A large chunk of my traffic is uncategorized. When I drill into it and look at the conversations most are talking to the exchange server. I tried to build an application definition to identify this traffic.
I created an address group for all the IPs of the exchange servers
I created an application that uses ports 1025-49152 TCP, and has a source of exchange servers. I couldn't figure out how to add a second rule to this application (like Oracle has), so I created a second application with the same name that has ports 1025-49152 TCP, and a destination of exchange servers.
This looks right, but the rule does not match any traffic.
Suggestions?
-=Dan=-