_Filter. Either I'm misconfiguring something here or there is a bug.

 

Any ideas?

 

@Vincent-TP  your help is welcome :)

  0      
  0      
#1
Options
9 Reply
Re:DPI filters not being obeyed
2025-05-21 10:15:23 - last edited 2025-05-21 11:07:38

1) For further testing I removed the Yonetici_Filter assigned to my privileged VLAN (yonetici) from the DPI assign restriction section. The apps I test (battlenet, steam, dropbox and discord) still does not work correctly.

 

2) I removed the filters from the blocking filter: Personel_Filter, and all the testing apps (battlenet, steam, dropbox and discord) started working on my PC, but my PC should not be affected by the blocking filter: Personel_Filter.

 

3) Further, the moment I disable the DPI all the apps start working again.

 

Is there a way to debug the filters that shows which filter rule blocked the app traffic for a specific user? So I can further trace the issue?

 

  0  
  0  
#2
Options
Re:DPI filters not being obeyed
2025-05-23 03:42:52

Hi  @Bonesoul 

 

During our local testing of the DPI feature, everything functioned as expected.

I believe this is most likely still a configuration issue.

 

To assist with troubleshooting, please verify the following configuration aspects:

  1. VLAN Consistency Check

    Ensure the PC's VLAN is the same as Yonetici_Filter. Your configuration screenshot obscured the subnet (via mosaicking). Private IPs are non-sensitive—no need for redaction.
  2. Client Functionality Validation

    Are other permitted APPs working normally on the PC?

 

 

You may refer to the config guide and configure it step by step again:

How to configure DPI on Omada Gateway via Omada Controller

  0  
  0  
#3
Options
Re:DPI filters not being obeyed
2025-05-23 10:13:44 - last edited 2025-05-23 11:16:01

  @Vincent-TP 

 

Hi there,

 

My pc vlan is actually correct, let me resend the screenshots:

 

First I renamed the VLAN's for you better to understand it:

 

this is the unrestricted VLAN (old name was yonetici)

 

and my PC is belongs to this VLAN

 

 

 

in DPI settings Unrestricted_Filter (old name was Yonetici_Filter) is assigned to unrestricted VLAN.

 

 

Unrestricted_Filter contains this rule: 

And Allowed_Unrestricted_Class1 enables traffic for apps like Battlenet, Steam, Discord, Dropbox etc (and all available defined apps):

 

 

With this configuration I expect Battlenet to work on my PC but it doesn't.

 

I further think that my PC in vlan unrestricted instead getting Full_Restriction_Filter applied (in first post it's name is Personal_Filter).

 

I can check this with this steps:

 

Every VLAN expect unrestricted VLAN is assigned with Full_Restriction_Filter

 

 

Full_Restriction_Filter contains all the blocking rules

 

 

The battlenet and steam is contained in Blocked_AppStore.

 

 

In this state Battlenet and Steam is blocked in my unrestricted vlan member pc (my own pc).

 

Once I remove the battlenet and steam from Full_Restriction_Filter's Blocked_AppStore rule, battlenet and steam starts to work on this PC.

 

So in summary: 

My own pc is set to unrestricted VLAN (100) and unrestricted VLAN uses Unrestricted_Filter. But my PCs apps are getting blocked by the Full_Restriction_Filter which should not be applied to my pc.

  0  
  0  
#4
Options
Re:DPI filters not being obeyed
2025-05-23 10:31:47 - last edited 2025-05-23 10:40:26

@Vincent-TP 

 

I suspect this should be related to that I have defined per-category rules:

 

I've a total of 29 per-category rules:

 

 

I think having this number of rules may be effecting my network?

 

Another test that pins the issue - incorrect rules are applied

 

I changed default vlan rule to Unrestricted_Filter and battlenet and steam starts working on my pc again.

 

 

So from my understanding for my PC that sits in unrestricted vlan (100), the default VLAN (1) DPI rules are applied incorrectly.

 

 

 

  0  
  0  
#5
Options
Re:DPI filters not being obeyed
2025-05-23 10:45:07

  @Vincent-TP 

 

> Client Functionality Validation

> Are other permitted APPs working normally on the PC?

 

Yes they are all working okay.

 

> You may refer to the config guide and configure it step by step again:

How to configure DPI on Omada Gateway via Omada Controller

 

I exactly followed this guide.

  0  
  0  
#7
Options
Re:DPI filters not being obeyed
2025-05-23 11:16:22 - last edited 2025-05-23 11:17:02

and here is my pc's ipconfig that shows it belongs to correct vlan:

 

 

vlan membership seems all good.

  0  
  0  
#8
Options
Re:DPI filters not being obeyed
2025-05-26 07:29:34

Hi  @Bonesoul 

 

Thanks for the reply.

Actually, DPI is a feature for Routers (ER8411), please start a new thread under Routers block to get more suggestions. 

  0  
  0  
#9
Options
Re:DPI filters not being obeyed
2025-05-26 08:32:45

I'm actually already using ER8411. Can't we move the thread to routers subforums? It'll be hard to repost every screenshot again.

 

 

  0  
  0  
#10
Options
Re:DPI filters not being obeyed
2025-05-26 14:38:36

okay recreated in router subforums as requested by @Vincent-TP  https://community.tp-link.com/en/business/forum/topic/818726

  0  
  0  
#11
Options