IP groups, and not just networks, should be able to be set as targets for DPI / Applicaiton Control
In DPI / Application control, we can currently only set Networks (ie, router interfaces) as targets for DPI.
We should also be allowed to set IP groups. Switch only VLANs do not exist on the gateway, but the gateway still recognises the IP source header of the packets (for things like policy routing etc). Currently, there is no way to set DPI for Switch only vlans. In larger and more complex environments, these are very common and there is still a valid use case for DPI to be set on them at the gateway level, which currently is not possible.
There couls also be a usecase for setting DPI just on a smaller subnet within a network (like half of a /23 for example)