App-Dictionary
These scenarios check the application dictionary support provided by app-detect feature.
Local Storage Application Dictionary
Description
DUT0 configures HTTP and DNS detection. DUT1 acts as a client behind DUT0 and DUT2 runs a DNS server. Traffic is first generated without a dictionary and connections are verified to be classified only by below-L7 detectors. Then a local dictionary file is loaded and statistics are checked to be empty. An HTTP download verifies FQDN match with local dictionary and performs IP-cache population. A second download verifies IP-cache match. An SSH connection verifies static IP address range match. Finally a DNS lookup and ping verify DNS-host detection with IP-cache lookup.
Scenario
Step 1: Set the following configuration in DUT0 :
set interfaces ethernet eth0 address 10.215.168.64/24 set interfaces ethernet eth0 traffic nat source rule 1 address masquerade set interfaces ethernet eth1 address 192.168.2.100/24 set system conntrack app-detect dns-host set system conntrack app-detect http-host set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
Step 2: Set the following configuration in DUT1 :
set interfaces ethernet eth1 address 192.168.2.101/24 set protocols static route 0.0.0.0/0 next-hop 192.168.2.100 set service dns forwarding name-server 10.215.168.66 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
Step 3: Set the following configuration in DUT2 :
set interfaces ethernet eth0 address 10.215.168.66/24 set service dns forwarding local-ttl 30 set service dns forwarding name-server 127.0.0.1 set service dns static host-name enterprise.opentok.com inet 10.215.168.1 set service dns static host-name static.opentok.com inet 192.168.2.100 set service dns static host-name www.gamblingteldat.com inet 192.168.2.10 set service dns static host-name www.newspaperteldat.com inet 192.168.2.20 set service ssh set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
Step 4: Ping the IP address 10.215.168.1 from DUT1:
admin@DUT1$ ping 10.215.168.1 count 1 size 56 timeout 1Show output
PING 10.215.168.1 (10.215.168.1) 56(84) bytes of data. 64 bytes from 10.215.168.1: icmp_seq=1 ttl=63 time=2.02 ms --- 10.215.168.1 ping statistics --- 1 packets transmitted, 1 received, 0% packet loss, time 0ms rtt min/avg/max/mdev = 2.023/2.023/2.023/0.000 ms
Step 5: Run the command file copy http://10.215.168.1/~robot/test_file running://user-data/ force on DUT0 and expect the following output:
Show output
% Total % Received % Xferd Average Speed Time Time Time Current Dload Upload Total Spent Left Speed 100 38 100 38 0 0 5869 0 --:--:-- --:--:-- --:--:-- 6333
Step 6: Initiate an SSH connection from DUT0 to IP address 10.215.168.66 using user admin:
admin@DUT0$ ssh admin@10.215.168.66 option StrictHostKeyChecking=no option UserKnownHostsFile=/dev/nullShow output
Warning: Permanently added '10.215.168.66' (ECDSA) to the list of known hosts. admin@10.215.168.66's password: Welcome to Teldat OSDx v4.2.10.4 This system includes free software. Contact Teldat for licenses information and source code. Last login: Wed Sep 16 20:10:15 2026 from 192.168.100.2 admin@osdx$
Step 7: Ping the IP address 10.215.168.64 from DUT1:
admin@DUT1$ ping 10.215.168.64 count 1 size 56 timeout 1Show output
PING 10.215.168.64 (10.215.168.64) 56(84) bytes of data. 64 bytes from 10.215.168.64: icmp_seq=1 ttl=64 time=0.707 ms --- 10.215.168.64 ping statistics --- 1 packets transmitted, 1 received, 0% packet loss, time 0ms rtt min/avg/max/mdev = 0.707/0.707/0.707/0.000 ms
Step 8: Run the command system conntrack show on DUT0 and expect the following output:
Show output
icmp 1 29 src=192.168.2.101 dst=10.215.168.1 type=8 code=0 id=746 packets=1 bytes=84 src=10.215.168.1 dst=10.215.168.64 type=0 code=0 id=746 packets=1 bytes=84 mark=0 use=1 appdetect[L3:1] icmp 1 29 src=192.168.2.101 dst=10.215.168.64 type=8 code=0 id=747 packets=1 bytes=84 src=10.215.168.64 dst=192.168.2.101 type=0 code=0 id=747 packets=1 bytes=84 mark=0 use=1 appdetect[L3:1] tcp 6 19 TIME_WAIT src=10.215.168.64 dst=10.215.168.1 sport=47272 dport=80 packets=6 bytes=583 src=10.215.168.1 dst=10.215.168.64 sport=80 dport=47272 packets=4 bytes=505 [ASSURED] mark=0 use=1 appdetect[L4:80 http-host:10.215.168.1] tcp 6 19 TIME_WAIT src=10.215.168.64 dst=10.215.168.66 sport=58446 dport=22 packets=24 bytes=5057 src=10.215.168.66 dst=10.215.168.64 sport=22 dport=58446 packets=21 bytes=4917 [ASSURED] mark=0 use=1 appdetect[L4:22] conntrack v1.4.7 (conntrack-tools): 4 flow entries have been shown.
Step 9: Run the command file copy http://10.215.168.1/~robot/test_dict.gz running://user-data/ force on DUT0 and expect the following output:
Show output
% Total % Received % Xferd Average Speed Time Time Time Current Dload Upload Total Spent Left Speed 100 68181 100 68181 0 0 10.1M 0 --:--:-- --:--:-- --:--:-- 10.8M
Note
The dictionary file contains the following test entries used in this scenario:
Show output
<app id="30" name="Teldat Test" version="1"> <fqdn_list> <fqdn>10.215.168.1</fqdn> </fqdn_list> </app> <app id="31" name="Teldat Test 2" version="1"> <address_list> <range id="1"> <net_address>10.215.168.64</net_address> <net_mask>255.255.255.192</net_mask> </range> </address_list> </app>
Step 10: Modify the following configuration lines in DUT0 :
set system conntrack app-detect dictionary 1 filename 'running://user-data/test_dict.gz' set system conntrack app-detect enable_dict_match_priv_ip
Step 11: Run the command system conntrack app-detect show on DUT0 and expect the following output:
Show output
--------------------------------------------------- App-detect Stats # --------------------------------------------------- Matches in static dictionaries 0 Matches in IP-cache 0 Modifications in IP-cache 0 Matches in dynamic dictionaries 0 Times appid has been refreshed 0 Ips blacklisted from cache due to appid flapping 0 Matches in DNS CNAME cache 0 Entries in DNS CNAME cache 0
Step 12: Run the command system conntrack clear on DUT0.
Step 13: Run the command file copy http://10.215.168.1/~robot/test_file running://user-data/ force on DUT0 and expect the following output:
Show output
% Total % Received % Xferd Average Speed Time Time Time Current Dload Upload Total Spent Left Speed 100 38 100 38 0 0 6639 0 --:--:-- --:--:-- --:--:-- 7600
Step 14: Run the command system conntrack show on DUT0 and check whether the output matches the following regular expressions:
appdetect\[U128:30\shttp-host:10.215.168.1\]Show output
tcp 6 19 TIME_WAIT src=10.215.168.64 dst=10.215.168.1 sport=40070 dport=80 packets=6 bytes=583 src=10.215.168.1 dst=10.215.168.64 sport=80 dport=40070 packets=4 bytes=505 [ASSURED] mark=0 use=1 appdetect[U128:30 http-host:10.215.168.1] conntrack v1.4.7 (conntrack-tools): 1 flow entries have been shown.
Step 15: Run the command system conntrack app-detect show on DUT0 and expect the following output:
Show output
--------------------------------------------------- App-detect Stats # --------------------------------------------------- Matches in static dictionaries 0 Matches in IP-cache 0 Modifications in IP-cache 1 Matches in dynamic dictionaries 1 Times appid has been refreshed 0 Ips blacklisted from cache due to appid flapping 0 Matches in DNS CNAME cache 0 Entries in DNS CNAME cache 0
Step 16: Run the command file copy http://10.215.168.1/~robot/test_file running://user-data/ force on DUT0 and expect the following output:
Show output
% Total % Received % Xferd Average Speed Time Time Time Current Dload Upload Total Spent Left Speed 100 38 100 38 0 0 7526 0 --:--:-- --:--:-- --:--:-- 7600
Step 17: Run the command system conntrack app-detect show on DUT0 and expect the following output:
Show output
--------------------------------------------------- App-detect Stats # --------------------------------------------------- Matches in static dictionaries 0 Matches in IP-cache 1 Modifications in IP-cache 1 Matches in dynamic dictionaries 2 Times appid has been refreshed 0 Ips blacklisted from cache due to appid flapping 0 Matches in DNS CNAME cache 0 Entries in DNS CNAME cache 0
Step 18: Initiate an SSH connection from DUT0 to IP address 10.215.168.66 using user admin:
admin@DUT0$ ssh admin@10.215.168.66 option StrictHostKeyChecking=no option UserKnownHostsFile=/dev/nullShow output
Warning: Permanently added '10.215.168.66' (ECDSA) to the list of known hosts. admin@10.215.168.66's password: Welcome to Teldat OSDx v4.2.10.4 This system includes free software. Contact Teldat for licenses information and source code. Last login: Wed Sep 16 20:12:05 2026 from 10.215.168.64 admin@osdx$
Step 19: Run the command system conntrack show on DUT0 and check whether the output matches the following regular expressions:
src=10.215.168.64\sdst=10.215.168.66.*appdetect\[U128:31]Show output
tcp 6 19 TIME_WAIT src=10.215.168.64 dst=10.215.168.66 sport=57586 dport=22 packets=24 bytes=5057 src=10.215.168.66 dst=10.215.168.64 sport=22 dport=57586 packets=21 bytes=4881 [ASSURED] mark=0 use=1 appdetect[U128:31] tcp 6 18 TIME_WAIT src=10.215.168.64 dst=10.215.168.1 sport=40070 dport=80 packets=6 bytes=583 src=10.215.168.1 dst=10.215.168.64 sport=80 dport=40070 packets=4 bytes=505 [ASSURED] mark=0 use=1 appdetect[U128:30 http-host:10.215.168.1] tcp 6 19 TIME_WAIT src=10.215.168.64 dst=10.215.168.1 sport=40080 dport=80 packets=6 bytes=583 src=10.215.168.1 dst=10.215.168.64 sport=80 dport=40080 packets=4 bytes=505 [ASSURED] mark=0 use=1 appdetect[U128:30 http-host:10.215.168.1] conntrack v1.4.7 (conntrack-tools): 3 flow entries have been shown.
Step 20: Run the command system conntrack app-detect show on DUT0 and expect the following output:
Show output
--------------------------------------------------- App-detect Stats # --------------------------------------------------- Matches in static dictionaries 1 Matches in IP-cache 1 Modifications in IP-cache 1 Matches in dynamic dictionaries 2 Times appid has been refreshed 0 Ips blacklisted from cache due to appid flapping 0 Matches in DNS CNAME cache 0 Entries in DNS CNAME cache 0
Step 21: Ping the IP address static.opentok.com from DUT1:
admin@DUT1$ ping static.opentok.com count 1 size 56 timeout 1Show output
PING static.opentok.com (192.168.2.100) 56(84) bytes of data. 64 bytes from static.opentok.com (192.168.2.100): icmp_seq=1 ttl=64 time=0.547 ms --- static.opentok.com ping statistics --- 1 packets transmitted, 1 received, 0% packet loss, time 0ms rtt min/avg/max/mdev = 0.547/0.547/0.547/0.000 ms
Step 22: Run the command system conntrack show on DUT0 and expect the following output:
Show output
tcp 6 19 TIME_WAIT src=10.215.168.64 dst=10.215.168.66 sport=57586 dport=22 packets=24 bytes=5057 src=10.215.168.66 dst=10.215.168.64 sport=22 dport=57586 packets=21 bytes=4881 [ASSURED] mark=0 use=1 appdetect[U128:31] udp 17 29 src=192.168.2.101 dst=10.215.168.66 sport=46201 dport=53 packets=1 bytes=64 src=10.215.168.66 dst=10.215.168.64 sport=53 dport=46201 packets=1 bytes=80 mark=0 use=1 appdetect[U128:31 dns-host:static.opentok.com] tcp 6 18 TIME_WAIT src=10.215.168.64 dst=10.215.168.1 sport=40070 dport=80 packets=6 bytes=583 src=10.215.168.1 dst=10.215.168.64 sport=80 dport=40070 packets=4 bytes=505 [ASSURED] mark=0 use=1 appdetect[U128:30 http-host:10.215.168.1] udp 17 29 src=192.168.2.101 dst=10.215.168.66 sport=51375 dport=53 packets=1 bytes=72 src=10.215.168.66 dst=10.215.168.64 sport=53 dport=51375 packets=1 bytes=104 mark=0 use=1 appdetect[U128:31] icmp 1 29 src=192.168.2.101 dst=192.168.2.100 type=8 code=0 id=748 packets=1 bytes=84 src=192.168.2.100 dst=192.168.2.101 type=0 code=0 id=748 packets=1 bytes=84 mark=0 use=1 appdetect[U128:12] udp 17 29 src=192.168.2.101 dst=10.215.168.66 sport=43588 dport=53 packets=1 bytes=64 src=10.215.168.66 dst=10.215.168.64 sport=53 dport=43588 packets=1 bytes=64 mark=0 use=1 appdetect[U128:31] tcp 6 19 TIME_WAIT src=10.215.168.64 dst=10.215.168.1 sport=40080 dport=80 packets=6 bytes=583 src=10.215.168.1 dst=10.215.168.64 sport=80 dport=40080 packets=4 bytes=505 [ASSURED] mark=0 use=1 appdetect[U128:30 http-host:10.215.168.1] conntrack v1.4.7 (conntrack-tools): 7 flow entries have been shown.
Step 23: Run the command system conntrack app-detect show on DUT0 and expect the following output:
Show output
--------------------------------------------------- App-detect Stats # --------------------------------------------------- Matches in static dictionaries 4 Matches in IP-cache 2 Modifications in IP-cache 2 Matches in dynamic dictionaries 3 Times appid has been refreshed 0 Ips blacklisted from cache due to appid flapping 0 Matches in DNS CNAME cache 0 Entries in DNS CNAME cache 0
CLI Custom Application Dictionary
Description
DUT0 configures HTTP detection with a custom dictionary defined via CLI. DUT1 acts as a client behind DUT0 and downloads a file via HTTP. The connection is verified to be classified with the custom App-ID on the first request through FQDN match, and on subsequent requests through IP-cache.
Scenario
Step 1: Set the following configuration in DUT0 :
set interfaces ethernet eth0 address 10.215.168.64/24 set interfaces ethernet eth0 traffic nat source rule 1 address masquerade set interfaces ethernet eth1 address 192.168.2.100/24 set system conntrack app-detect dictionary 1 local app-id custom 42 fqdn enterprise.opentok.com set system conntrack app-detect dictionary 1 local app-id custom 42 name 'Teldat Test' set system conntrack app-detect dictionary 2 local app-id custom 43 fqdn enterprise.opentok.com set system conntrack app-detect dictionary 2 local app-id custom 43 name 'Teldat Test' set system conntrack app-detect http-host set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
Step 2: Set the following configuration in DUT1 :
set interfaces ethernet eth1 address 192.168.2.101/24 set protocols static route 0.0.0.0/0 next-hop 192.168.2.100 set service dns forwarding name-server 10.215.168.66 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
Step 3: Set the following configuration in DUT2 :
set interfaces ethernet eth0 address 10.215.168.66/24 set service dns forwarding local-ttl 30 set service dns forwarding name-server 127.0.0.1 set service dns static host-name enterprise.opentok.com inet 10.215.168.1 set service dns static host-name static.opentok.com inet 192.168.2.100 set service dns static host-name www.gamblingteldat.com inet 192.168.2.10 set service dns static host-name www.newspaperteldat.com inet 192.168.2.20 set service ssh set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
Step 4: Ping the IP address 10.215.168.1 from DUT1:
admin@DUT1$ ping 10.215.168.1 count 1 size 56 timeout 1Show output
PING 10.215.168.1 (10.215.168.1) 56(84) bytes of data. 64 bytes from 10.215.168.1: icmp_seq=1 ttl=63 time=0.748 ms --- 10.215.168.1 ping statistics --- 1 packets transmitted, 1 received, 0% packet loss, time 0ms rtt min/avg/max/mdev = 0.748/0.748/0.748/0.000 ms
Step 5: Run the command system conntrack clear on DUT0.
Step 6: Run the command system conntrack app-detect show on DUT0 and expect the following output:
Show output
--------------------------------------------------- App-detect Stats # --------------------------------------------------- Matches in static dictionaries 0 Matches in IP-cache 0 Modifications in IP-cache 0 Matches in dynamic dictionaries 0 Times appid has been refreshed 0 Ips blacklisted from cache due to appid flapping 0 Matches in DNS CNAME cache 0 Entries in DNS CNAME cache 0
Step 7: Run the command system conntrack clear on DUT0.
Step 8: Run the command file copy http://enterprise.opentok.com/~robot/test_file running://user-data/ force on DUT1 and expect the following output:
Show output
% Total % Received % Xferd Average Speed Time Time Time Current Dload Upload Total Spent Left Speed 100 38 100 38 0 0 5313 0 --:--:-- --:--:-- --:--:-- 5428
Step 9: Run the command system conntrack show on DUT0 and check whether the output matches the following regular expressions:
appdetect\[U6:42\shttp-host:enterprise.opentok.com\]Show output
udp 17 29 src=192.168.2.101 dst=10.215.168.66 sport=37912 dport=53 packets=1 bytes=68 src=10.215.168.66 dst=10.215.168.64 sport=53 dport=37912 packets=1 bytes=84 mark=0 use=1 appdetect[L4:53] udp 17 29 src=192.168.2.101 dst=10.215.168.66 sport=55812 dport=53 packets=1 bytes=68 src=10.215.168.66 dst=10.215.168.64 sport=53 dport=55812 packets=1 bytes=68 mark=0 use=1 appdetect[L4:53] tcp 6 src=192.168.2.101 dst=10.215.168.1 sport=53990 dport=80 packets=6 bytes=593 src=10.215.168.1 dst=10.215.168.64 sport=80 dport=53990 packets=4 bytes=505 [ASSURED] [OFFLOAD, packets=1 bytes=52 packets=2 bytes=393] mark=0 use=3 appdetect[U6:42 http-host:enterprise.opentok.com] conntrack v1.4.7 (conntrack-tools): 3 flow entries have been shown.
Step 10: Run the command system conntrack app-detect show on DUT0 and expect the following output:
Show output
--------------------------------------------------- App-detect Stats # --------------------------------------------------- Matches in static dictionaries 0 Matches in IP-cache 0 Modifications in IP-cache 1 Matches in dynamic dictionaries 1 Times appid has been refreshed 0 Ips blacklisted from cache due to appid flapping 0 Matches in DNS CNAME cache 0 Entries in DNS CNAME cache 0
Step 11: Run the command file copy http://enterprise.opentok.com/~robot/test_file running://user-data/ force on DUT1 and expect the following output:
Show output
% Total % Received % Xferd Average Speed Time Time Time Current Dload Upload Total Spent Left Speed 100 38 100 38 0 0 7520 0 --:--:-- --:--:-- --:--:-- 9500
Step 12: Run the command system conntrack app-detect show on DUT0 and expect the following output:
Show output
--------------------------------------------------- App-detect Stats # --------------------------------------------------- Matches in static dictionaries 0 Matches in IP-cache 1 Modifications in IP-cache 1 Matches in dynamic dictionaries 2 Times appid has been refreshed 0 Ips blacklisted from cache due to appid flapping 0 Matches in DNS CNAME cache 0 Entries in DNS CNAME cache 0
Remote Application Dictionary
Description
DUT0 configures HTTP detection with a remote application dictionary served by a categorization server. DUT1 acts as a client behind DUT0 and DUT2 runs a DNS server. A traffic policy drops uncategorized traffic until the remote dictionary classifies it. Traffic belonging to the remote dictionary protocol is allowed.
Phase 1: HTTP-host detection triggers a remote dictionary lookup in override mode and the connection is classified with the remote App-ID.
Phase 2: DNS-host detection is added so classification happens at DNS resolution time and populates the IP-cache.
Phase 3: App-detect chained storage mode is enabled and the full App-ID chain is verified.
Phase 4: An alarm is configured to detect communication errors with the remote dictionary server.
Scenario
Step 1: Set the following configuration in DUT0 :
set interfaces ethernet eth0 address 10.215.168.64/24 set interfaces ethernet eth0 traffic nat source rule 1 address masquerade set interfaces ethernet eth0 traffic policy out POL set interfaces ethernet eth1 address 192.168.2.100/24 set system conntrack app-detect debug set system conntrack app-detect dictionary 1 remote encrypted-key U2FsdGVkX18jsHtVKCymP2EREyezWSXVXMIF6Ct4tBk= set system conntrack app-detect dictionary 1 remote encrypted-url U2FsdGVkX18rWq3OEpWenrNhaAxBNJLhWbR264JuNAos9Uwcn8m+SMLvxXFYl+/B set system conntrack app-detect dictionary 1 remote mark 5555 set system conntrack app-detect dictionary 1 remote property category set system conntrack app-detect dictionary 1 remote ssl-allow-insecure set system conntrack app-detect dictionary 2 remote encrypted-key U2FsdGVkX18UkVJR9qsgLKZwzE+MhpXG3dGRhFs83Jo= set system conntrack app-detect dictionary 2 remote encrypted-url U2FsdGVkX1+7rl8SALRmxjZlN2/2nbXE+EWzIJ4ynfu9fyB2YOVCuHNeJpNmMNSa set system conntrack app-detect dictionary 2 remote mark 5555 set system conntrack app-detect dictionary 2 remote property reputation set system conntrack app-detect dictionary 2 remote ssl-allow-insecure set system conntrack app-detect enable_dict_match_priv_ip set system conntrack app-detect http set system conntrack app-detect http-host set system conntrack app-detect refresh-flow-appid set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy POL rule 1 action accept set traffic policy POL rule 1 selector RDICT set traffic policy POL rule 2 action drop set traffic policy POL rule 2 selector RESOLVING set traffic selector RDICT rule 1 mark 5555 set traffic selector RESOLVING rule 1 app-detect state detecting set traffic selector RESOLVING rule 1 app-detect state host-detected
Step 2: Set the following configuration in DUT1 :
set interfaces ethernet eth1 address 192.168.2.101/24 set protocols static route 0.0.0.0/0 next-hop 192.168.2.100 set service dns forwarding name-server 10.215.168.66 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
Step 3: Set the following configuration in DUT2 :
set interfaces ethernet eth0 address 10.215.168.66/24 set service dns forwarding local-ttl 30 set service dns forwarding name-server 127.0.0.1 set service dns static host-name enterprise.opentok.com inet 10.215.168.1 set service dns static host-name static.opentok.com inet 192.168.2.100 set service dns static host-name www.gamblingteldat.com inet 192.168.2.10 set service dns static host-name www.newspaperteldat.com inet 192.168.2.20 set service ssh set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
Step 4: Ping the IP address 10.215.168.1 from DUT1:
admin@DUT1$ ping 10.215.168.1 count 1 size 56 timeout 1Show output
PING 10.215.168.1 (10.215.168.1) 56(84) bytes of data. 64 bytes from 10.215.168.1: icmp_seq=1 ttl=63 time=0.568 ms --- 10.215.168.1 ping statistics --- 1 packets transmitted, 1 received, 0% packet loss, time 0ms rtt min/avg/max/mdev = 0.568/0.568/0.568/0.000 ms
Step 5: Run the command system conntrack clear on DUT0.
Step 6: Run the command file copy http://enterprise.opentok.com/~robot/test_file running://user-data/ force on DUT1, press Ctrl+C after 2 seconds and expect the following output:
Show output
% Total % Received % Xferd Average Speed Time Time Time Current Dload Upload Total Spent Left Speed 0 0 0 0 0 0 0 0 --:--:-- 0:00:01 --:--:-- 0^C Operation aborted by user. admin@osdx$
Step 7: Run the command system journal show | tail -n 200 on DUT0 and expect the following output:
Show output
Sep 16 20:13:37.000050 osdx systemd[1]: Started systemd-timedated.service - Time & Date Service. Sep 16 20:13:37.000193 osdx systemd-timedated[169369]: Changed local time to Wed 2026-09-16 20:13:37 UTC Sep 16 20:13:37.000860 osdx systemd-journald[2158]: Time jumped backwards, rotating. Sep 16 20:13:37.001795 osdx OSDxCLI[157302]: User 'admin' executed a new command: 'set date 2026-09-16 20:13:37'. Sep 16 20:13:37.330554 osdx systemd-journald[2158]: Runtime Journal (/run/log/journal/7ab9d0c6c88d486ab30f6cca192546c5) is 1.9M, max 13.8M, 11.8M free. Sep 16 20:13:37.332529 osdx systemd-journald[2158]: Received client request to rotate journal, rotating. Sep 16 20:13:37.332606 osdx systemd-journald[2158]: Vacuuming done, freed 0B of archived journals from /run/log/journal/7ab9d0c6c88d486ab30f6cca192546c5. Sep 16 20:13:37.342234 osdx OSDxCLI[157302]: User 'admin' executed a new command: 'system journal clear'. Sep 16 20:13:37.572114 osdx OSDxCLI[157302]: User 'admin' executed a new command: 'system coredump delete all'. Sep 16 20:13:37.795009 osdx OSDxCLI[157302]: User 'admin' entered the configuration menu. Sep 16 20:13:37.875122 osdx OSDxCLI[157302]: User 'admin' added a new cfg line: 'set interfaces ethernet eth1 address 192.168.2.100/24'. Sep 16 20:13:37.951633 osdx OSDxCLI[157302]: User 'admin' added a new cfg line: 'set interfaces ethernet eth0 address 10.215.168.64/24'. Sep 16 20:13:38.013871 osdx OSDxCLI[157302]: User 'admin' added a new cfg line: 'set interfaces ethernet eth0 traffic nat source rule 1 address masquerade'. Sep 16 20:13:38.102077 osdx OSDxCLI[157302]: User 'admin' added a new cfg line: 'set interfaces ethernet eth0 traffic policy out POL'. Sep 16 20:13:38.156005 osdx OSDxCLI[157302]: User 'admin' added a new cfg line: 'set traffic policy POL rule 1 action accept'. Sep 16 20:13:38.247682 osdx OSDxCLI[157302]: User 'admin' added a new cfg line: 'set traffic policy POL rule 1 selector RDICT'. Sep 16 20:13:38.302000 osdx OSDxCLI[157302]: User 'admin' added a new cfg line: 'set traffic policy POL rule 2 action drop'. Sep 16 20:13:38.396237 osdx OSDxCLI[157302]: User 'admin' added a new cfg line: 'set traffic policy POL rule 2 selector RESOLVING'. Sep 16 20:13:38.451785 osdx OSDxCLI[157302]: User 'admin' added a new cfg line: 'set traffic selector RDICT rule 1 mark 5555'. Sep 16 20:13:38.558221 osdx OSDxCLI[157302]: User 'admin' added a new cfg line: 'set traffic selector RESOLVING rule 1 app-detect state detecting'. Sep 16 20:13:38.636556 osdx OSDxCLI[157302]: User 'admin' added a new cfg line: 'set traffic selector RESOLVING rule 1 app-detect state host-detected'. Sep 16 20:13:38.759938 osdx OSDxCLI[157302]: User 'admin' added a new cfg line: 'set system conntrack app-detect dictionary 1 remote url ******'. Sep 16 20:13:38.824363 osdx OSDxCLI[157302]: User 'admin' added a new cfg line: 'set system conntrack app-detect dictionary 1 remote key ******'. Sep 16 20:13:38.913428 osdx OSDxCLI[157302]: User 'admin' added a new cfg line: 'set system conntrack app-detect dictionary 1 remote ssl-allow-insecure'. Sep 16 20:13:38.975872 osdx OSDxCLI[157302]: User 'admin' added a new cfg line: 'set system conntrack app-detect dictionary 1 remote property category'. Sep 16 20:13:39.094240 osdx OSDxCLI[157302]: User 'admin' added a new cfg line: 'set system conntrack app-detect dictionary 2 remote url ******'. Sep 16 20:13:39.166148 osdx OSDxCLI[157302]: User 'admin' added a new cfg line: 'set system conntrack app-detect dictionary 2 remote key ******'. Sep 16 20:13:39.244614 osdx OSDxCLI[157302]: User 'admin' added a new cfg line: 'set system conntrack app-detect dictionary 2 remote ssl-allow-insecure'. Sep 16 20:13:39.298938 osdx OSDxCLI[157302]: User 'admin' added a new cfg line: 'set system conntrack app-detect dictionary 2 remote property reputation'. Sep 16 20:13:39.395061 osdx OSDxCLI[157302]: User 'admin' added a new cfg line: 'set system conntrack app-detect dictionary 1 remote mark 5555'. Sep 16 20:13:39.448978 osdx OSDxCLI[157302]: User 'admin' added a new cfg line: 'set system conntrack app-detect dictionary 2 remote mark 5555'. Sep 16 20:13:39.533143 osdx OSDxCLI[157302]: User 'admin' added a new cfg line: 'set system conntrack app-detect http'. Sep 16 20:13:39.584632 osdx OSDxCLI[157302]: User 'admin' added a new cfg line: 'set system conntrack app-detect http-host'. Sep 16 20:13:39.680815 osdx OSDxCLI[157302]: User 'admin' added a new cfg line: 'set system conntrack app-detect refresh-flow-appid'. Sep 16 20:13:39.753813 osdx OSDxCLI[157302]: User 'admin' added a new cfg line: 'set system conntrack app-detect enable_dict_match_priv_ip'. Sep 16 20:13:39.869813 osdx OSDxCLI[157302]: User 'admin' added a new cfg line: 'set system conntrack app-detect debug'. Sep 16 20:13:39.944045 osdx OSDxCLI[157302]: User 'admin' added a new cfg line: 'show working'. Sep 16 20:13:40.065992 osdx ubnt-cfgd[169431]: inactive Sep 16 20:13:40.140493 osdx INFO[169476]: FRR daemons did not change Sep 16 20:13:40.248554 osdx kernel: nfUDPlink: module init Sep 16 20:13:40.252531 osdx kernel: app-detect: module init Sep 16 20:13:40.252574 osdx kernel: app-detect: registered: sysctl net.appdetect Sep 16 20:13:40.252583 osdx kernel: nfUDPlink: connected 127.0.0.1:49000 Sep 16 20:13:40.252591 osdx kernel: nfUDPlink: added destination 127.0.0.1:49000 Sep 16 20:13:40.252599 osdx kernel: app-detect: registered: /proc/net/stat/appdetect Sep 16 20:13:40.252610 osdx kernel: app-detect: expression init Sep 16 20:13:40.252618 osdx kernel: app-detect: appid cache initialized (override=yes, chained=yes) Sep 16 20:13:40.252625 osdx kernel: app-detect: cache changes counter set appid_changes_count found (klen=4, dlen=4) Sep 16 20:13:40.256535 osdx kernel: app-detect: selected hash dict hash table with 13 hash bits and 8192 buckets for max 5000 entries (supported range 2^8...2^20) Sep 16 20:13:40.256582 osdx kernel: app-detect: allocated memory for hash table with 8192 buckets (65536 bytes) Sep 16 20:13:40.256592 osdx kernel: app-detect: allocated memory for 5000 hash entries (520000 bytes) Sep 16 20:13:40.256599 osdx kernel: app-detect: CNAME database reallocated to 5000 entries Sep 16 20:13:40.268536 osdx kernel: app-detect: set target dict _remote_ priority 1 type unknown (new,empty) Sep 16 20:13:40.268589 osdx kernel: app-detect: linked list of enabled dicts: Sep 16 20:13:40.268606 osdx kernel: app-detect: (empty, no dicts) Sep 16 20:13:40.268615 osdx kernel: app-detect: linked list of disabled dicts: Sep 16 20:13:40.268623 osdx kernel: app-detect: (0) dictionary _remote_, priority 1 type unknown (target_dict) Sep 16 20:13:40.268632 osdx kernel: app-detect: initialized expiration timer for REMOTE dict _remote_ Sep 16 20:13:40.268642 osdx kernel: app-detect: set type of dict _remote_ to remote Sep 16 20:13:40.268649 osdx kernel: app-detect: user set num_hash_entries=40000 Sep 16 20:13:40.268657 osdx kernel: app-detect: selected hash dict hash table with 16 hash bits and 65536 buckets for max 40000 entries (supported range 2^8...2^20) Sep 16 20:13:40.268669 osdx kernel: app-detect: allocated memory for hash table with 65536 buckets (524288 bytes) Sep 16 20:13:40.268676 osdx kernel: app-detect: allocated memory for 40000 hash entries (4160000 bytes) Sep 16 20:13:40.268684 osdx kernel: app-detect: set dictionary _remote_ hash_key d46225f3cb7730441efc28f7ad6acf2604ffe1719e801afac8457b3bf45deec3 Sep 16 20:13:40.268693 osdx kernel: app-detect: enable remote dictionary _remote_ Sep 16 20:13:40.268703 osdx kernel: app-detect: dictionary _remote_ enabled Sep 16 20:13:40.268712 osdx kernel: app-detect: linked list of enabled dicts: Sep 16 20:13:40.268719 osdx kernel: app-detect: (0) dictionary _remote_, priority 1 type remote (target_dict) Sep 16 20:13:40.268726 osdx kernel: app-detect: linked list of disabled dicts: Sep 16 20:13:40.268733 osdx kernel: app-detect: (empty, no dicts) Sep 16 20:13:40.268740 osdx kernel: app-detect: set target dict _remote_ priority 2 type unknown (new,empty) Sep 16 20:13:40.268748 osdx kernel: app-detect: linked list of enabled dicts: Sep 16 20:13:40.268755 osdx kernel: app-detect: (0) dictionary _remote_, priority 1 type remote Sep 16 20:13:40.268762 osdx kernel: app-detect: linked list of disabled dicts: Sep 16 20:13:40.268769 osdx kernel: app-detect: (0) dictionary _remote_, priority 2 type unknown (target_dict) Sep 16 20:13:40.268777 osdx kernel: app-detect: initialized expiration timer for REMOTE dict _remote_ Sep 16 20:13:40.268784 osdx kernel: app-detect: set type of dict _remote_ to remote Sep 16 20:13:40.268791 osdx kernel: app-detect: user set num_hash_entries=40000 Sep 16 20:13:40.268799 osdx kernel: app-detect: selected hash dict hash table with 16 hash bits and 65536 buckets for max 40000 entries (supported range 2^8...2^20) Sep 16 20:13:40.268808 osdx kernel: app-detect: allocated memory for hash table with 65536 buckets (524288 bytes) Sep 16 20:13:40.268817 osdx kernel: app-detect: allocated memory for 40000 hash entries (4160000 bytes) Sep 16 20:13:40.268826 osdx kernel: app-detect: set dictionary _remote_ hash_key d46225f3cb7730441efc28f7ad6acf2604ffe1719e801afac8457b3bf45deec3 Sep 16 20:13:40.268841 osdx kernel: app-detect: enable remote dictionary _remote_ Sep 16 20:13:40.268850 osdx kernel: app-detect: dictionary _remote_ enabled Sep 16 20:13:40.268857 osdx kernel: app-detect: linked list of enabled dicts: Sep 16 20:13:40.268864 osdx kernel: app-detect: (0) dictionary _remote_, priority 1 type remote Sep 16 20:13:40.268871 osdx kernel: app-detect: (1) dictionary _remote_, priority 2 type remote (target_dict) Sep 16 20:13:40.268878 osdx kernel: app-detect: linked list of disabled dicts: Sep 16 20:13:40.268885 osdx kernel: app-detect: (empty, no dicts) Sep 16 20:13:40.277445 osdx INFO[169513]: Updated /etc/default/osdx_tcatd.conf Sep 16 20:13:40.277493 osdx INFO[169513]: Restarting Traffic Categorization (TCATD) service ... Sep 16 20:13:40.320918 osdx systemd[1]: Starting osdx-tcatd.service - App-Detect Traffic Categorization daemon... Sep 16 20:13:40.619964 osdx systemd[1]: Started osdx-tcatd.service - App-Detect Traffic Categorization daemon. Sep 16 20:13:40.621193 osdx osdx-tcatd[169517]: Dict_client. rdict_num 2 mark 5555 local-vrf Sep 16 20:13:40.621301 osdx osdx-tcatd[169517]: Dict_client. ERROR (dict 2) 7 (Couldn't connect to server): Unable to connect to server Sep 16 20:13:40.621387 osdx osdx-tcatd[169517]: Dict_client. rdict_num 1 mark 5555 local-vrf Sep 16 20:13:40.621426 osdx osdx-tcatd[169517]: Dict_client. ERROR (dict 1) 7 (Couldn't connect to server): Unable to connect to server Sep 16 20:13:40.656525 osdx kernel: 8021q: adding VLAN 0 to HW filter on device eth0 Sep 16 20:13:40.699731 osdx WARNING[169609]: No supported link modes on interface eth0 Sep 16 20:13:40.701120 osdx modulelauncher[169609]: osdx.utils.xos cmd error: /sbin/ethtool -A eth0 autoneg on Sep 16 20:13:40.701132 osdx modulelauncher[169609]: Command '/sbin/ethtool -A eth0 autoneg on' returned non-zero exit status 76. Sep 16 20:13:40.702284 osdx modulelauncher[169609]: osdx.utils.xos cmd error: /sbin/ethtool -s eth0 autoneg on advertise Pause off Asym_Pause off -- Sep 16 20:13:40.702292 osdx modulelauncher[169609]: Command '/sbin/ethtool -s eth0 autoneg on advertise Pause off Asym_Pause off --' returned non-zero exit status 75. Sep 16 20:13:40.732535 osdx kernel: 8021q: adding VLAN 0 to HW filter on device eth1 Sep 16 20:13:40.773639 osdx WARNING[169684]: No supported link modes on interface eth1 Sep 16 20:13:40.775010 osdx modulelauncher[169684]: osdx.utils.xos cmd error: /sbin/ethtool -A eth1 autoneg on Sep 16 20:13:40.775021 osdx modulelauncher[169684]: Command '/sbin/ethtool -A eth1 autoneg on' returned non-zero exit status 76. Sep 16 20:13:40.776203 osdx modulelauncher[169684]: osdx.utils.xos cmd error: /sbin/ethtool -s eth1 autoneg on advertise Pause off Asym_Pause off -- Sep 16 20:13:40.776210 osdx modulelauncher[169684]: Command '/sbin/ethtool -s eth1 autoneg on advertise Pause off Asym_Pause off --' returned non-zero exit status 75. Sep 16 20:13:41.162246 osdx cfgd[1899]: [157302]Completed change to active configuration Sep 16 20:13:41.162890 osdx OSDxCLI[157302]: User 'admin' committed the configuration. Sep 16 20:13:41.191186 osdx OSDxCLI[157302]: User 'admin' left the configuration menu. Sep 16 20:13:44.059098 osdx OSDxCLI[157302]: User 'admin' executed a new command: 'system conntrack clear'. Sep 16 20:13:44.210035 osdx kernel: app-detect: field http-host detected: enterprise.opentok.com. Org(src/dst) 192.168.2.101:33082/10.215.168.1:80 Sep 16 20:13:44.210100 osdx kernel: app-detect: http detected. Org(src/dst) 192.168.2.101:33082/10.215.168.1:80 Sep 16 20:13:44.210110 osdx kernel: app-detect: dictionary search for enterprise.opentok.com Sep 16 20:13:44.210119 osdx kernel: app-detect: search in dict _remote_, prio 1 Sep 16 20:13:44.210129 osdx kernel: app-detect: search in dict _remote_, prio 2 Sep 16 20:13:44.210092 osdx osdx-tcatd[169517]: UDP_Server. Read 27 bytes Sep 16 20:13:44.210095 osdx osdx-tcatd[169517]: UDP_Server. Kernel_Message parse. Read message addressed to dictionary 1 FQDN enterprise.opentok.com Sep 16 20:13:44.210112 osdx osdx-tcatd[169517]: Dict_client. Send query (dict 1): {"requestid": "besafepro_request_id","oemid": "Teldat","deviceid": "develop","uid": "","queries": ["getinfo", "getrepinfo"],"fqdns": ["enterprise.opentok.com"],"xml": 0} Sep 16 20:13:44.210123 osdx osdx-tcatd[169517]: UDP_Server. Read 27 bytes Sep 16 20:13:44.210125 osdx osdx-tcatd[169517]: UDP_Server. Kernel_Message parse. Read message addressed to dictionary 2 FQDN enterprise.opentok.com Sep 16 20:13:44.210137 osdx osdx-tcatd[169517]: Dict_client. Send query (dict 2): {"requestid": "besafepro_request_id","oemid": "Teldat","deviceid": "develop","uid": "","queries": ["getinfo", "getrepinfo"],"fqdns": ["enterprise.opentok.com"],"xml": 0} Sep 16 20:13:44.220992 osdx osdx-tcatd[169517]: Dict_client. Received answer (dict 1): {"status": 200, "requestid": "besafepro_request_id", "type": "fqdns", "TTL": 172800, "results": [{"fqdns": "enterprise.opentok.com", "queries": {"getinfo": {"a1cat": 0, "reputation": 88, "lcp": "opentok.com", "cats": [{"catid": 7, "conf": 95}]}, "getrepinfo": {"reputation": 88, "country": "", "popularity": 0, "a ge": 0, "threathistory": 0}}}]} Sep 16 20:13:44.221009 osdx osdx-tcatd[169517]: UDP_Server. Kernel_Message format. Write message addressed to dictionary 1 FQDN enterprise.opentok.com TTL 172800 AppID:82000007 Sep 16 20:13:44.221258 osdx osdx-tcatd[169517]: UDP_Server. Sent 38 bytes Sep 16 20:13:44.222023 osdx osdx-tcatd[169517]: Dict_client. Received answer (dict 2): {"status": 200, "requestid": "besafepro_request_id", "type": "fqdns", "TTL": 172800, "results": [{"fqdns": "enterprise.opentok.com", "queries": {"getinfo": {"a1cat": 0, "reputation": 88, "lcp": "opentok.com", "cats": [{"catid": 7, "conf": 95}]}, "getrepinfo": {"reputation": 88, "country": "", "popularity": 0, "a ge": 0, "threathistory": 0}}}]} Sep 16 20:13:44.222035 osdx osdx-tcatd[169517]: UDP_Server. Kernel_Message format. Write message addressed to dictionary 2 FQDN enterprise.opentok.com TTL 172800 AppID:83000058 Sep 16 20:13:44.222072 osdx osdx-tcatd[169517]: UDP_Server. Sent 38 bytes Sep 16 20:13:44.224528 osdx kernel: app-detect: set target dict _remote_ priority 1 type remote (existing,enabled) Sep 16 20:13:44.224555 osdx kernel: app-detect: linked list of enabled dicts: Sep 16 20:13:44.224563 osdx kernel: app-detect: (0) dictionary _remote_, priority 1 type remote (target_dict) Sep 16 20:13:44.224571 osdx kernel: app-detect: (1) dictionary _remote_, priority 2 type remote Sep 16 20:13:44.224578 osdx kernel: app-detect: linked list of disabled dicts: Sep 16 20:13:44.224586 osdx kernel: app-detect: (empty, no dicts) Sep 16 20:13:44.224593 osdx kernel: app-detect: set fqdn hash 46b26ca475a30e2c2b54f5356b2738abe73ead8a02742c712c9e645e233e9d74, hash table index=0018098 (0x046b2) (16 bits), ttl 172800 seconds Sep 16 20:13:44.224601 osdx kernel: app-detect: set target dict _remote_ priority 2 type remote (existing,enabled) Sep 16 20:13:44.224609 osdx kernel: app-detect: linked list of enabled dicts: Sep 16 20:13:44.224616 osdx kernel: app-detect: (0) dictionary _remote_, priority 1 type remote Sep 16 20:13:44.224626 osdx kernel: app-detect: (1) dictionary _remote_, priority 2 type remote (target_dict) Sep 16 20:13:44.224633 osdx kernel: app-detect: linked list of disabled dicts: Sep 16 20:13:44.224640 osdx kernel: app-detect: (empty, no dicts) Sep 16 20:13:44.224653 osdx kernel: app-detect: set fqdn hash 46b26ca475a30e2c2b54f5356b2738abe73ead8a02742c712c9e645e233e9d74, hash table index=0018098 (0x046b2) (16 bits), ttl 172800 seconds
Step 8: Run the command system conntrack show on DUT0 and check whether the output matches the following regular expressions:
tcp.*dst=10.215.168.1.*dport=443Show output
tcp 6 3597 ESTABLISHED src=10.215.168.64 dst=10.215.168.1 sport=52604 dport=443 packets=11 bytes=1659 src=10.215.168.1 dst=10.215.168.64 sport=443 dport=52604 packets=10 bytes=3462 [ASSURED] mark=0 use=1 appdetect[L4:443] tcp 6 3597 ESTABLISHED src=10.215.168.64 dst=10.215.168.1 sport=52602 dport=443 packets=11 bytes=1659 src=10.215.168.1 dst=10.215.168.64 sport=443 dport=52602 packets=10 bytes=3462 [ASSURED] mark=0 use=1 appdetect[L4:443] tcp 6 299 ESTABLISHED src=192.168.2.101 dst=10.215.168.1 sport=33082 dport=80 packets=7 bytes=1737 src=10.215.168.1 dst=10.215.168.64 sport=80 dport=33082 packets=1 bytes=60 [ASSURED] mark=0 use=1 appdetect[L4:80 http-host:enterprise.opentok.com] udp 17 27 src=127.0.0.1 dst=127.0.0.1 sport=41838 dport=49000 packets=2 bytes=110 src=127.0.0.1 dst=127.0.0.1 sport=49000 dport=41838 packets=2 bytes=132 mark=0 use=1 appdetect[L4:49000] udp 17 27 src=192.168.2.101 dst=10.215.168.66 sport=59866 dport=53 packets=1 bytes=68 src=10.215.168.66 dst=10.215.168.64 sport=53 dport=59866 packets=1 bytes=68 mark=0 use=1 appdetect[L4:53] udp 17 27 src=192.168.2.101 dst=10.215.168.66 sport=46116 dport=53 packets=1 bytes=68 src=10.215.168.66 dst=10.215.168.64 sport=53 dport=46116 packets=1 bytes=84 mark=0 use=1 appdetect[L4:53] conntrack v1.4.7 (conntrack-tools): 6 flow entries have been shown.
Step 9: Run the command traffic selector RDICT show on DUT0 and check whether the output matches the following regular expressions:
1\s+[1-9]\d*\s+\d+Show output
Selector RDICT (Policy POL -- ifc eth0 -- hook out prio very-high -- rule 1) ----------------------------------------------------- rule pkts match pkts eval bytes match bytes eval ----------------------------------------------------- 1 22 40 3318 6139 ----------------------------------------------------- Total 22 40 3318 6139
Step 10: Run the command system conntrack show on DUT0 and check whether the output matches the following regular expressions:
tcp.*dport=80.*packets=[1-9].*appdetect\[L4:80\shttp-host:enterprise.opentok.com\]Show output
tcp 6 3597 ESTABLISHED src=10.215.168.64 dst=10.215.168.1 sport=52604 dport=443 packets=11 bytes=1659 src=10.215.168.1 dst=10.215.168.64 sport=443 dport=52604 packets=10 bytes=3462 [ASSURED] mark=0 use=1 appdetect[L4:443] tcp 6 3597 ESTABLISHED src=10.215.168.64 dst=10.215.168.1 sport=52602 dport=443 packets=11 bytes=1659 src=10.215.168.1 dst=10.215.168.64 sport=443 dport=52602 packets=10 bytes=3462 [ASSURED] mark=0 use=1 appdetect[L4:443] tcp 6 299 ESTABLISHED src=192.168.2.101 dst=10.215.168.1 sport=33082 dport=80 packets=7 bytes=1737 src=10.215.168.1 dst=10.215.168.64 sport=80 dport=33082 packets=1 bytes=60 [ASSURED] mark=0 use=1 appdetect[L4:80 http-host:enterprise.opentok.com] udp 17 27 src=127.0.0.1 dst=127.0.0.1 sport=41838 dport=49000 packets=2 bytes=110 src=127.0.0.1 dst=127.0.0.1 sport=49000 dport=41838 packets=2 bytes=132 mark=0 use=1 appdetect[L4:49000] udp 17 27 src=192.168.2.101 dst=10.215.168.66 sport=59866 dport=53 packets=1 bytes=68 src=10.215.168.66 dst=10.215.168.64 sport=53 dport=59866 packets=1 bytes=68 mark=0 use=1 appdetect[L4:53] udp 17 27 src=192.168.2.101 dst=10.215.168.66 sport=46116 dport=53 packets=1 bytes=68 src=10.215.168.66 dst=10.215.168.64 sport=53 dport=46116 packets=1 bytes=84 mark=0 use=1 appdetect[L4:53] conntrack v1.4.7 (conntrack-tools): 6 flow entries have been shown.
Step 11: Run the command system conntrack clear on DUT1.
Step 12: Run the command file copy http://enterprise.opentok.com/~robot/test_file running://user-data/ force on DUT1, press Ctrl+C after 2 seconds and expect the following output:
Show output
% Total % Received % Xferd Average Speed Time Time Time Current Dload Upload Total Spent Left Speed 100 38 100 38 0 0 5204 0 --:--:-- --:--:-- --:--:-- 4750 admin@osdx$
Step 13: Run the command system conntrack show on DUT0 and check whether the output matches the following regular expressions:
appdetect\[U130:7\shttp-host:enterprise.opentok.com\]Show output
tcp 6 3595 ESTABLISHED src=10.215.168.64 dst=10.215.168.1 sport=52604 dport=443 packets=11 bytes=1659 src=10.215.168.1 dst=10.215.168.64 sport=443 dport=52604 packets=10 bytes=3462 [ASSURED] mark=0 use=1 appdetect[L4:443] tcp 6 3595 ESTABLISHED src=10.215.168.64 dst=10.215.168.1 sport=52602 dport=443 packets=11 bytes=1659 src=10.215.168.1 dst=10.215.168.64 sport=443 dport=52602 packets=10 bytes=3462 [ASSURED] mark=0 use=1 appdetect[L4:443] udp 17 28 src=192.168.2.101 dst=10.215.168.66 sport=43096 dport=53 packets=1 bytes=68 src=10.215.168.66 dst=10.215.168.64 sport=53 dport=43096 packets=1 bytes=68 mark=0 use=1 appdetect[L4:53] tcp 6 298 ESTABLISHED src=192.168.2.101 dst=10.215.168.1 sport=33082 dport=80 packets=8 bytes=2062 src=10.215.168.1 dst=10.215.168.64 sport=80 dport=33082 packets=1 bytes=60 [ASSURED] mark=0 use=1 appdetect[L4:80 http-host:enterprise.opentok.com] udp 17 25 src=127.0.0.1 dst=127.0.0.1 sport=41838 dport=49000 packets=2 bytes=110 src=127.0.0.1 dst=127.0.0.1 sport=49000 dport=41838 packets=2 bytes=132 mark=0 use=1 appdetect[L4:49000] udp 17 25 src=192.168.2.101 dst=10.215.168.66 sport=59866 dport=53 packets=1 bytes=68 src=10.215.168.66 dst=10.215.168.64 sport=53 dport=59866 packets=1 bytes=68 mark=0 use=1 appdetect[L4:53] udp 17 25 src=192.168.2.101 dst=10.215.168.66 sport=46116 dport=53 packets=1 bytes=68 src=10.215.168.66 dst=10.215.168.64 sport=53 dport=46116 packets=1 bytes=84 mark=0 use=1 appdetect[L4:53] tcp 6 src=192.168.2.101 dst=10.215.168.1 sport=33384 dport=80 packets=6 bytes=593 src=10.215.168.1 dst=10.215.168.64 sport=80 dport=33384 packets=4 bytes=505 [ASSURED] [OFFLOAD, packets=1 bytes=52 packets=2 bytes=393] mark=0 use=2 appdetect[U130:7 http-host:enterprise.opentok.com] conntrack v1.4.7 (conntrack-tools): 8 flow entries have been shown.
Step 14: Run the command system conntrack app-detect show ip-cache on DUT0 and check whether the output matches the following regular expressions:
10.215.168.1\s*.*U130:7Show output
---------------------------------------- IP Application ID Expires in ---------------------------------------- 10.215.168.1 U130:7 4m57s920ms
Step 15: Run the command system conntrack app-detect show on DUT0 and expect the following output:
Show output
--------------------------------------------------- App-detect Stats # --------------------------------------------------- Matches in static dictionaries 0 Matches in IP-cache 0 Modifications in IP-cache 1 Matches in dynamic dictionaries 1 Times appid has been refreshed 0 Ips blacklisted from cache due to appid flapping 0 Matches in DNS CNAME cache 0 Entries in DNS CNAME cache 0
Step 16: Run the command system conntrack clear on DUT0.
Step 17: Run the command system conntrack clear on DUT1.
Step 18: Run the command file copy http://enterprise.opentok.com/~robot/test_file running://user-data/ force on DUT1 and expect the following output:
Show output
% Total % Received % Xferd Average Speed Time Time Time Current Dload Upload Total Spent Left Speed 100 38 100 38 0 0 5137 0 --:--:-- --:--:-- --:--:-- 5428
Step 19: Run the command system conntrack show on DUT0 and check whether the output matches the following regular expressions:
appdetect\[U130:7\shttp-host:enterprise.opentok.com\]Show output
udp 17 29 src=192.168.2.101 dst=10.215.168.66 sport=36790 dport=53 packets=1 bytes=68 src=10.215.168.66 dst=10.215.168.64 sport=53 dport=36790 packets=1 bytes=68 mark=0 use=1 appdetect[L4:53] tcp 6 src=192.168.2.101 dst=10.215.168.1 sport=33388 dport=80 packets=6 bytes=593 src=10.215.168.1 dst=10.215.168.64 sport=80 dport=33388 packets=4 bytes=505 [ASSURED] [OFFLOAD, packets=1 bytes=52 packets=2 bytes=393] mark=0 use=3 appdetect[U130:7 http-host:enterprise.opentok.com] conntrack v1.4.7 (conntrack-tools): 2 flow entries have been shown.
Step 20: Run the command system conntrack app-detect show on DUT0 and expect the following output:
Show output
--------------------------------------------------- App-detect Stats # --------------------------------------------------- Matches in static dictionaries 0 Matches in IP-cache 1 Modifications in IP-cache 1 Matches in dynamic dictionaries 2 Times appid has been refreshed 0 Ips blacklisted from cache due to appid flapping 0 Matches in DNS CNAME cache 0 Entries in DNS CNAME cache 0
Step 21: Set the following configuration in DUT0 :
set interfaces ethernet eth0 address 10.215.168.64/24 set interfaces ethernet eth0 traffic nat source rule 1 address masquerade set interfaces ethernet eth0 traffic policy out POL set interfaces ethernet eth1 address 192.168.2.100/24 set system conntrack app-detect app-id-storage override set system conntrack app-detect debug set system conntrack app-detect dictionary 1 remote encrypted-key U2FsdGVkX18fR2xJaS9FBW+N+IqVUNa6iKkR0o+KfYw= set system conntrack app-detect dictionary 1 remote encrypted-url U2FsdGVkX190jo9cGghtb1C7MVePGpyn4+VwyIrVOfUIz90hrXJtl/ZLS7MkO/nR set system conntrack app-detect dictionary 1 remote mark 5555 set system conntrack app-detect dictionary 1 remote property category set system conntrack app-detect dictionary 1 remote ssl-allow-insecure set system conntrack app-detect dictionary 2 remote encrypted-key U2FsdGVkX1+Uh9WsU3Xlc6aIhToa/+Jvafb1DR9NnO0= set system conntrack app-detect dictionary 2 remote encrypted-url U2FsdGVkX19u8byapk7TFxP4DHvQl7p8fdgFnXF5wbpS9t34FE63kzuF+DyhGt5l set system conntrack app-detect dictionary 2 remote mark 5555 set system conntrack app-detect dictionary 2 remote property reputation set system conntrack app-detect dictionary 2 remote ssl-allow-insecure set system conntrack app-detect dns set system conntrack app-detect dns-host set system conntrack app-detect enable_dict_match_priv_ip set system conntrack app-detect http set system conntrack app-detect http-host set system conntrack app-detect refresh-flow-appid set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy POL rule 1 action accept set traffic policy POL rule 1 selector RDICT set traffic policy POL rule 2 action drop set traffic policy POL rule 2 selector RESOLVING set traffic selector RDICT rule 1 mark 5555 set traffic selector RESOLVING rule 1 app-detect state detecting set traffic selector RESOLVING rule 1 app-detect state host-detected
Step 22: Run the command system conntrack clear on DUT0.
Step 23: Run the command nslookup enterprise.opentok.com dns-server 10.215.168.66 on DUT1 and expect the following output:
Show output
Server: 10.215.168.66 Address: 10.215.168.66#53 Name: enterprise.opentok.com Address: 10.215.168.1 ** server can't find enterprise.opentok.com: REFUSED
Step 24: Run the command nslookup www.gamblingteldat.com dns-server 10.215.168.66 on DUT1 and expect the following output:
Show output
Server: 10.215.168.66 Address: 10.215.168.66#53 Name: www.gamblingteldat.com Address: 192.168.2.10 ** server can't find www.gamblingteldat.com: REFUSED
Step 25: Run the command nslookup www.newspaperteldat.com dns-server 10.215.168.66 on DUT1 and expect the following output:
Show output
Server: 10.215.168.66 Address: 10.215.168.66#53 Name: www.newspaperteldat.com Address: 192.168.2.20 ** server can't find www.newspaperteldat.com: REFUSED
Step 26: Run the command system conntrack show on DUT0 and expect the following output:
Show output
udp 17 29 src=192.168.2.101 dst=10.215.168.66 sport=56311 dport=53 packets=1 bytes=68 src=10.215.168.66 dst=10.215.168.64 sport=53 dport=56311 packets=1 bytes=84 mark=0 use=1 appdetect[L4:53 dns-host:enterprise.opentok.com] tcp 6 299 ESTABLISHED src=10.215.168.64 dst=10.215.168.1 sport=46398 dport=443 packets=12 bytes=1501 src=10.215.168.1 dst=10.215.168.64 sport=443 dport=46398 packets=9 bytes=2042 [ASSURED] mark=0 use=1 appdetect[L4:443] tcp 6 299 ESTABLISHED src=10.215.168.64 dst=10.215.168.1 sport=46408 dport=443 packets=9 bytes=1345 src=10.215.168.1 dst=10.215.168.64 sport=443 dport=46408 packets=8 bytes=1990 [ASSURED] mark=0 use=1 appdetect[L4:443] udp 17 29 src=192.168.2.101 dst=10.215.168.66 sport=33411 dport=53 packets=1 bytes=68 src=10.215.168.66 dst=10.215.168.64 sport=53 dport=33411 packets=1 bytes=84 mark=0 use=1 appdetect[L4:53 dns-host:www.gamblingteldat.com] udp 17 29 src=192.168.2.101 dst=10.215.168.66 sport=55211 dport=53 packets=1 bytes=68 src=10.215.168.66 dst=10.215.168.64 sport=53 dport=55211 packets=1 bytes=68 mark=0 use=1 appdetect[L4:53] udp 17 29 src=192.168.2.101 dst=10.215.168.66 sport=51456 dport=53 packets=1 bytes=68 src=10.215.168.66 dst=10.215.168.64 sport=53 dport=51456 packets=1 bytes=68 mark=0 use=1 appdetect[L4:53] udp 17 29 src=192.168.2.101 dst=10.215.168.66 sport=40848 dport=53 packets=1 bytes=69 src=10.215.168.66 dst=10.215.168.64 sport=53 dport=40848 packets=1 bytes=85 mark=0 use=1 appdetect[L4:53 dns-host:www.newspaperteldat.com] udp 17 29 src=127.0.0.1 dst=127.0.0.1 sport=41838 dport=49000 packets=6 bytes=332 src=127.0.0.1 dst=127.0.0.1 sport=49000 dport=41838 packets=6 bytes=398 mark=0 use=1 appdetect[L4:49000] udp 17 29 src=192.168.2.101 dst=10.215.168.66 sport=56627 dport=53 packets=1 bytes=69 src=10.215.168.66 dst=10.215.168.64 sport=53 dport=56627 packets=1 bytes=69 mark=0 use=1 appdetect[L4:53] conntrack v1.4.7 (conntrack-tools): 9 flow entries have been shown.
Step 27: Run the command nslookup enterprise.opentok.com dns-server 10.215.168.66 on DUT1 and expect the following output:
Show output
Server: 10.215.168.66 Address: 10.215.168.66#53 Name: enterprise.opentok.com Address: 10.215.168.1 ** server can't find enterprise.opentok.com: REFUSED
Step 28: Run the command nslookup www.gamblingteldat.com dns-server 10.215.168.66 on DUT1 and expect the following output:
Show output
Server: 10.215.168.66 Address: 10.215.168.66#53 Name: www.gamblingteldat.com Address: 192.168.2.10 ** server can't find www.gamblingteldat.com: REFUSED
Step 29: Run the command nslookup www.newspaperteldat.com dns-server 10.215.168.66 on DUT1 and expect the following output:
Show output
Server: 10.215.168.66 Address: 10.215.168.66#53 Name: www.newspaperteldat.com Address: 192.168.2.20 ** server can't find www.newspaperteldat.com: REFUSED
Step 30: Run the command system conntrack show on DUT0 and expect the following output:
Show output
udp 17 29 src=192.168.2.101 dst=10.215.168.66 sport=59614 dport=53 packets=1 bytes=68 src=10.215.168.66 dst=10.215.168.64 sport=53 dport=59614 packets=1 bytes=84 mark=0 use=1 appdetect[L4:53 dns-host:enterprise.opentok.com] udp 17 28 src=192.168.2.101 dst=10.215.168.66 sport=56311 dport=53 packets=1 bytes=68 src=10.215.168.66 dst=10.215.168.64 sport=53 dport=56311 packets=1 bytes=84 mark=0 use=1 appdetect[L4:53 dns-host:enterprise.opentok.com] tcp 6 298 ESTABLISHED src=10.215.168.64 dst=10.215.168.1 sport=46398 dport=443 packets=12 bytes=1501 src=10.215.168.1 dst=10.215.168.64 sport=443 dport=46398 packets=9 bytes=2042 [ASSURED] mark=0 use=1 appdetect[L4:443] tcp 6 298 ESTABLISHED src=10.215.168.64 dst=10.215.168.1 sport=46408 dport=443 packets=9 bytes=1345 src=10.215.168.1 dst=10.215.168.64 sport=443 dport=46408 packets=8 bytes=1990 [ASSURED] mark=0 use=1 appdetect[L4:443] udp 17 28 src=192.168.2.101 dst=10.215.168.66 sport=33411 dport=53 packets=1 bytes=68 src=10.215.168.66 dst=10.215.168.64 sport=53 dport=33411 packets=1 bytes=84 mark=0 use=1 appdetect[L4:53 dns-host:www.gamblingteldat.com] udp 17 28 src=192.168.2.101 dst=10.215.168.66 sport=55211 dport=53 packets=1 bytes=68 src=10.215.168.66 dst=10.215.168.64 sport=53 dport=55211 packets=1 bytes=68 mark=0 use=1 appdetect[L4:53] udp 17 28 src=192.168.2.101 dst=10.215.168.66 sport=51456 dport=53 packets=1 bytes=68 src=10.215.168.66 dst=10.215.168.64 sport=53 dport=51456 packets=1 bytes=68 mark=0 use=1 appdetect[L4:53] udp 17 28 src=192.168.2.101 dst=10.215.168.66 sport=40848 dport=53 packets=1 bytes=69 src=10.215.168.66 dst=10.215.168.64 sport=53 dport=40848 packets=1 bytes=85 mark=0 use=1 appdetect[L4:53 dns-host:www.newspaperteldat.com] udp 17 28 src=127.0.0.1 dst=127.0.0.1 sport=41838 dport=49000 packets=6 bytes=332 src=127.0.0.1 dst=127.0.0.1 sport=49000 dport=41838 packets=6 bytes=398 mark=0 use=1 appdetect[L4:49000] udp 17 29 src=192.168.2.101 dst=10.215.168.66 sport=57261 dport=53 packets=1 bytes=68 src=10.215.168.66 dst=10.215.168.64 sport=53 dport=57261 packets=1 bytes=84 mark=0 use=1 appdetect[L4:53 dns-host:www.gamblingteldat.com] udp 17 29 src=192.168.2.101 dst=10.215.168.66 sport=34631 dport=53 packets=1 bytes=69 src=10.215.168.66 dst=10.215.168.64 sport=53 dport=34631 packets=1 bytes=85 mark=0 use=1 appdetect[L4:53 dns-host:www.newspaperteldat.com] udp 17 29 src=192.168.2.101 dst=10.215.168.66 sport=33572 dport=53 packets=1 bytes=68 src=10.215.168.66 dst=10.215.168.64 sport=53 dport=33572 packets=1 bytes=68 mark=0 use=1 appdetect[L4:53] udp 17 28 src=192.168.2.101 dst=10.215.168.66 sport=56627 dport=53 packets=1 bytes=69 src=10.215.168.66 dst=10.215.168.64 sport=53 dport=56627 packets=1 bytes=69 mark=0 use=1 appdetect[L4:53] udp 17 29 src=192.168.2.101 dst=10.215.168.66 sport=43423 dport=53 packets=1 bytes=69 src=10.215.168.66 dst=10.215.168.64 sport=53 dport=43423 packets=1 bytes=69 mark=0 use=1 appdetect[L4:53] udp 17 29 src=192.168.2.101 dst=10.215.168.66 sport=38559 dport=53 packets=1 bytes=68 src=10.215.168.66 dst=10.215.168.64 sport=53 dport=38559 packets=1 bytes=68 mark=0 use=1 appdetect[L4:53] conntrack v1.4.7 (conntrack-tools): 15 flow entries have been shown.
Step 31: Run the command system journal show | tail -n 200 on DUT0 and expect the following output:
Show output
Sep 16 20:13:52.564655 osdx kernel: app-detect: (0) dictionary _remote_, priority 2 type remote Sep 16 20:13:52.564662 osdx kernel: app-detect: linked list of disabled dicts: Sep 16 20:13:52.564669 osdx kernel: app-detect: (0) dictionary _remote_, priority 1 type remote (target_dict) Sep 16 20:13:52.564676 osdx kernel: app-detect: freed hash table Sep 16 20:13:52.564689 osdx kernel: app-detect: freed memory for hashes+appids Sep 16 20:13:52.564698 osdx kernel: app-detect: dictionary _remote_ deleted Sep 16 20:13:52.564706 osdx kernel: app-detect: linked list of enabled dicts: Sep 16 20:13:52.564718 osdx kernel: app-detect: (0) dictionary _remote_, priority 2 type remote Sep 16 20:13:52.564725 osdx kernel: app-detect: linked list of disabled dicts: Sep 16 20:13:52.564732 osdx kernel: app-detect: (empty, no dicts) Sep 16 20:13:52.564739 osdx kernel: app-detect: set target dict _remote_ priority 1 type unknown (new,empty) Sep 16 20:13:52.564748 osdx kernel: app-detect: linked list of enabled dicts: Sep 16 20:13:52.564757 osdx kernel: app-detect: (0) dictionary _remote_, priority 2 type remote Sep 16 20:13:52.564767 osdx kernel: app-detect: linked list of disabled dicts: Sep 16 20:13:52.564775 osdx kernel: app-detect: (0) dictionary _remote_, priority 1 type unknown (target_dict) Sep 16 20:13:52.564783 osdx kernel: app-detect: initialized expiration timer for REMOTE dict _remote_ Sep 16 20:13:52.564791 osdx kernel: app-detect: set type of dict _remote_ to remote Sep 16 20:13:52.564800 osdx kernel: app-detect: user set num_hash_entries=40000 Sep 16 20:13:52.564812 osdx kernel: app-detect: selected hash dict hash table with 16 hash bits and 65536 buckets for max 40000 entries (supported range 2^8...2^20) Sep 16 20:13:52.564820 osdx kernel: app-detect: allocated memory for hash table with 65536 buckets (524288 bytes) Sep 16 20:13:52.564829 osdx kernel: app-detect: allocated memory for 40000 hash entries (4160000 bytes) Sep 16 20:13:52.564843 osdx kernel: app-detect: set dictionary _remote_ hash_key d46225f3cb7730441efc28f7ad6acf2604ffe1719e801afac8457b3bf45deec3 Sep 16 20:13:52.564851 osdx kernel: app-detect: enable remote dictionary _remote_ Sep 16 20:13:52.564859 osdx kernel: app-detect: dictionary _remote_ enabled Sep 16 20:13:52.564869 osdx kernel: app-detect: linked list of enabled dicts: Sep 16 20:13:52.564877 osdx kernel: app-detect: (0) dictionary _remote_, priority 1 type remote (target_dict) Sep 16 20:13:52.564885 osdx kernel: app-detect: (1) dictionary _remote_, priority 2 type remote Sep 16 20:13:52.564892 osdx kernel: app-detect: linked list of disabled dicts: Sep 16 20:13:52.564901 osdx kernel: app-detect: (empty, no dicts) Sep 16 20:13:52.564908 osdx kernel: app-detect: set target dict _remote_ priority 2 type remote (existing,enabled) Sep 16 20:13:52.564921 osdx kernel: app-detect: linked list of enabled dicts: Sep 16 20:13:52.564929 osdx kernel: app-detect: (0) dictionary _remote_, priority 1 type remote Sep 16 20:13:52.564936 osdx kernel: app-detect: (1) dictionary _remote_, priority 2 type remote (target_dict) Sep 16 20:13:52.564943 osdx kernel: app-detect: linked list of disabled dicts: Sep 16 20:13:52.564951 osdx kernel: app-detect: (empty, no dicts) Sep 16 20:13:52.564960 osdx kernel: app-detect: dictionary _remote_ disabled Sep 16 20:13:52.564968 osdx kernel: app-detect: linked list of enabled dicts: Sep 16 20:13:52.564975 osdx kernel: app-detect: (0) dictionary _remote_, priority 1 type remote Sep 16 20:13:52.564981 osdx kernel: app-detect: linked list of disabled dicts: Sep 16 20:13:52.564988 osdx kernel: app-detect: (0) dictionary _remote_, priority 2 type remote (target_dict) Sep 16 20:13:52.564995 osdx kernel: app-detect: freed hash table Sep 16 20:13:52.565002 osdx kernel: app-detect: freed memory for hashes+appids Sep 16 20:13:52.565009 osdx kernel: app-detect: dictionary _remote_ deleted Sep 16 20:13:52.565015 osdx kernel: app-detect: linked list of enabled dicts: Sep 16 20:13:52.565022 osdx kernel: app-detect: (0) dictionary _remote_, priority 1 type remote Sep 16 20:13:52.565029 osdx kernel: app-detect: linked list of disabled dicts: Sep 16 20:13:52.565038 osdx kernel: app-detect: (empty, no dicts) Sep 16 20:13:52.565045 osdx kernel: app-detect: set target dict _remote_ priority 2 type unknown (new,empty) Sep 16 20:13:52.565052 osdx kernel: app-detect: linked list of enabled dicts: Sep 16 20:13:52.565059 osdx kernel: app-detect: (0) dictionary _remote_, priority 1 type remote Sep 16 20:13:52.565066 osdx kernel: app-detect: linked list of disabled dicts: Sep 16 20:13:52.565073 osdx kernel: app-detect: (0) dictionary _remote_, priority 2 type unknown (target_dict) Sep 16 20:13:52.565079 osdx kernel: app-detect: initialized expiration timer for REMOTE dict _remote_ Sep 16 20:13:52.565086 osdx kernel: app-detect: set type of dict _remote_ to remote Sep 16 20:13:52.565093 osdx kernel: app-detect: user set num_hash_entries=40000 Sep 16 20:13:52.565100 osdx kernel: app-detect: selected hash dict hash table with 16 hash bits and 65536 buckets for max 40000 entries (supported range 2^8...2^20) Sep 16 20:13:52.565107 osdx kernel: app-detect: allocated memory for hash table with 65536 buckets (524288 bytes) Sep 16 20:13:52.565114 osdx kernel: app-detect: allocated memory for 40000 hash entries (4160000 bytes) Sep 16 20:13:52.565121 osdx kernel: app-detect: set dictionary _remote_ hash_key d46225f3cb7730441efc28f7ad6acf2604ffe1719e801afac8457b3bf45deec3 Sep 16 20:13:52.565128 osdx kernel: app-detect: enable remote dictionary _remote_ Sep 16 20:13:52.565135 osdx kernel: app-detect: dictionary _remote_ enabled Sep 16 20:13:52.565141 osdx kernel: app-detect: linked list of enabled dicts: Sep 16 20:13:52.565148 osdx kernel: app-detect: (0) dictionary _remote_, priority 1 type remote Sep 16 20:13:52.565155 osdx kernel: app-detect: (1) dictionary _remote_, priority 2 type remote (target_dict) Sep 16 20:13:52.565162 osdx kernel: app-detect: linked list of disabled dicts: Sep 16 20:13:52.565170 osdx kernel: app-detect: (empty, no dicts) Sep 16 20:13:52.574168 osdx INFO[169949]: Updated /etc/default/osdx_tcatd.conf Sep 16 20:13:52.574201 osdx INFO[169949]: Restarting Traffic Categorization (TCATD) service ... Sep 16 20:13:52.581501 osdx osdx-tcatd[169517]: UDP_Server. Received STOP signal. Cleanup Sep 16 20:13:52.581546 osdx systemd[1]: Stopping osdx-tcatd.service - App-Detect Traffic Categorization daemon... Sep 16 20:13:52.581539 osdx osdx-tcatd[169517]: Dict_client. Cleanup Sep 16 20:13:52.583578 osdx systemd[1]: osdx-tcatd.service: Deactivated successfully. Sep 16 20:13:52.583770 osdx systemd[1]: Stopped osdx-tcatd.service - App-Detect Traffic Categorization daemon. Sep 16 20:13:52.612953 osdx systemd[1]: Starting osdx-tcatd.service - App-Detect Traffic Categorization daemon... Sep 16 20:13:52.911173 osdx systemd[1]: Started osdx-tcatd.service - App-Detect Traffic Categorization daemon. Sep 16 20:13:52.912312 osdx osdx-tcatd[169953]: Dict_client. rdict_num 2 mark 5555 local-vrf Sep 16 20:13:52.921759 osdx osdx-tcatd[169953]: Dict_client. rdict_num 1 mark 5555 local-vrf Sep 16 20:13:53.155907 osdx cfgd[1899]: [157302]Completed change to active configuration Sep 16 20:13:53.156445 osdx OSDxCLI[157302]: User 'admin' committed the configuration. Sep 16 20:13:53.181084 osdx OSDxCLI[157302]: User 'admin' left the configuration menu. Sep 16 20:13:53.315784 osdx OSDxCLI[157302]: User 'admin' executed a new command: 'system conntrack clear'. Sep 16 20:13:55.535086 osdx kernel: app-detect: field dns-host detected: enterprise.opentok.com. Org(src/dst) 192.168.2.101:56311/10.215.168.66:53 Sep 16 20:13:55.535450 osdx osdx-tcatd[169953]: UDP_Server. Read 27 bytes Sep 16 20:13:55.535457 osdx osdx-tcatd[169953]: UDP_Server. Kernel_Message parse. Read message addressed to dictionary 1 FQDN enterprise.opentok.com Sep 16 20:13:55.535477 osdx osdx-tcatd[169953]: Dict_client. Send query (dict 1): {"requestid": "besafepro_request_id","oemid": "Teldat","deviceid": "develop","uid": "","queries": ["getinfo", "getrepinfo"],"fqdns": ["enterprise.opentok.com"],"xml": 0} Sep 16 20:13:55.535489 osdx osdx-tcatd[169953]: UDP_Server. Read 27 bytes Sep 16 20:13:55.535491 osdx osdx-tcatd[169953]: UDP_Server. Kernel_Message parse. Read message addressed to dictionary 2 FQDN enterprise.opentok.com Sep 16 20:13:55.535497 osdx osdx-tcatd[169953]: Dict_client. Send query (dict 2): {"requestid": "besafepro_request_id","oemid": "Teldat","deviceid": "develop","uid": "","queries": ["getinfo", "getrepinfo"],"fqdns": ["enterprise.opentok.com"],"xml": 0} Sep 16 20:13:55.536541 osdx kernel: app-detect: dns detected, continuing detection for further analysis. Org(src/dst) 192.168.2.101:56311/10.215.168.66:53 Sep 16 20:13:55.536577 osdx kernel: app-detect: dictionary search for enterprise.opentok.com Sep 16 20:13:55.536606 osdx kernel: app-detect: search in CNAMEs db for enterprise.opentok.com Sep 16 20:13:55.536617 osdx kernel: app-detect: search in dict _remote_, prio 1 Sep 16 20:13:55.536625 osdx kernel: app-detect: search in dict _remote_, prio 2 Sep 16 20:13:55.536633 osdx kernel: app-detect: set target dict _remote_ priority 2 type remote (existing,enabled) Sep 16 20:13:55.536640 osdx kernel: app-detect: linked list of enabled dicts: Sep 16 20:13:55.536650 osdx kernel: app-detect: (0) dictionary _remote_, priority 1 type remote Sep 16 20:13:55.536661 osdx kernel: app-detect: (1) dictionary _remote_, priority 2 type remote (target_dict) Sep 16 20:13:55.536696 osdx kernel: app-detect: linked list of disabled dicts: Sep 16 20:13:55.536706 osdx kernel: app-detect: (empty, no dicts) Sep 16 20:13:55.536716 osdx kernel: app-detect: set fqdn hash 46b26ca475a30e2c2b54f5356b2738abe73ead8a02742c712c9e645e233e9d74, hash table index=0018098 (0x046b2) (16 bits), ttl 172800 seconds Sep 16 20:13:55.536496 osdx osdx-tcatd[169953]: Dict_client. Received answer (dict 2): {"status": 200, "requestid": "besafepro_request_id", "type": "fqdns", "TTL": 172800, "results": [{"fqdns": "enterprise.opentok.com", "queries": {"getinfo": {"a1cat": 0, "reputation": 88, "lcp": "opentok.com", "cats": [{"catid": 7, "conf": 95}]}, "getrepinfo": {"reputation": 88, "country": "", "popularity": 0, "a ge": 0, "threathistory": 0}}}]} Sep 16 20:13:55.536544 osdx osdx-tcatd[169953]: UDP_Server. Kernel_Message format. Write message addressed to dictionary 2 FQDN enterprise.opentok.com TTL 172800 AppID:83000058 Sep 16 20:13:55.536590 osdx osdx-tcatd[169953]: UDP_Server. Sent 38 bytes Sep 16 20:13:55.536768 osdx osdx-tcatd[169953]: Dict_client. Received answer (dict 1): {"status": 200, "requestid": "besafepro_request_id", "type": "fqdns", "TTL": 172800, "results": [{"fqdns": "enterprise.opentok.com", "queries": {"getinfo": {"a1cat": 0, "reputation": 88, "lcp": "opentok.com", "cats": [{"catid": 7, "conf": 95}]}, "getrepinfo": {"reputation": 88, "country": "", "popularity": 0, "a ge": 0, "threathistory": 0}}}]} Sep 16 20:13:55.536777 osdx osdx-tcatd[169953]: UDP_Server. Kernel_Message format. Write message addressed to dictionary 1 FQDN enterprise.opentok.com TTL 172800 AppID:82000007 Sep 16 20:13:55.536806 osdx osdx-tcatd[169953]: UDP_Server. Sent 38 bytes Sep 16 20:13:55.540524 osdx kernel: app-detect: set target dict _remote_ priority 1 type remote (existing,enabled) Sep 16 20:13:55.540549 osdx kernel: app-detect: linked list of enabled dicts: Sep 16 20:13:55.540559 osdx kernel: app-detect: (0) dictionary _remote_, priority 1 type remote (target_dict) Sep 16 20:13:55.540568 osdx kernel: app-detect: (1) dictionary _remote_, priority 2 type remote Sep 16 20:13:55.540579 osdx kernel: app-detect: linked list of disabled dicts: Sep 16 20:13:55.540587 osdx kernel: app-detect: (empty, no dicts) Sep 16 20:13:55.540594 osdx kernel: app-detect: set fqdn hash 46b26ca475a30e2c2b54f5356b2738abe73ead8a02742c712c9e645e233e9d74, hash table index=0018098 (0x046b2) (16 bits), ttl 172800 seconds Sep 16 20:13:55.639555 osdx kernel: app-detect: field dns-host detected: www.gamblingteldat.com. Org(src/dst) 192.168.2.101:33411/10.215.168.66:53 Sep 16 20:13:55.639930 osdx osdx-tcatd[169953]: UDP_Server. Read 27 bytes Sep 16 20:13:55.639939 osdx osdx-tcatd[169953]: UDP_Server. Kernel_Message parse. Read message addressed to dictionary 1 FQDN www.gamblingteldat.com Sep 16 20:13:55.639959 osdx osdx-tcatd[169953]: Dict_client. Send query (dict 1): {"requestid": "besafepro_request_id","oemid": "Teldat","deviceid": "develop","uid": "","queries": ["getinfo", "getrepinfo"],"fqdns": ["www.gamblingteldat.com"],"xml": 0} Sep 16 20:13:55.639972 osdx osdx-tcatd[169953]: UDP_Server. Read 27 bytes Sep 16 20:13:55.639975 osdx osdx-tcatd[169953]: UDP_Server. Kernel_Message parse. Read message addressed to dictionary 2 FQDN www.gamblingteldat.com Sep 16 20:13:55.639982 osdx osdx-tcatd[169953]: Dict_client. Send query (dict 2): {"requestid": "besafepro_request_id","oemid": "Teldat","deviceid": "develop","uid": "","queries": ["getinfo", "getrepinfo"],"fqdns": ["www.gamblingteldat.com"],"xml": 0} Sep 16 20:13:55.640574 osdx kernel: app-detect: dns detected, continuing detection for further analysis. Org(src/dst) 192.168.2.101:33411/10.215.168.66:53 Sep 16 20:13:55.640601 osdx kernel: app-detect: dictionary search for www.gamblingteldat.com Sep 16 20:13:55.640613 osdx kernel: app-detect: search in CNAMEs db for www.gamblingteldat.com Sep 16 20:13:55.640630 osdx kernel: app-detect: search in dict _remote_, prio 1 Sep 16 20:13:55.640641 osdx kernel: app-detect: search in dict _remote_, prio 2 Sep 16 20:13:55.641038 osdx osdx-tcatd[169953]: Dict_client. Received answer (dict 1): {"status": 200, "requestid": "besafepro_request_id", "type": "fqdns", "TTL": 172800, "results": [{"fqdns": "www.gamblingteldat.com", "queries": {"getinfo": {"a1cat": 0, "reputation": 25, "lcp": "gamblingteldat.com", "cats": [{"catid": 15, "conf": 93}]}, "getrepinfo": {"reputation": 25, "country": "", "popularity ": 0, "age": 0, "threathistory": 0}}}]} Sep 16 20:13:55.641053 osdx osdx-tcatd[169953]: UDP_Server. Kernel_Message format. Write message addressed to dictionary 1 FQDN www.gamblingteldat.com TTL 172800 AppID:8200000F Sep 16 20:13:55.641095 osdx osdx-tcatd[169953]: UDP_Server. Sent 38 bytes Sep 16 20:13:55.641309 osdx osdx-tcatd[169953]: Dict_client. Received answer (dict 2): {"status": 200, "requestid": "besafepro_request_id", "type": "fqdns", "TTL": 172800, "results": [{"fqdns": "www.gamblingteldat.com", "queries": {"getinfo": {"a1cat": 0, "reputation": 25, "lcp": "gamblingteldat.com", "cats": [{"catid": 15, "conf": 93}]}, "getrepinfo": {"reputation": 25, "country": "", "popularity ": 0, "age": 0, "threathistory": 0}}}]} Sep 16 20:13:55.641321 osdx osdx-tcatd[169953]: UDP_Server. Kernel_Message format. Write message addressed to dictionary 2 FQDN www.gamblingteldat.com TTL 172800 AppID:83000019 Sep 16 20:13:55.641355 osdx osdx-tcatd[169953]: UDP_Server. Sent 38 bytes Sep 16 20:13:55.644524 osdx kernel: app-detect: set target dict _remote_ priority 1 type remote (existing,enabled) Sep 16 20:13:55.644547 osdx kernel: app-detect: linked list of enabled dicts: Sep 16 20:13:55.644555 osdx kernel: app-detect: (0) dictionary _remote_, priority 1 type remote (target_dict) Sep 16 20:13:55.644563 osdx kernel: app-detect: (1) dictionary _remote_, priority 2 type remote Sep 16 20:13:55.644571 osdx kernel: app-detect: linked list of disabled dicts: Sep 16 20:13:55.644578 osdx kernel: app-detect: (empty, no dicts) Sep 16 20:13:55.644585 osdx kernel: app-detect: set fqdn hash 95d7d9863609db9ccc870c2d2b6f3048a307595f4ee206f3a041baa9f588fc85, hash table index=0038359 (0x095d7) (16 bits), ttl 172800 seconds Sep 16 20:13:55.644593 osdx kernel: app-detect: set target dict _remote_ priority 2 type remote (existing,enabled) Sep 16 20:13:55.644608 osdx kernel: app-detect: linked list of enabled dicts: Sep 16 20:13:55.644617 osdx kernel: app-detect: (0) dictionary _remote_, priority 1 type remote Sep 16 20:13:55.644625 osdx kernel: app-detect: (1) dictionary _remote_, priority 2 type remote (target_dict) Sep 16 20:13:55.644641 osdx kernel: app-detect: linked list of disabled dicts: Sep 16 20:13:55.644648 osdx kernel: app-detect: (empty, no dicts) Sep 16 20:13:55.644655 osdx kernel: app-detect: set fqdn hash 95d7d9863609db9ccc870c2d2b6f3048a307595f4ee206f3a041baa9f588fc85, hash table index=0038359 (0x095d7) (16 bits), ttl 172800 seconds Sep 16 20:13:55.757805 osdx kernel: app-detect: field dns-host detected: www.newspaperteldat.com. Org(src/dst) 192.168.2.101:40848/10.215.168.66:53 Sep 16 20:13:55.758223 osdx osdx-tcatd[169953]: UDP_Server. Read 28 bytes Sep 16 20:13:55.758237 osdx osdx-tcatd[169953]: UDP_Server. Kernel_Message parse. Read message addressed to dictionary 1 FQDN www.newspaperteldat.com Sep 16 20:13:55.758261 osdx osdx-tcatd[169953]: Dict_client. Send query (dict 1): {"requestid": "besafepro_request_id","oemid": "Teldat","deviceid": "develop","uid": "","queries": ["getinfo", "getrepinfo"],"fqdns": ["www.newspaperteldat.com"],"xml": 0} Sep 16 20:13:55.758275 osdx osdx-tcatd[169953]: UDP_Server. Read 28 bytes Sep 16 20:13:55.758278 osdx osdx-tcatd[169953]: UDP_Server. Kernel_Message parse. Read message addressed to dictionary 2 FQDN www.newspaperteldat.com Sep 16 20:13:55.758285 osdx osdx-tcatd[169953]: Dict_client. Send query (dict 2): {"requestid": "besafepro_request_id","oemid": "Teldat","deviceid": "develop","uid": "","queries": ["getinfo", "getrepinfo"],"fqdns": ["www.newspaperteldat.com"],"xml": 0} Sep 16 20:13:55.759233 osdx osdx-tcatd[169953]: Dict_client. Received answer (dict 2): {"status": 200, "requestid": "besafepro_request_id", "type": "fqdns", "TTL": 172800, "results": [{"fqdns": "www.newspaperteldat.com", "queries": {"getinfo": {"a1cat": 0, "reputation": 92, "lcp": "newspaperteldat.com", "cats": [{"catid": 4, "conf": 93}]}, "getrepinfo": {"reputation": 92, "country": "", "popularit y": 0, "age": 0, "threathistory": 0}}}]} Sep 16 20:13:55.759255 osdx osdx-tcatd[169953]: UDP_Server. Kernel_Message format. Write message addressed to dictionary 2 FQDN www.newspaperteldat.com TTL 172800 AppID:8300005C Sep 16 20:13:55.759299 osdx osdx-tcatd[169953]: UDP_Server. Sent 39 bytes Sep 16 20:13:55.759430 osdx osdx-tcatd[169953]: Dict_client. Received answer (dict 1): {"status": 200, "requestid": "besafepro_request_id", "type": "fqdns", "TTL": 172800, "results": [{"fqdns": "www.newspaperteldat.com", "queries": {"getinfo": {"a1cat": 0, "reputation": 92, "lcp": "newspaperteldat.com", "cats": [{"catid": 4, "conf": 93}]}, "getrepinfo": {"reputation": 92, "country": "", "popularit y": 0, "age": 0, "threathistory": 0}}}]} Sep 16 20:13:55.759443 osdx osdx-tcatd[169953]: UDP_Server. Kernel_Message format. Write message addressed to dictionary 1 FQDN www.newspaperteldat.com TTL 172800 AppID:82000004 Sep 16 20:13:55.759479 osdx osdx-tcatd[169953]: UDP_Server. Sent 39 bytes Sep 16 20:13:55.760529 osdx kernel: app-detect: dns detected, continuing detection for further analysis. Org(src/dst) 192.168.2.101:40848/10.215.168.66:53 Sep 16 20:13:55.760554 osdx kernel: app-detect: dictionary search for www.newspaperteldat.com Sep 16 20:13:55.760567 osdx kernel: app-detect: search in CNAMEs db for www.newspaperteldat.com Sep 16 20:13:55.760578 osdx kernel: app-detect: search in dict _remote_, prio 1 Sep 16 20:13:55.760590 osdx kernel: app-detect: search in dict _remote_, prio 2 Sep 16 20:13:55.760600 osdx kernel: app-detect: set target dict _remote_ priority 2 type remote (existing,enabled) Sep 16 20:13:55.760612 osdx kernel: app-detect: linked list of enabled dicts: Sep 16 20:13:55.760622 osdx kernel: app-detect: (0) dictionary _remote_, priority 1 type remote Sep 16 20:13:55.760633 osdx kernel: app-detect: (1) dictionary _remote_, priority 2 type remote (target_dict) Sep 16 20:13:55.760645 osdx kernel: app-detect: linked list of disabled dicts: Sep 16 20:13:55.760655 osdx kernel: app-detect: (empty, no dicts) Sep 16 20:13:55.760666 osdx kernel: app-detect: set fqdn hash f32edeb00a440e970fb18ad576d01b83fe00cd767533ed3c53233a2aaaa9dce8, hash table index=0062254 (0x0f32e) (16 bits), ttl 172800 seconds Sep 16 20:13:55.760678 osdx kernel: app-detect: set target dict _remote_ priority 1 type remote (existing,enabled) Sep 16 20:13:55.760689 osdx kernel: app-detect: linked list of enabled dicts: Sep 16 20:13:55.760702 osdx kernel: app-detect: (0) dictionary _remote_, priority 1 type remote (target_dict) Sep 16 20:13:55.760714 osdx kernel: app-detect: (1) dictionary _remote_, priority 2 type remote Sep 16 20:13:55.760725 osdx kernel: app-detect: linked list of disabled dicts: Sep 16 20:13:55.760735 osdx kernel: app-detect: (empty, no dicts) Sep 16 20:13:55.760746 osdx kernel: app-detect: set fqdn hash f32edeb00a440e970fb18ad576d01b83fe00cd767533ed3c53233a2aaaa9dce8, hash table index=0062254 (0x0f32e) (16 bits), ttl 172800 seconds Sep 16 20:13:55.875761 osdx OSDxCLI[157302]: User 'admin' executed a new command: 'system conntrack show'. Sep 16 20:13:56.992867 osdx kernel: app-detect: field dns-host detected: enterprise.opentok.com. Org(src/dst) 192.168.2.101:59614/10.215.168.66:53 Sep 16 20:13:56.996542 osdx kernel: app-detect: dns detected, continuing detection for further analysis. Org(src/dst) 192.168.2.101:59614/10.215.168.66:53 Sep 16 20:13:56.996583 osdx kernel: app-detect: dictionary search for enterprise.opentok.com Sep 16 20:13:56.996593 osdx kernel: app-detect: search in CNAMEs db for enterprise.opentok.com Sep 16 20:13:56.996601 osdx kernel: app-detect: search in dict _remote_, prio 1 Sep 16 20:13:56.996616 osdx kernel: app-detect: appid 82000007 found in hash dictionary Sep 16 20:13:56.996624 osdx kernel: app-detect: add address 10.215.168.1, appids 82000007 to cache Sep 16 20:13:57.076811 osdx kernel: app-detect: field dns-host detected: www.gamblingteldat.com. Org(src/dst) 192.168.2.101:57261/10.215.168.66:53 Sep 16 20:13:57.080531 osdx kernel: app-detect: dns detected, continuing detection for further analysis. Org(src/dst) 192.168.2.101:57261/10.215.168.66:53 Sep 16 20:13:57.080557 osdx kernel: app-detect: dictionary search for www.gamblingteldat.com Sep 16 20:13:57.080565 osdx kernel: app-detect: search in CNAMEs db for www.gamblingteldat.com Sep 16 20:13:57.080573 osdx kernel: app-detect: search in dict _remote_, prio 1 Sep 16 20:13:57.080580 osdx kernel: app-detect: appid 8200000f found in hash dictionary Sep 16 20:13:57.080588 osdx kernel: app-detect: add address 192.168.2.10, appids 8200000f to cache Sep 16 20:13:57.174862 osdx kernel: app-detect: field dns-host detected: www.newspaperteldat.com. Org(src/dst) 192.168.2.101:34631/10.215.168.66:53 Sep 16 20:13:57.176545 osdx kernel: app-detect: dns detected, continuing detection for further analysis. Org(src/dst) 192.168.2.101:34631/10.215.168.66:53 Sep 16 20:13:57.176587 osdx kernel: app-detect: dictionary search for www.newspaperteldat.com Sep 16 20:13:57.176600 osdx kernel: app-detect: search in CNAMEs db for www.newspaperteldat.com Sep 16 20:13:57.176612 osdx kernel: app-detect: search in dict _remote_, prio 1 Sep 16 20:13:57.176630 osdx kernel: app-detect: appid 82000004 found in hash dictionary Sep 16 20:13:57.176641 osdx kernel: app-detect: add address 192.168.2.20, appids 82000004 to cache Sep 16 20:13:57.281197 osdx OSDxCLI[157302]: User 'admin' executed a new command: 'system conntrack show'.
Step 32: Run the command system conntrack app-detect show ip-cache on DUT0 and expect the following output:
Show output
---------------------------------------- IP Application ID Expires in ---------------------------------------- 10.215.168.1 U130:7 28s 192.168.2.10 U130:15 28s84ms 192.168.2.20 U130:4 28s180ms
Step 33: Run the command system conntrack app-detect show ip-cache on DUT0 and check whether the output matches the following regular expressions:
10.215.168.1\s*.*U130:7Show output
---------------------------------------- IP Application ID Expires in ---------------------------------------- 10.215.168.1 U130:7 27s932ms 192.168.2.10 U130:15 28s16ms 192.168.2.20 U130:4 28s112ms
Step 34: Run the command system conntrack app-detect show ip-cache on DUT0 and check whether the output matches the following regular expressions:
192.168.2.10\s*.*U130:15Show output
---------------------------------------- IP Application ID Expires in ---------------------------------------- 10.215.168.1 U130:7 27s844ms 192.168.2.10 U130:15 27s928ms 192.168.2.20 U130:4 28s24ms
Step 35: Run the command system conntrack app-detect show ip-cache on DUT0 and check whether the output matches the following regular expressions:
192.168.2.20\s*.*U130:4Show output
---------------------------------------- IP Application ID Expires in ---------------------------------------- 10.215.168.1 U130:7 27s776ms 192.168.2.10 U130:15 27s860ms 192.168.2.20 U130:4 27s956ms
Step 36: Set the following configuration in DUT0 :
set interfaces ethernet eth0 address 10.215.168.64/24 set interfaces ethernet eth0 traffic nat source rule 1 address masquerade set interfaces ethernet eth0 traffic policy out POL set interfaces ethernet eth1 address 192.168.2.100/24 set system conntrack app-detect app-id-storage chained set system conntrack app-detect debug set system conntrack app-detect dictionary 1 remote encrypted-key U2FsdGVkX190OUL+fc2lBeVEKEq3HVTbr81r1U6oL64= set system conntrack app-detect dictionary 1 remote encrypted-url U2FsdGVkX1+tTZFCC12gdsJitFcHZTUzjzH3RadkKhgT9Xjrnn4kyuaPevognFE/ set system conntrack app-detect dictionary 1 remote mark 5555 set system conntrack app-detect dictionary 1 remote property category set system conntrack app-detect dictionary 1 remote ssl-allow-insecure set system conntrack app-detect dictionary 2 remote encrypted-key U2FsdGVkX1+sDhb+d+SiqiaCr58yJL1RwCx1IaO7VA0= set system conntrack app-detect dictionary 2 remote encrypted-url U2FsdGVkX1+uSoKAAhynouos7OHw1N4gnSH4+zJx2hvDPPJzXKYmKQNJ71waKlPO set system conntrack app-detect dictionary 2 remote mark 5555 set system conntrack app-detect dictionary 2 remote property reputation set system conntrack app-detect dictionary 2 remote ssl-allow-insecure set system conntrack app-detect dns set system conntrack app-detect dns-host set system conntrack app-detect enable_dict_match_priv_ip set system conntrack app-detect http set system conntrack app-detect http-host set system conntrack app-detect refresh-flow-appid set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy POL rule 1 action accept set traffic policy POL rule 1 selector RDICT set traffic policy POL rule 2 action drop set traffic policy POL rule 2 selector RESOLVING set traffic selector RDICT rule 1 mark 5555 set traffic selector RESOLVING rule 1 app-detect state detecting set traffic selector RESOLVING rule 1 app-detect state host-detected
Step 37: Run the command system conntrack clear on DUT0.
Step 38: Run the command system conntrack clear on DUT0.
Step 39: Run the command file copy http://enterprise.opentok.com/~robot/test_file running://user-data/ force on DUT1, press Ctrl+C after 2 seconds and expect the following output:
Show output
% Total % Received % Xferd Average Speed Time Time Time Current Dload Upload Total Spent Left Speed 0 0 0 0 0 0 0 0 --:--:-- 0:00:01 --:--:-- 0^C Operation aborted by user. admin@osdx$
Step 40: Run the command system conntrack clear on DUT1.
Step 41: Run the command file copy http://enterprise.opentok.com/~robot/test_file running://user-data/ force on DUT1 and expect the following output:
Show output
% Total % Received % Xferd Average Speed Time Time Time Current Dload Upload Total Spent Left Speed 100 38 100 38 0 0 5583 0 --:--:-- --:--:-- --:--:-- 6333
Step 42: Run the command system conntrack clear on DUT1.
Step 43: Run the command file copy http://enterprise.opentok.com/~robot/test_file running://user-data/ force on DUT1 and expect the following output:
Show output
% Total % Received % Xferd Average Speed Time Time Time Current Dload Upload Total Spent Left Speed 100 38 100 38 0 0 5161 0 --:--:-- --:--:-- --:--:-- 5428
Step 44: Run the command system conntrack show on DUT0 and check whether the output matches the following regular expressions:
appdetect\[(U130:7;U131:88|U131:88;U130:7);L3:6;L4:80\shttp-host:enterprise.opentok.com\]Show output
tcp 6 297 ESTABLISHED src=10.215.168.64 dst=10.215.168.1 sport=42940 dport=443 packets=4 bytes=532 src=10.215.168.1 dst=10.215.168.64 sport=443 dport=42940 packets=3 bytes=675 [ASSURED] mark=0 use=1 appdetect[L3:6;L4:443] tcp 6 src=192.168.2.101 dst=10.215.168.1 sport=44244 dport=80 packets=6 bytes=593 src=10.215.168.1 dst=10.215.168.64 sport=80 dport=44244 packets=4 bytes=505 [ASSURED] [OFFLOAD, packets=1 bytes=52 packets=2 bytes=393] mark=0 use=3 appdetect[U130:7;U131:88;L3:6;L4:80 http-host:enterprise.opentok.com] udp 17 29 src=192.168.2.101 dst=10.215.168.66 sport=52159 dport=53 packets=1 bytes=68 src=10.215.168.66 dst=10.215.168.64 sport=53 dport=52159 packets=1 bytes=68 mark=0 use=1 appdetect[L3:17;L4:53] tcp 6 299 ESTABLISHED src=192.168.2.101 dst=10.215.168.1 sport=44230 dport=80 packets=7 bytes=1737 src=10.215.168.1 dst=10.215.168.64 sport=80 dport=44230 packets=1 bytes=60 [ASSURED] mark=0 use=1 appdetect[L3:6;L4:80 http-host:enterprise.opentok.com] tcp 6 src=192.168.2.101 dst=10.215.168.1 sport=44234 dport=80 packets=6 bytes=593 src=10.215.168.1 dst=10.215.168.64 sport=80 dport=44234 packets=4 bytes=505 [ASSURED] [OFFLOAD, packets=1 bytes=52 packets=2 bytes=393] mark=0 use=2 appdetect[L3:6;L4:80;U130:7;U131:88 http-host:enterprise.opentok.com] udp 17 27 src=192.168.2.101 dst=10.215.168.66 sport=39425 dport=53 packets=1 bytes=68 src=10.215.168.66 dst=10.215.168.64 sport=53 dport=39425 packets=1 bytes=68 mark=0 use=1 appdetect[L3:17;L4:53] tcp 6 297 ESTABLISHED src=10.215.168.64 dst=10.215.168.1 sport=42948 dport=443 packets=4 bytes=532 src=10.215.168.1 dst=10.215.168.64 sport=443 dport=42948 packets=3 bytes=675 [ASSURED] mark=0 use=1 appdetect[L3:6;L4:443] udp 17 29 src=192.168.2.101 dst=10.215.168.66 sport=34840 dport=53 packets=1 bytes=68 src=10.215.168.66 dst=10.215.168.64 sport=53 dport=34840 packets=1 bytes=68 mark=0 use=1 appdetect[L3:17;L4:53] udp 17 27 src=127.0.0.1 dst=127.0.0.1 sport=41838 dport=49000 packets=2 bytes=110 src=127.0.0.1 dst=127.0.0.1 sport=49000 dport=41838 packets=2 bytes=132 mark=0 use=1 appdetect[L3:17;L4:49000] conntrack v1.4.7 (conntrack-tools): 9 flow entries have been shown.
Step 45: Run the command nslookup www.gamblingteldat.com dns-server 10.215.168.66 on DUT1 and expect the following output:
Show output
Server: 10.215.168.66 Address: 10.215.168.66#53 Name: www.gamblingteldat.com Address: 192.168.2.10 ** server can't find www.gamblingteldat.com: REFUSED
Step 46: Run the command nslookup www.newspaperteldat.com dns-server 10.215.168.66 on DUT1 and expect the following output:
Show output
Server: 10.215.168.66 Address: 10.215.168.66#53 Name: www.newspaperteldat.com Address: 192.168.2.20 ** server can't find www.newspaperteldat.com: REFUSED
Step 47: Run the command nslookup www.gamblingteldat.com dns-server 10.215.168.66 on DUT1 and expect the following output:
Show output
Server: 10.215.168.66 Address: 10.215.168.66#53 Name: www.gamblingteldat.com Address: 192.168.2.10 ** server can't find www.gamblingteldat.com: REFUSED
Step 48: Run the command nslookup www.newspaperteldat.com dns-server 10.215.168.66 on DUT1 and expect the following output:
Show output
Server: 10.215.168.66 Address: 10.215.168.66#53 Name: www.newspaperteldat.com Address: 192.168.2.20 ** server can't find www.newspaperteldat.com: REFUSED
Step 49: Run the command system conntrack app-detect show ip-cache on DUT0 and check whether the output matches the following regular expressions:
10.215.168.1\s*.*(U130:7;U131:88|U131:88;U130:7)Show output
----------------------------------------- IP Application ID Expires in ----------------------------------------- 10.215.168.1 U130:7;U131:88 4m55s96ms 192.168.2.10 U130:15;U131:25 28s808ms 192.168.2.20 U130:4;U131:92 28s920ms
Step 50: Run the command system conntrack app-detect show ip-cache on DUT0 and check whether the output matches the following regular expressions:
192.168.2.10\s*.*(U130:15;U131:25|U131:25;U130:15)Show output
----------------------------------------- IP Application ID Expires in ----------------------------------------- 10.215.168.1 U130:7;U131:88 4m55s16ms 192.168.2.10 U130:15;U131:25 28s728ms 192.168.2.20 U130:4;U131:92 28s840ms
Step 51: Run the command system conntrack app-detect show ip-cache on DUT0 and check whether the output matches the following regular expressions:
192.168.2.20\s*.*(U130:4;U131:92|U131:92;U130:4)Show output
----------------------------------------- IP Application ID Expires in ----------------------------------------- 10.215.168.1 U130:7;U131:88 4m54s836ms 192.168.2.10 U130:15;U131:25 28s548ms 192.168.2.20 U130:4;U131:92 28s660ms
Step 52: Modify the following configuration lines in DUT0 :
set system alarm DICTERROR1 set system alarm DICTERROR2 set system conntrack app-detect dictionary 1 remote alarm connection-error DICTERROR1 set system conntrack app-detect dictionary 2 remote alarm connection-error DICTERROR2
Step 53: Run the command system alarm show on DUT0 and check whether the output matches the following regular expressions:
DICTERROR1\s+falseShow output
-------------------------------------------------------------------- Alarm Status Toggled Prev-toggled Toggle-count Time up (%) -------------------------------------------------------------------- DICTERROR1 false 0 0.00 DICTERROR2 false 0 0.00
Step 54: Run the command system alarm show on DUT0 and check whether the output matches the following regular expressions:
DICTERROR2\s+falseShow output
-------------------------------------------------------------------- Alarm Status Toggled Prev-toggled Toggle-count Time up (%) -------------------------------------------------------------------- DICTERROR1 false 0 0.00 DICTERROR2 false 0 0.00
Step 55: Modify the following configuration lines in DUT0 :
set system conntrack app-detect dictionary 1 remote encrypted-key U2FsdGVkX1/ioGbu1jo9yvzUWuKBGgPyrMyCpb5G6tU= set system conntrack app-detect dictionary 2 remote encrypted-key U2FsdGVkX19Bm6amKsgfvgyv4nXVYtokEd2gPvXz058=
Step 56: Run the command system conntrack clear on DUT0.
Step 57: Run the command system conntrack clear on DUT1.
Step 58: Run the command file copy http://enterprise.opentok.com/~robot/test_file running://user-data/ force on DUT1, press Ctrl+C after 3 seconds and expect the following output:
Show output
% Total % Received % Xferd Average Speed Time Time Time Current Dload Upload Total Spent Left Speed 0 0 0 0 0 0 0 0 --:--:-- 0:00:02 --:--:-- 0^C Operation aborted by user. admin@osdx$
Step 59: Run the command system alarm show on DUT0 and check whether the output matches the following regular expressions:
(DICTERROR1|DICTERROR2)\s+trueShow output
--------------------------------------------------------------------------------------------- Alarm Status Toggled Prev-toggled Toggle-count Time up (%) --------------------------------------------------------------------------------------------- DICTERROR1 true 2026-09-16 20:14:13.469625+00:00 1 70.43 DICTERROR2 true 2026-09-16 20:14:13.469793+00:00 1 70.49
Step 60: Modify the following configuration lines in DUT0 :
set system conntrack app-detect dictionary 1 remote encrypted-key U2FsdGVkX19gMsLvnTSU1w3HbagdDYfHvixoy39as9k= set system conntrack app-detect dictionary 2 remote encrypted-key U2FsdGVkX1+++iymJUtm6GKhVpqG4u8Jb1P02ICqliw=
Step 61: Run the command system conntrack clear on DUT0.
Step 62: Run the command system conntrack clear on DUT1.
Step 63: Run the command file copy http://enterprise.opentok.com/~robot/test_file running://user-data/ force on DUT1, press Ctrl+C after 3 seconds and expect the following output:
Show output
% Total % Received % Xferd Average Speed Time Time Time Current Dload Upload Total Spent Left Speed 100 38 100 38 0 0 6563 0 --:--:-- --:--:-- --:--:-- 7600 admin@osdx$
Step 64: Run the command system alarm show on DUT0 and check whether the output matches the following regular expressions:
(DICTERROR1|DICTERROR2)\s+falseShow output
----------------------------------------------------------------------------------------------------------------- Alarm Status Toggled Prev-toggled Toggle-count Time up (%) ----------------------------------------------------------------------------------------------------------------- DICTERROR1 false 2026-09-16 20:14:19.982756+00:00 2026-09-16 20:14:13.469625+00:00 2 47.91 DICTERROR2 false 2026-09-16 20:14:19.982499+00:00 2026-09-16 20:14:13.469793+00:00 2 47.93
Remote Application Dictionary run in a VRF
Description
DUT0 configures HTTP detection with a remote application dictionary running in a separate VRF. DUT1 acts as a client behind DUT0. The test verifies that remote dictionary protocol traffic uses the VRF and HTTP connections are classified.
Phase 1: Using the local-vrf option to specify the VRF for the remote dictionary protocol.
Phase 2: Using the local-interface option with an interface assigned to the VRF.
Phase 3: Using the local-address option to source from an address on an interface in the VRF.
Scenario
Step 1: Set the following configuration in DUT0 :
set interfaces ethernet eth0 address 10.215.168.64/24 set interfaces ethernet eth0 traffic nat source rule 1 address masquerade set interfaces ethernet eth0 traffic policy out POL set interfaces ethernet eth0 vrf MYVRF set interfaces ethernet eth1 address 192.168.2.100/24 set interfaces ethernet eth1 vrf MYVRF set system conntrack app-detect dictionary 1 remote encrypted-key U2FsdGVkX1/xPVmMclK5VR+3Gl36X4bCU+zkNzqprbA= set system conntrack app-detect dictionary 1 remote encrypted-url U2FsdGVkX1/pjqBBZWKzU35bmQZBE0vaOKPg65u8cxijy/yp6XqcyQrccZUdjtEZ set system conntrack app-detect dictionary 1 remote local-vrf MYVRF set system conntrack app-detect dictionary 1 remote property category set system conntrack app-detect dictionary 1 remote ssl-allow-insecure set system conntrack app-detect dictionary 1 remote vrf-mark MYVRF set system conntrack app-detect dictionary 2 remote encrypted-key U2FsdGVkX18NO/oowEXd0F6h0stPbS7ZfC02e/99Pq8= set system conntrack app-detect dictionary 2 remote encrypted-url U2FsdGVkX18QylwfyX6L1fxA6ucCuE3X1OgVUi8TIxLO14UUblPOzKSKoAOxtonA set system conntrack app-detect dictionary 2 remote local-vrf MYVRF set system conntrack app-detect dictionary 2 remote property reputation set system conntrack app-detect dictionary 2 remote ssl-allow-insecure set system conntrack app-detect dictionary 2 remote vrf-mark MYVRF set system conntrack app-detect enable_dict_match_priv_ip set system conntrack app-detect http set system conntrack app-detect http-host set system conntrack app-detect refresh-flow-appid set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set system vrf MYVRF set traffic policy POL rule 1 action accept set traffic policy POL rule 1 selector RDICT set traffic policy POL rule 2 action drop set traffic policy POL rule 2 selector RESOLVING set traffic selector RDICT rule 1 vrf-mark MYVRF set traffic selector RESOLVING rule 1 app-detect state detecting set traffic selector RESOLVING rule 1 app-detect state host-detected
Step 2: Set the following configuration in DUT1 :
set interfaces ethernet eth1 address 192.168.2.101/24 set protocols static route 0.0.0.0/0 next-hop 192.168.2.100 set service dns forwarding name-server 10.215.168.66 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
Step 3: Set the following configuration in DUT2 :
set interfaces ethernet eth0 address 10.215.168.66/24 set service dns forwarding local-ttl 30 set service dns forwarding name-server 127.0.0.1 set service dns static host-name enterprise.opentok.com inet 10.215.168.1 set service dns static host-name static.opentok.com inet 192.168.2.100 set service dns static host-name www.gamblingteldat.com inet 192.168.2.10 set service dns static host-name www.newspaperteldat.com inet 192.168.2.20 set service ssh set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
Step 4: Ping the IP address 10.215.168.1 from DUT1:
admin@DUT1$ ping 10.215.168.1 count 1 size 56 timeout 1Show output
PING 10.215.168.1 (10.215.168.1) 56(84) bytes of data. 64 bytes from 10.215.168.1: icmp_seq=1 ttl=63 time=1.07 ms --- 10.215.168.1 ping statistics --- 1 packets transmitted, 1 received, 0% packet loss, time 0ms rtt min/avg/max/mdev = 1.066/1.066/1.066/0.000 ms
Step 5: Run the command system conntrack clear on DUT0.
Step 6: Run the command file copy http://enterprise.opentok.com/~robot/test_file running://user-data/ force on DUT1, press Ctrl+C after 2 seconds and expect the following output:
Show output
% Total % Received % Xferd Average Speed Time Time Time Current Dload Upload Total Spent Left Speed 0 0 0 0 0 0 0 0 --:--:-- 0:00:01 --:--:-- 0^C Operation aborted by user. admin@osdx$
Step 7: Run the command system conntrack show on DUT0 and check whether the output matches the following regular expressions:
tcp.*dst=10.215.168.1.*dport=443.*vrf=MYVRF.*vrf=MYVRFShow output
tcp 6 3598 ESTABLISHED src=10.215.168.64 dst=10.215.168.1 sport=38314 dport=443 vrf=MYVRF packets=11 bytes=1659 src=10.215.168.1 dst=10.215.168.64 sport=443 dport=38314 vrf=MYVRF packets=10 bytes=3462 [ASSURED] mark=0 use=1 appdetect[L4:443] udp 17 28 src=192.168.2.101 dst=10.215.168.66 sport=52494 dport=53 vrf=MYVRF packets=1 bytes=68 src=10.215.168.66 dst=10.215.168.64 sport=53 dport=52494 vrf=MYVRF packets=1 bytes=84 mark=0 use=1 appdetect[L4:53] tcp 6 3598 ESTABLISHED src=10.215.168.64 dst=10.215.168.1 sport=38312 dport=443 vrf=MYVRF packets=11 bytes=1659 src=10.215.168.1 dst=10.215.168.64 sport=443 dport=38312 vrf=MYVRF packets=10 bytes=3462 [ASSURED] mark=0 use=1 appdetect[L4:443] udp 17 28 src=192.168.2.101 dst=10.215.168.66 sport=43857 dport=53 vrf=MYVRF packets=1 bytes=68 src=10.215.168.66 dst=10.215.168.64 sport=53 dport=43857 vrf=MYVRF packets=1 bytes=68 mark=0 use=1 appdetect[L4:53] tcp 6 299 ESTABLISHED src=192.168.2.101 dst=10.215.168.1 sport=48474 dport=80 vrf=MYVRF packets=7 bytes=1737 src=10.215.168.1 dst=10.215.168.64 sport=80 dport=48474 vrf=MYVRF packets=1 bytes=60 [ASSURED] mark=0 use=1 appdetect[L4:80 http-host:enterprise.opentok.com] udp 17 28 src=127.0.0.1 dst=127.0.0.1 sport=50882 dport=49000 packets=2 bytes=110 src=127.0.0.1 dst=127.0.0.1 sport=49000 dport=50882 packets=2 bytes=132 mark=0 use=1 appdetect[L4:49000] conntrack v1.4.7 (conntrack-tools): 6 flow entries have been shown.
Step 8: Run the command traffic selector RDICT show on DUT0 and check whether the output matches the following regular expressions:
1\s+[1-9]\d*\s+\d+Show output
Selector RDICT (Policy POL -- ifc eth0 -- hook out prio very-high -- rule 1) ----------------------------------------------------- rule pkts match pkts eval bytes match bytes eval ----------------------------------------------------- 1 22 41 3318 6235 ----------------------------------------------------- Total 22 41 3318 6235
Step 9: Run the command system conntrack clear on DUT1.
Step 10: Run the command file copy http://enterprise.opentok.com/~robot/test_file running://user-data/ force on DUT1, press Ctrl+C after 2 seconds and expect the following output:
Show output
% Total % Received % Xferd Average Speed Time Time Time Current Dload Upload Total Spent Left Speed 100 38 100 38 0 0 5518 0 --:--:-- --:--:-- --:--:-- 6333 admin@osdx$
Step 11: Run the command system conntrack show on DUT0 and check whether the output matches the following regular expressions:
vrf=MYVRF.*vrf=MYVRF.*appdetect\[U130:7\shttp-host:enterprise.opentok.com\]Show output
udp 17 28 src=192.168.2.101 dst=10.215.168.66 sport=58785 dport=53 vrf=MYVRF packets=1 bytes=68 src=10.215.168.66 dst=10.215.168.64 sport=53 dport=58785 vrf=MYVRF packets=1 bytes=68 mark=0 use=1 appdetect[L4:53] tcp 6 3595 ESTABLISHED src=10.215.168.64 dst=10.215.168.1 sport=38314 dport=443 vrf=MYVRF packets=11 bytes=1659 src=10.215.168.1 dst=10.215.168.64 sport=443 dport=38314 vrf=MYVRF packets=10 bytes=3462 [ASSURED] mark=0 use=1 appdetect[L4:443] udp 17 25 src=192.168.2.101 dst=10.215.168.66 sport=52494 dport=53 vrf=MYVRF packets=1 bytes=68 src=10.215.168.66 dst=10.215.168.64 sport=53 dport=52494 vrf=MYVRF packets=1 bytes=84 mark=0 use=1 appdetect[L4:53] tcp 6 3595 ESTABLISHED src=10.215.168.64 dst=10.215.168.1 sport=38312 dport=443 vrf=MYVRF packets=11 bytes=1659 src=10.215.168.1 dst=10.215.168.64 sport=443 dport=38312 vrf=MYVRF packets=10 bytes=3462 [ASSURED] mark=0 use=1 appdetect[L4:443] udp 17 25 src=192.168.2.101 dst=10.215.168.66 sport=43857 dport=53 vrf=MYVRF packets=1 bytes=68 src=10.215.168.66 dst=10.215.168.64 sport=53 dport=43857 vrf=MYVRF packets=1 bytes=68 mark=0 use=1 appdetect[L4:53] tcp 6 src=192.168.2.101 dst=10.215.168.1 sport=48488 dport=80 vrf=MYVRF packets=6 bytes=593 src=10.215.168.1 dst=10.215.168.64 sport=80 dport=48488 vrf=MYVRF packets=4 bytes=505 [ASSURED] [OFFLOAD, packets=1 bytes=52 packets=2 bytes=393] mark=0 use=2 appdetect[U130:7 http-host:enterprise.opentok.com] tcp 6 298 ESTABLISHED src=192.168.2.101 dst=10.215.168.1 sport=48474 dport=80 vrf=MYVRF packets=8 bytes=2062 src=10.215.168.1 dst=10.215.168.64 sport=80 dport=48474 vrf=MYVRF packets=1 bytes=60 [ASSURED] mark=0 use=1 appdetect[L4:80 http-host:enterprise.opentok.com] udp 17 25 src=127.0.0.1 dst=127.0.0.1 sport=50882 dport=49000 packets=2 bytes=110 src=127.0.0.1 dst=127.0.0.1 sport=49000 dport=50882 packets=2 bytes=132 mark=0 use=1 appdetect[L4:49000] conntrack v1.4.7 (conntrack-tools): 8 flow entries have been shown.
Step 12: Modify the following configuration lines in DUT0 :
delete system conntrack app-detect dictionary 1 remote local-vrf delete system conntrack app-detect dictionary 2 remote local-vrf set system conntrack app-detect dictionary 1 remote local-interface eth1 set system conntrack app-detect dictionary 2 remote local-interface eth1
Step 13: Run the command system conntrack clear on DUT0.
Step 14: Run the command file copy http://enterprise.opentok.com/~robot/test_file running://user-data/ force on DUT1, press Ctrl+C after 2 seconds and expect the following output:
Show output
% Total % Received % Xferd Average Speed Time Time Time Current Dload Upload Total Spent Left Speed 0 0 0 0 0 0 0 0 --:--:-- 0:00:01 --:--:-- 0^C Operation aborted by user. admin@osdx$
Step 15: Run the command system conntrack show on DUT0 and check whether the output matches the following regular expressions:
tcp.*dst=10.215.168.1.*dport=443.*vrf=MYVRF.*vrf=MYVRFShow output
tcp 6 3597 ESTABLISHED src=10.215.168.64 dst=10.215.168.1 sport=38348 dport=443 vrf=MYVRF packets=14 bytes=1875 src=10.215.168.1 dst=10.215.168.64 sport=443 dport=38348 vrf=MYVRF packets=12 bytes=3700 [ASSURED] mark=0 use=1 appdetect[L4:443] udp 17 27 src=192.168.2.101 dst=10.215.168.66 sport=37453 dport=53 vrf=MYVRF packets=1 bytes=68 src=10.215.168.66 dst=10.215.168.64 sport=53 dport=37453 vrf=MYVRF packets=1 bytes=68 mark=0 use=1 appdetect[L4:53] tcp 6 3597 ESTABLISHED src=10.215.168.1 dst=10.215.168.64 sport=443 dport=38336 vrf=MYVRF packets=9 bytes=2088 src=10.215.168.64 dst=10.215.168.1 sport=38336 dport=443 vrf=MYVRF packets=10 bytes=1142 [ASSURED] mark=0 use=1 appdetect[L4:38336] tcp 6 299 ESTABLISHED src=192.168.2.101 dst=10.215.168.1 sport=48494 dport=80 vrf=MYVRF packets=7 bytes=1737 src=10.215.168.1 dst=10.215.168.64 sport=80 dport=48494 vrf=MYVRF packets=1 bytes=60 [ASSURED] mark=0 use=1 appdetect[L4:80 http-host:enterprise.opentok.com] tcp 6 8 CLOSE src=192.168.2.101 dst=10.215.168.1 sport=48474 dport=80 vrf=MYVRF packets=4 bytes=457 src=10.215.168.1 dst=10.215.168.64 sport=80 dport=48474 vrf=MYVRF packets=3 bytes=445 [ASSURED] mark=0 use=1 appdetect[L4:80] udp 17 27 src=127.0.0.1 dst=127.0.0.1 sport=50882 dport=49000 packets=2 bytes=110 src=127.0.0.1 dst=127.0.0.1 sport=49000 dport=50882 packets=2 bytes=132 mark=0 use=1 appdetect[L4:49000] conntrack v1.4.7 (conntrack-tools): 6 flow entries have been shown.
Step 16: Run the command system conntrack clear on DUT1.
Step 17: Run the command file copy http://enterprise.opentok.com/~robot/test_file running://user-data/ force on DUT1, press Ctrl+C after 2 seconds and expect the following output:
Show output
% Total % Received % Xferd Average Speed Time Time Time Current Dload Upload Total Spent Left Speed 100 38 100 38 0 0 6118 0 --:--:-- --:--:-- --:--:-- 6333 admin@osdx$
Step 18: Run the command system conntrack show on DUT0 and check whether the output matches the following regular expressions:
vrf=MYVRF.*vrf=MYVRF.*appdetect\[U130:7\shttp-host:enterprise.opentok.com\]Show output
tcp 6 3595 ESTABLISHED src=10.215.168.64 dst=10.215.168.1 sport=38348 dport=443 vrf=MYVRF packets=14 bytes=1875 src=10.215.168.1 dst=10.215.168.64 sport=443 dport=38348 vrf=MYVRF packets=12 bytes=3700 [ASSURED] mark=0 use=1 appdetect[L4:443] udp 17 25 src=192.168.2.101 dst=10.215.168.66 sport=37453 dport=53 vrf=MYVRF packets=1 bytes=68 src=10.215.168.66 dst=10.215.168.64 sport=53 dport=37453 vrf=MYVRF packets=1 bytes=68 mark=0 use=1 appdetect[L4:53] tcp 6 3595 ESTABLISHED src=10.215.168.1 dst=10.215.168.64 sport=443 dport=38336 vrf=MYVRF packets=9 bytes=2088 src=10.215.168.64 dst=10.215.168.1 sport=38336 dport=443 vrf=MYVRF packets=10 bytes=1142 [ASSURED] mark=0 use=1 appdetect[L4:38336] udp 17 27 src=192.168.2.101 dst=10.215.168.66 sport=59069 dport=53 vrf=MYVRF packets=1 bytes=68 src=10.215.168.66 dst=10.215.168.64 sport=53 dport=59069 vrf=MYVRF packets=1 bytes=68 mark=0 use=1 appdetect[L4:53] tcp 6 298 ESTABLISHED src=192.168.2.101 dst=10.215.168.1 sport=48494 dport=80 vrf=MYVRF packets=8 bytes=2062 src=10.215.168.1 dst=10.215.168.64 sport=80 dport=48494 vrf=MYVRF packets=1 bytes=60 [ASSURED] mark=0 use=1 appdetect[L4:80 http-host:enterprise.opentok.com] tcp 6 src=192.168.2.101 dst=10.215.168.1 sport=36776 dport=80 vrf=MYVRF packets=6 bytes=593 src=10.215.168.1 dst=10.215.168.64 sport=80 dport=36776 vrf=MYVRF packets=4 bytes=505 [ASSURED] [OFFLOAD, packets=1 bytes=52 packets=2 bytes=393] mark=0 use=2 appdetect[U130:7 http-host:enterprise.opentok.com] tcp 6 6 CLOSE src=192.168.2.101 dst=10.215.168.1 sport=48474 dport=80 vrf=MYVRF packets=4 bytes=457 src=10.215.168.1 dst=10.215.168.64 sport=80 dport=48474 vrf=MYVRF packets=3 bytes=445 [ASSURED] mark=0 use=1 appdetect[L4:80] udp 17 25 src=127.0.0.1 dst=127.0.0.1 sport=50882 dport=49000 packets=2 bytes=110 src=127.0.0.1 dst=127.0.0.1 sport=49000 dport=50882 packets=2 bytes=132 mark=0 use=1 appdetect[L4:49000] conntrack v1.4.7 (conntrack-tools): 8 flow entries have been shown.
Step 19: Modify the following configuration lines in DUT0 :
delete system conntrack app-detect dictionary 1 remote local-interface delete system conntrack app-detect dictionary 2 remote local-interface set system conntrack app-detect dictionary 1 remote local-address 10.215.168.64 set system conntrack app-detect dictionary 1 remote local-vrf MYVRF set system conntrack app-detect dictionary 2 remote local-address 10.215.168.64 set system conntrack app-detect dictionary 2 remote local-vrf MYVRF
Step 20: Run the command system conntrack clear on DUT0.
Step 21: Run the command file copy http://enterprise.opentok.com/~robot/test_file running://user-data/ force on DUT1, press Ctrl+C after 2 seconds and expect the following output:
Show output
% Total % Received % Xferd Average Speed Time Time Time Current Dload Upload Total Spent Left Speed 0 0 0 0 0 0 0 0 --:--:-- 0:00:01 --:--:-- 0^C Operation aborted by user. admin@osdx$
Step 22: Run the command system conntrack show on DUT0 and check whether the output matches the following regular expressions:
tcp.*dst=10.215.168.1.*dport=443.*vrf=MYVRF.*vrf=MYVRFShow output
tcp 6 299 ESTABLISHED src=192.168.2.101 dst=10.215.168.1 sport=36778 dport=80 vrf=MYVRF packets=7 bytes=1737 src=10.215.168.1 dst=10.215.168.64 sport=80 dport=36778 vrf=MYVRF packets=1 bytes=60 [ASSURED] mark=0 use=1 appdetect[L4:80 http-host:enterprise.opentok.com] tcp 6 8 CLOSE src=192.168.2.101 dst=10.215.168.1 sport=48494 dport=80 vrf=MYVRF packets=4 bytes=457 src=10.215.168.1 dst=10.215.168.64 sport=80 dport=48494 vrf=MYVRF packets=3 bytes=445 [ASSURED] mark=0 use=1 appdetect[L4:80] udp 17 28 src=192.168.2.101 dst=10.215.168.66 sport=46171 dport=53 vrf=MYVRF packets=1 bytes=68 src=10.215.168.66 dst=10.215.168.64 sport=53 dport=46171 vrf=MYVRF packets=1 bytes=68 mark=0 use=1 appdetect[L4:53] tcp 6 3598 ESTABLISHED src=10.215.168.64 dst=10.215.168.1 sport=47408 dport=443 vrf=MYVRF packets=4 bytes=532 src=10.215.168.1 dst=10.215.168.64 sport=443 dport=47408 vrf=MYVRF packets=2 bytes=623 [ASSURED] mark=0 use=1 appdetect[L4:443] udp 17 28 src=127.0.0.1 dst=127.0.0.1 sport=50882 dport=49000 packets=2 bytes=110 src=127.0.0.1 dst=127.0.0.1 sport=49000 dport=50882 packets=2 bytes=132 mark=0 use=1 appdetect[L4:49000] tcp 6 298 ESTABLISHED src=10.215.168.64 dst=10.215.168.1 sport=47396 dport=443 vrf=MYVRF packets=4 bytes=532 src=10.215.168.1 dst=10.215.168.64 sport=443 dport=47396 vrf=MYVRF packets=3 bytes=675 [ASSURED] mark=0 use=1 appdetect[L4:443] conntrack v1.4.7 (conntrack-tools): 6 flow entries have been shown.
Step 23: Run the command system conntrack clear on DUT1.
Step 24: Run the command file copy http://enterprise.opentok.com/~robot/test_file running://user-data/ force on DUT1, press Ctrl+C after 2 seconds and expect the following output:
Show output
% Total % Received % Xferd Average Speed Time Time Time Current Dload Upload Total Spent Left Speed 100 38 100 38 0 0 7647 0 --:--:-- --:--:-- --:--:-- 9500 admin@osdx$
Step 25: Run the command system conntrack show on DUT0 and check whether the output matches the following regular expressions:
vrf=MYVRF.*vrf=MYVRF.*appdetect\[U130:7\shttp-host:enterprise.opentok.com\]Show output
tcp 6 299 ESTABLISHED src=192.168.2.101 dst=10.215.168.1 sport=36778 dport=80 vrf=MYVRF packets=8 bytes=2062 src=10.215.168.1 dst=10.215.168.64 sport=80 dport=36778 vrf=MYVRF packets=1 bytes=60 [ASSURED] mark=0 use=1 appdetect[L4:80 http-host:enterprise.opentok.com] tcp 6 6 CLOSE src=192.168.2.101 dst=10.215.168.1 sport=48494 dport=80 vrf=MYVRF packets=4 bytes=457 src=10.215.168.1 dst=10.215.168.64 sport=80 dport=48494 vrf=MYVRF packets=3 bytes=445 [ASSURED] mark=0 use=1 appdetect[L4:80] udp 17 28 src=192.168.2.101 dst=10.215.168.66 sport=38815 dport=53 vrf=MYVRF packets=1 bytes=68 src=10.215.168.66 dst=10.215.168.64 sport=53 dport=38815 vrf=MYVRF packets=1 bytes=68 mark=0 use=1 appdetect[L4:53] udp 17 25 src=192.168.2.101 dst=10.215.168.66 sport=46171 dport=53 vrf=MYVRF packets=1 bytes=68 src=10.215.168.66 dst=10.215.168.64 sport=53 dport=46171 vrf=MYVRF packets=1 bytes=68 mark=0 use=1 appdetect[L4:53] tcp 6 src=192.168.2.101 dst=10.215.168.1 sport=36788 dport=80 vrf=MYVRF packets=6 bytes=593 src=10.215.168.1 dst=10.215.168.64 sport=80 dport=36788 vrf=MYVRF packets=4 bytes=505 [ASSURED] [OFFLOAD, packets=1 bytes=52 packets=2 bytes=393] mark=0 use=2 appdetect[U130:7 http-host:enterprise.opentok.com] tcp 6 3595 ESTABLISHED src=10.215.168.64 dst=10.215.168.1 sport=47408 dport=443 vrf=MYVRF packets=4 bytes=532 src=10.215.168.1 dst=10.215.168.64 sport=443 dport=47408 vrf=MYVRF packets=2 bytes=623 [ASSURED] mark=0 use=1 appdetect[L4:443] udp 17 25 src=127.0.0.1 dst=127.0.0.1 sport=50882 dport=49000 packets=2 bytes=110 src=127.0.0.1 dst=127.0.0.1 sport=49000 dport=50882 packets=2 bytes=132 mark=0 use=1 appdetect[L4:49000] tcp 6 295 ESTABLISHED src=10.215.168.64 dst=10.215.168.1 sport=47396 dport=443 vrf=MYVRF packets=4 bytes=532 src=10.215.168.1 dst=10.215.168.64 sport=443 dport=47396 vrf=MYVRF packets=3 bytes=675 [ASSURED] mark=0 use=1 appdetect[L4:443] conntrack v1.4.7 (conntrack-tools): 8 flow entries have been shown.