Encrypted network communications reduce the effectiveness of payload based traffic identification and complicate the translation of traffic analysis into network access control decisions. This study evaluates a payload independent workflow that connects flow based multiclass classification with administrator triggered, time limited firewall enforcement. The experiment used the public ISCXVPN2016 benchmark. After removing 18,719 duplicate records, 40,987 unique flows remained; all 23 available numerical flow features were retained without feature selection or normalization. A Random Forest classifier with 300 trees was selected using five-fold cross-validated grid search on a stratified 80% training partition and evaluated on an independent 8,198 sample test set covering 14 VPN and non-VPN traffic classes. The model achieved 88.01% accuracy, 88.00% weighted precision, 88.01% weighted recall, and 87.97% weighted F1-score. It exceeded the strongest reproduced baseline, K-Nearest Neighbors, by 16.09 percentage points in accuracy and 16.29 percentage points in weighted F1-score. Supplemental five-fold evaluation produced a mean accuracy of 88.05% with a 0.36 percentage point standard deviation. The trained classifier was integrated with a web application in which administrators review predicted flows and initiate temporary MikroTik RouterOS rules. All 30 temporary blocking entries observed in the evaluation database reached the Unblocked state with recorded timestamps, demonstrating rule lifecycle traceability at the database level. The findings show that Random Forest can provide competitive flow based classification while supporting an auditable, human controlled access control workflow; however, device level reliability and cross dataset generalizability require further validation.
Copyrights © 2026