Intrusion prevention and traffic observation
The DPI tier applies inline prevention in selected zones to flows allowed by policy. Flows are marked so subsequent packets and replies also return to the inspection engine. The advanced tier adds passive observation, authentication events, DNS anomalies, periodic communications and host inventory. The management baseline remains outside inspection.
Encrypted content and analytical limits
Argos does not decrypt TLS. It analyzes available metadata, TLS/QUIC JA4 client fingerprints and application signals; traffic with insufficient signals remains unclassified. When the inline engine is unavailable the queue allows traffic through. Passive observation does not issue blocking verdicts. Coverage depends on selected zones, protocols and loaded signatures.
DPI tier requirements
Traffic analysis requires at least 2 cores, 2 GiB RAM and 20 GB disk; the advanced level requires at least 4 cores, 4 GiB and 40 GB, plus required components. These are activation thresholds, not throughput guarantees. Interface count and speed depend on hardware; verify sizing against expected traffic.