head

Precision Enforcement at Every Layer

Policy Enforcement Module

In complex, high-speed networks, visibility alone is not enough. To safeguard performance, security, and compliance, organizations need to act instantly and intelligently. By turning traffic intelligence into actionable control, the network responds to what’s happening and what matters.

Control Traffic in Real Time

The Policy Enforcement Module operates at the core of the Network Intelligence Platform (NIP), applying real-time rules to traffic flows at scale. Powered by inline Deep Packet Inspection (DPI) and enriched subscriber context, it enables policy decisions based on:

• Protocol or application type.

• Subscriber identity, location, or group.

• Network congestion thresholds.

• Detected threats or behavioral anomalies.

• Service-level priorities and SLAs.

Policies can be enforced globally or per subscriber, with real-time decisions executed directly in the data path - not via delayed offline tools.

Supported Enforcement Actions

Blocking

• Drops packets matching policy rules to prevent access or mitigate risk.

Shaping

• Applies QoS-based throttling to limit bandwidth for specific traffic types.

Redirection

• Routes traffic to alternative destinations (e.g., a warning page, a proxy, or a honeypot).

Mirroring

• Duplicates flow to monitoring tools without affecting delivery.

F-30 Timer

• Temporarily allows a flow for 30 seconds before enforcement is triggered.

Modular Policy Layers

Policy enforcement is applied across three major control layers:

Subscriber Policies

Rules targeting specific users, SIMs, or subscriber groups based on behavioral, geographic, or identity data.
→ Examples: Blocking adult content in schools, throttling high-volume streamers in rural zones.

Global Policy

Network-wide enforcement policies applied regardless of user identity.
→ Examples: Blocking illegal content domains, enforcing national content regulation.

Heavy Traffic Policies

Dynamic control during network congestion events, applied per:
◦ Heavy Users (high-consumption subscribers)
◦ Heavy Services (bandwidth-intensive applications)
◦ Heavy Locations (saturated regions)
◦ Heavy Links (bottleneck paths or international transit points)

This tiered framework ensures both scalability and specificity - policies can be broad or hyper-targeted.

Full Policy Transparency

FULL OBSERVABILITY & AUDITING

All policy actions are visualized in dedicated dashboards and recorded in historical logs, providing control and accountability.:
• Real-time views of policy hits and affected flows.
• Breakdown by action type, subscriber, and policy rule.
• Exportable reports for compliance, SLA tracking, or legal review.

VS

DESIGNED FOR SCALE & SPEED

The Policy Enforcement Module adapts to any topology and scales to millions of flows per second without performance loss. It is built on our core principles:
• Inline Action • No latency or dependency on external appliances
• Microservice-based Logic • Modular, isolated rule engines
• Real-time Streaming • Integrated with Kafka pipelines
• Multi-domain Enforcement • Works across mobile, fixed, and edge deployments

Control with Intelligence

With the Policy Enforcement Module, Quant Azimuth delivers a fundamental capability for modern networks • the ability to act immediately on insight. Whether enforcing bandwidth limits, protecting against threats, or upholding national policy, our platform enables precise, auditable, and real-time enforcement.

Learn More