---
title: "Customize VPN Path Aryaka for an application group"
canonical: "https://docs.aryaka.com/space/KNOW/1545088/Customize%20VPN%20Path%20Aryaka%20for%20an%20application%20group"
format: markdown
---
The VPN Path Aryaka tab is the third of three configuration tabs accessed from the Add Application Group Policy page. This topic assumes you have completed the configuration on the first two tabs as described in  Configure application group policy information  and  Configure application group routing . The VPN Path Aryaka tab allows you to customize the behavior of your application groups that utilize the VPN Path Aryaka network.  You can have one configuration that controls the behavior of the entire application group or you can divide the application group into its identifiable Layer 3 and Layer 4 devices and specify separate behaviors for each of them.  For example, you can group Confluence, Jira, and Review Board into an application group named  Developer Tools  and mark all of the traffic on these applications as Productivity and to use the secondary tunnel to the POP. You could then group Slack and Zoom into an application group called  Collaboration Tools  and classify TCP traffic for this group to be Mission Critical, and UDP traffic for it to be Real Time and to have Link Assure Dejitter applied to it.  In this case, the Developer Tools group has one optimization for all its VPN Path Aryaka traffic, while the Collaboration Tools group uses two optimizations for its VPN Path Aryaka traffic. VPN Path Aryaka customization is optional. To customize VPN Path Aryaka for an application group If it is not already open, open the VPN Path Aryaka tab. Click the  Customize Optimization  toggle. The Use One Optimization for all VPN Path Aryaka Traffic toggle appears in the Optimization for VPN Path Aryaka pane and the Custom Optimizations pane appears. Select one of the following optimization methods: Use one optimization—Click the  Use One Optimization for all VPN Path Aryaka Traffic  toggle if you want to apply one custom optimization for all VPN Path Aryaka traffic. The SSL and TCP Optimization, QoS, and Link Assure panes appear. Complete the procedure in To use one custom optimization on VPN Path Aryaka. Use multiple optimizations—Leave the Use One Optimization for all VPN Path Aryaka Traffic toggle in the default off position if you want to define and apply multiple custom optimizations for different types of VPN Path Aryaka traffic. Complete the procedure in To use multiple custom optimizations on VPN Path Aryaka. To use one custom optimization on VPN Path Aryaka Do one of the following to define the optimization in the SSL and TCP Optimization pane: Click the  Use Aryaka's Default Optimization  toggle to use the default optimization configuration. The other fields in the pane are hidden—no additional optimization settings are required. The default rules are described in  View VPN Path Aryaka optimization rules . Leave the  Use Aryaka's Default Optimization  toggle in its default off position and complete the optimization configuration as follows: Click the  TCP Flow Optimization  drop-down list and select one of the following options: Full—(Recommended) The TCP flow is accelerated by the Aryaka Acceleration Engine. The flow for this application group experiences TCP interception where the TCP segment is broken into several segments and clients experience local acknowledgment to their flows and high TCP throughput. Partial—The TCP flow is not accelerated by the Aryaka Acceleration Engine. However, the flow does see some window scale and MSS adjustments to achieve slightly better throughout. Off—The TCP flow is not accelerated by the Aryaka Acceleration Engine and no modification is done to the TCP flow as it transits through the Aryaka network. Click the  Three-Way Handshake Optimization  drop-down list and select one of the following options (this field is only available if the TCP Flow Optimization is set to Full): Never—The Aryaka Acceleration Engine does  not  intervene in the three-way TCP handshake. The client's SYN is returned by the server. Adaptive (recommended)—The Aryaka Acceleration Engine intervenes in the three-way TCP handshake. The client's SYN is returned by the nearest POP only if a previous connection to this server was successful. Always—The Aryaka Acceleration Engine intervenes in the three-way TCP handshake. The client's SYN is returned by the nearest POP whether the server is available or not. Click the  Optimize SSL  toggle to have Aryaka perform SSL interception and compression for your encrypted SSL traffic. The SSL Certificates table appears. Click  Add  and select the certificates to share with Aryaka as described in  Add static certificates .  Click the  QOS Optimization  drop-down list and select one of the following options as described in  View and edit VPN Path Aryaka QoS settings : No Selection (cannot be selected when Link Assure is enabled) Real Time Mission Critical Transactional Productivity Best Effort Do one of the following to determine how the Link Assure traffic-steering engine decides which site-to-POP tunnel is used for all flows: Click the  Use Aryaka's Default Link Assure Settings  toggle to use the default rules described in  VPN Path Aryaka Link Assure overview . Leave the Use Aryaka's Default Link Assure Settings toggle in its default off position, then customize the Link Assure configuration by completing the following fields: Leave the Skip Link Assure toggle to in its default off position to customize the engine's traffic processing. If you click the  Skip Link Assure  toggle, you prevent the Link Assure engine from processing this traffic.  Click the  Link Assure Traffic Steering Policy  drop-down list and select one of the following options: Prefer a Path—Displays the  Path  drop-down list where you must select the primary or secondary tunnel to the POP. Path Replication—Duplicates the traffic on both tunnels to prevent loss due to ISP outages. Load Balancing—Distributes the flows as equally as possible to each tunnel to optimize traffic processing. Restrict to a Path—Displays the  Path  drop-down list where you must restrict the application group traffic to the primary or secondary tunnel. Click the  Loss Recovery  toggle to enable Aryaka's proprietary loss recovery functionality. This option is available if the traffic steering policy is  not  Path Replication. Click the  Dejitter  toggle to reduce or eliminate jitter in your edge link's health. Click  Submit . You are prompted to select one of the following submit options:  Activate Later  or  Activate Now . See  Activate configuration updates  for details. To use multiple custom optimizations on VPN Path Aryaka Define multiple optimizations in the Custom Optimizations table on the VPN Path Aryaka tab. The table allows you add traffic segments that identify a portion of your application group traffic, which can then have custom optimization controls applied to it. Click  Add New  above the Custom Optimizations table. The Add Custom Optimization page appears. Enter a name for this optimization in the Name field. Configure the following fields in the Traffic Segment pane: Ensure the  Manual  toggle is on. When it is off, the traffic segment fields are hidden, and the current customization is applied to all traffic  not  specified by other custom optimizations. Identify the application group's traffic segment in the following fields:  Protocol—Enter the assigned internet protocol number. For example, 6 for TCP, 17 for UDP, and so on. Source CIDR—Enter a representation of the source IP address and its network mask using CIDR notation. For example, 198.51.100.14/24. Destination CIDR—Enter a representation of the destination IP address and its network mask using CIDR notation. For example, 128.32.0.1/32. Source Ports—Enter a single port number or a range of ports. For example, 101-111. Destination Ports—Enter a single port number or a range of ports. For example, 53. TOS—Enter the Terms of Service (ToS) decimal value. For example, 48 or 184. Do one of the following to define the optimization in the SSL and TCP Optimization pane: Click the  Use Aryaka's Default Optimization  toggle to use the default optimization configuration. The other fields in the pane are hidden—no additional optimization settings are required. The default rules are described in  View VPN Path Aryaka optimization rules . Leave the Use Aryaka's Default Optimization toggle in its default off position and complete the optimization configuration as follows: Click the  TCP Flow Optimization  drop-down list and select one of the following options: Full—(Recommended) The TCP flow is accelerated by the Aryaka Acceleration Engine. The flow for this application group experiences TCP interception where the TCP segment is broken into several segments and clients experience local acknowledgment to their flows and high TCP throughput. Partial—The TCP flow is not accelerated by the Aryaka Acceleration Engine. However, the flow does see some window scale and MSS adjustments to achieve slightly better throughout. Off—The TCP flow is not accelerated by the Aryaka Acceleration Engine and no modification is done to the TCP flow as it transits through the Aryaka network. Click the  Three-Way Handshake Optimization  drop-down list and select one of the following options (this field is only available if the TCP Flow Optimization is set to Full): Never—The Aryaka Acceleration Engine does  not  intervene in the three-way TCP handshake. The client's SYN is returned by the server. Adaptive (recommended)—The Aryaka Acceleration Engine intervenes in the three-way TCP handshake. The client's SYN is returned by the nearest POP only if a previous connection to this server was successful. Always—The Aryaka Acceleration Engine intervenes in the three-way TCP handshake. The client's SYN is returned by the nearest POP whether the server is available or not. Click the  Optimize SSL  toggle to have Aryaka perform SSL interception and compression for your encrypted SSL traffic. The SSL Certificates table appears. Click  Add  and select the certificates to share with Aryaka as described in  Add static certificates . Click the  QOS Optimization  drop-down list and select one of the following options as described in  View and edit VPN Path Aryaka QoS settings : No Selection (cannot be selected when Link Assure is enabled) Real Time Mission Critical Transactional Productivity Best Effort Do one of the following to determine how the Link Assure traffic-steering engine decides which site-to-POP tunnel is used for all flows: Click the  Use Aryaka's Default Link Assure Settings  toggle to use the default rules described in  VPN Path Aryaka Link Assure overview . Leave the Use Aryaka's Default Link Assure Settings toggle in its default off position, then customize the Link Assure configuration by completing the following fields: Leave the Skip Link Assure toggle to in its default off position to customize the engine's traffic processing. If you click the  Skip Link Assure  toggle, you prevent the Link Assure engine from processing this application group's traffic.  Click the  Link Assure Traffic Steering Policy  drop-down list and select one of the following options: Prefer a Path—Displays the  Path  drop-down list where you must select the primary or secondary tunnel to the POP. Path Replication—Duplicates the traffic on both tunnels to prevent loss due to ISP outages. Load Balancing—Distributes the flows as equally as possible to each tunnel to optimize traffic processing. Restrict to a Path—Displays the  Path  drop-down list where you must restrict the application group traffic to the primary or secondary tunnel. Click the  Loss Recovery  toggle to enable Aryaka's proprietary loss recovery functionality. This option is available if the traffic steering policy is not Path Replication. Click the  Dejitter  toggle to reduce or eliminate jitter in your edge link's health. Click  OK . The optimization appears as the first row in the Custom Optimizations table on the VPN Path Aryaka tab. Repeat this procedure to optimize different VPN Path Aryaka traffic segments as required. When all of your specific traffic segments are optimized, create one last optimization, and click the  Manual  toggle (step 4) to the off position.  Click  Submit . You are prompted to select one of the following submit options:  Activate Later  or  Activate Now . See  Activate configuration updates  for details. Related Topics Add a custom application group Create and application group control policy