You can't use the unified policy until your gateways are upgraded to R80.10 or above.
Also, there are quite a number of ways these policies could be unified.
Unification of the policy is left as a manual exercise.
That said, my first attempt at doing this in my lab went something like the following:
- My App Control policy generally applies to Internet bound traffic
- There was a rule in my firewall policy that permitted outbound access
- I changed the action to an inline layer:
- The inline layer basically contained my "Application" layer from R77.30 (I'd copy/paste the rules versus reuse the same layer, though).
It evolved a bit from here.
One thing also to note: the Implicit Cleanup rule on R77.x App Control policies is an ACCEPT (not a drop) whereas the default is generally a drop.
You can set this on a per-layer basis for layers you install to R80.10 gateways.
As this has implications for constructing your policy, you may need to refactor your existing policy a little bit.