A Policy is a list of Policy Criteria (listed in section 8.5). Policies are assigned to Application Flows and Application Flow Groups at each SWVC End Point (see section 9.3). A Policy provides details on how Ingress[1] IP Packets associated with each Application Flow (or the members of an Application Flow Group) should be handled by the SD-WAN Service, providing rules concerning forwarding, security, rate limits, and others.

As noted in section 7.1, when a Policy is assigned to an Application Flow Group at an SWVC End Point, it applies to all Application Flows in the group unless superseded by an explicit Policy assignment to the Application Flow (but note that treatment of the BANDWIDTH Policy Criterion as described in section 8.5.7 operates a bit differently).

For example, if there is an Application Flow Group called fruits containing Application Flows banana, apple, and pear, and a Policy jam is assigned to this Application Flow Group at an SWVC End Point, then the three listed flows will be forwarded over the SD-WAN using Policy jam. However, if at the SWVC End Point the Policy jelly is assigned to Application Flow apple, then banana and pear will be forwarded using Policy jam, and apple will be forwarded using Policy jelly. This behavior is formally defined in [R54].



[1] Policies only apply to Ingress IP Packets. Packets that arrive at the SD-WAN Edge from other sites are forwarded to the UNI regardless of Policies that are associated with their Application Flow.