---
title: "FAQ: What is Aryaka Unified SASE?"
canonical: "https://docs.aryaka.com/space/KNOW/1275330566/FAQ%3A%20What%20is%20Aryaka%20Unified%20SASE%3F"
format: markdown
---
This topic includes questions users often ask about Aryaka Unified SASE, including what it is, how to use it, and how to manage it.

# About

<details>
<summary>What does Aryaka Unified SASE offer?</summary>

Aryaka Unified SASE offers performance, agility, simplicity, and security, without any trade-offs. It converges SD-WAN, security, observability, multi-cloud SaaS, and enhanced application performance into a single platform, delivered as a service. You can ensure security, application performance, and data access for distributed users without increasing costs, risks, or complexity, and without sacrificing user experience.

Only Aryaka Unified SASE provides the following:

- A unified single-pass architecture (Aryaka OnePASS<sup>TM</sup>).
- A secure, global private network backbone (Aryaka Zero Trust WAN).
- Comprehensive SD-WAN, security, acceleration, observability, and integrated third-party services, with an Open Integration Framework.
- Flexible delivery options (self managed, co-managed, or Aryaka managed) and tailored implementation.

Aryaka Unified SASE combines Next Generation Firewall (NGFW) and Secure Web Gateway (SWG) security services to protect on-premises and remote users from internet-borne threats and evolving cyber threats by inspecting traffic and applying user-defined controls. It also includes Anti-Malware, to detect file-based threats, and Intrusion Prevention System (IPS), to inspect traffic for signatures that indicate a potential threat.

If you require additional security, an Advanced Security license for a site or remote user provides Cloud Access Security Broker (CASB), to enforce access control and tenant restriction on SaaS application traffic, and Data Loss Prevention (DLP), to protect sensitive data.

[Contact an Aryaka representative](https://aryakadocs.atlassian.net/wiki/spaces/KNOW/pages/1542320) to learn more.
</details>

<details>
<summary>Is Aryaka a new vendor in SASE?</summary>

No. Prior to the introduction of Aryaka OnePass<sup>TM</sup>, Aryaka had already established itself as a provider of SASE services by incorporating market-leading third-party security solutions.
</details>

<details>
<summary>What are the most common use cases for Aryaka Unified SASE?</summary>

Aryaka Unified SASE allows enterprises to replace traditional multi-vendor networking and security services with a unified single-vendor platform. There are two primary use cases for Aryaka Unified SASE:

- Replace third-party on-premises firewalls.
- Replace cloud-native Secure Web Gateway (SWG) vendors.
</details>

<details>
<summary>Is Aryaka Unified SASE integrated with Aryaka SD-WAN?</summary>

Yes. Aryaka Unified SASE includes all Aryaka SD-WAN capabilities and is natively integrated into the Aryaka SD-WAN solution throughout the data, control, and management planes. This integration unifies security rule enforcement and cloud-native network architecture and streamlines the management process, enabling organizations to benefit from converged network and security to achieve Zero Trust.
</details>

<details>
<summary>Does Aryaka Unified SASE support multi-cloud and hybrid cloud environments?</summary>

Yes. Aryaka Unified SASE is natively integrated with the Aryaka SD-WAN architecture, which supports multi-cloud and hybrid cloud environments. You can configure security rules to protect your cloud infrastructure with Aryaka Unified SASE.
</details>

<details>
<summary>Does Aryaka provide an SLA for Aryaka Unified SASE?</summary>

Yes. The Service Level Agreement (SLA) plays an essential role in holding Aryaka accountable for meeting or exceeding customers’ expectations. Aryaka strives to provide customers with an experience that is unmatched in the industry. Therefore, Aryaka Unified SASE offers the most comprehensive SLA in the industry. For details, see [Aryaka SLA](https://www.aryaka.com/aryaka-service-level-agreement/).
</details>

<details>
<summary>Does Aryaka Unified SASE integrate with IdPs?</summary>

Yes. You can use Aryaka as your identity provider (IdP) or you can connect to a third-party IdP. Currently, Aryaka supports the following third-party IdPs:

- Enterprise LDAP
- On-premises AD
- Okta
- Duo
- Microsoft Entra (formerly known as Azure AD)

Of these options, Okta, Duo, and Microsoft Entra are based on SAML and OIDC authentication standards.
</details>

<details>
<summary>Where are security rules enforced?</summary>

Aryaka Unified SASE ensures that security rules are enforced in optimal locations—either in the cloud or at the network edge. For a site with an ANAP, security rules are enforced on the ANAP. For a site without an ANAP, rule enforcement occurs on the POP. For remote users, rule enforcement occurs on the POP. For each of these implementations, Aryaka Unified SASE provides consistent control and management across the network.
</details>

<details>
<summary>Is the latest threat intelligence integrated into Aryaka Unified SASE?</summary>

Yes. Aryaka Unified SASE leverages the industry’s leading threat intelligence solutions to provide the latest and most insightful threat intelligence feeds. These feeds are integrated with Aryaka OnePASS<sup>TM</sup> to create an efficient Zero Trust network that is based on the industry’s latest threat intelligence.
</details>

<details>
<summary>Does Aryaka support exporting logs to external SIEM solutions?</summary>

Yes. Aryaka supports integrations with external SIEM solutions for log export. This allows enterprises to aggregate, correlate, and analyze security events from multiple sources in real time. This also provides enterprise customers with actionable insights, enabling them to detect and respond to security incidents more effectively and efficiently.
</details>

<details>
<summary>What log format is supported for SIEM export?</summary>

Currently, Aryaka supports log exports using JavaScript Object Notation (JSON) format.
</details>

<details>
<summary>What file types does the Anti-Malware service support?</summary>

Currently, Portable Executable (PE) files and Portable Document Format (PDF) formats are supported. The Aryaka Anti-Malware service leverages an advanced machine learning engine that scans file content as it passes through the network. Files are separated into sections of data that are classified by reputation (Good, Bad, or Unknown) one at a time to reduce the bandwidth required to classify a large file. If a Bad section is detected, the file transfer can be blocked.
</details>

<details>
<summary>Where can I find more information about Aryaka Unified SASE?</summary>

The following topics provide additional details about Aryaka Unified SASE:

- <u>[Security](https://aryakadocs.atlassian.net/wiki/spaces/KNOW/pages/1210941743)</u>—Describes the security engines, rule tables, and reusable components that are used to configure security rules.
- [NGFW-SWG](https://aryakadocs.atlassian.net/wiki/spaces/KNOW/pages/1275462073)—Describes the features includes with a Unified SASE license.
- [Getting Started with Aryaka Unified SASE](https://aryakadocs.atlassian.net/wiki/spaces/KNOW/pages/136773659)—Describes how to get started with configuring and monitoring your service in MyAryaka.
</details>

# Deployment

<details>
<summary>I am a new customer, how can I enable Aryaka Unified SASE for my sites and remote users?</summary>

To enable Aryaka Unified SASE for your sites, purchase a Unified SASE Site license for each site.

To enable Aryaka Unified for your remote users, purchase Unified SASE Remote User licenses for each remote user.
</details>

<details>
<summary>I am already an Aryaka SD-WAN customer, how can I add Aryaka Unified SASE?</summary>

To add Aryaka Unified SASE to a site, upgrade the site to a Unified SASE license. For remote users, upgrade your remote user license to Unified SASE.
</details>

<details>
<summary>What factors should I consider when choosing site licenses for Aryaka Unified SASE?</summary>

There are two main factors to consider when choosing an Aryaka Unified SASE site license: size and location. Ensure that the site tier you select for your site license matches the bandwidth requirements for your site (Small (100 Mbps), Medium (200 Mbps), Large (500 Mbps), XL (1 Gbps), 2XL (2Gbps), 5XL (5 Gbps), or 10XL (10 Gbps)). Additionally, select the appropriate service region for your sites—either Global or Mainland China. 

You can also choose whether to include any of the following add-on services with your license:

- ANAP High Availability—Deploy a second ANAP for device-level redundancy.
- POP High Availability—Connect to a second POP for POP-level redundancy.
- Last Mile Management—Have Aryaka manage your site’s ISPs.
- Firewall Management—Have Aryaka manage supported third-party firewalls.
</details>

<details>
<summary>What factors should I consider when choosing remote user licenses for Aryaka Unified SASE?</summary>

There are two main factors to consider when choosing an Aryaka Unified SASE remote user license: number of users and region. Ensure that you purchase a license for each remote user that you want to configure. Additionally, select the appropriate service region for your remote users—either Global or Mainland China.
</details>

<details>
<summary>Can Aryaka Unified SASE be deployed on all ANAP models?</summary>

Aryaka Unified SASE ensures that security rules are enforced in optimal locations—either in the cloud or at the network edge. When a site requires an edge device, Aryaka includes an ANAP as part of the service, which enforces security rules at the network edge. Aryaka guarantees that the provided ANAP is fully capable of carrying out its designated tasks.
</details>

<details>
<summary>How do I add Aryaka Unified SASE if I currently have Aryaka SD-WAN High Availability?</summary>

For Aryaka’s current product offering, high availability for a site is enabled by adding ANAP High Availability or POP High Availability to your site license. Site licenses can be purchased for any of Aryaka’s products (SD-WAN, Unified SASE, or Advanced Security). If you have an existing SD-WAN site license with High Availability, contact Aryaka Support to upgrade to Unified SASE site license with High Availability.
</details>

<details>
<summary>Can I enable Aryaka Unified SASE if I have remote users but do no have any sites?</summary>

Yes. You can enable Aryaka Unified SASE for your remote users by purchasing a Unified SASE remote user licenses for the region where you have remote users (either Global or Mainland China).
</details>

<details>
<summary>Can I enable Aryaka Unified SASE without Aryaka SD-WAN?</summary>

No. A Unified SASE license for sites or remote users includes SD-WAN capabilities by default.
</details>

<details>
<summary>I have a cloud site with IaaS, can I apply Aryaka Unified SASE?</summary>

Yes. You can protect your IaaS site just as you would your physical sites, by licensing the site for Unified SASE.
</details>

<details>
<summary>Can I enable Aryaka Unified SASE if I have a legacy IaaS license?</summary>

No. You must first convert your legacy SmartCloud IaaS license to a Unified SASE license in one of the currently available sizes.
</details>

<details>
<summary>Can I enable Aryaka Unified SASE protection for remote users if I have a VPN solution from a third-party vendor?</summary>

No. At present, Aryaka requires remote users to use one of Aryaka’s UZTNA options (Private Access, Aryaka Agent, or Explicit Proxy) to be eligible for Aryaka Unified SASE.
</details>

<details>
<summary>What is the Aryaka fair use policy?</summary>

The use of a remote user license is expected to be in accordance with Aryaka standard use, which permits a total data transfer volume of 6 GB on average for each remote user every month. This is calculated by tracking the total data transfer volume for all your remote users within the same region (Global or Mainland China). This is a customer-level calculation and does not take into account usage by individual remote users within a region. If the data transfer usage exceeds the acceptable amount, a one-time overage charge is applied per unit rate included in the contract.
</details>

<details>
<summary>Does the Aryaka fair use policy apply to sites?</summary>

No. The fair use policy only applies to remote users.
</details>

# Management

<details>
<summary>Can I manage my own security policies?</summary>

Yes. Aryaka provides three management options: fully managed, co-managed, and self managed. [MyAryaka](https://my.aryaka.com/LoginForm) is the management portal for all Aryaka services. When you opt to co-manage or self manage your service, you can configure your own network and security rules in MyAryaka.
</details>

<details>
<summary>Can Aryaka help migrate my existing security policies and configuration during the onboarding process?</summary>

Yes. Aryaka offers optional Day 0 professional services to facilitate a seamless transition from your existing security solution to Aryaka Unified SASE as a Service. This service is provided once during the migration and activation process. [Contact an Aryaka representative](https://aryakadocs.atlassian.net/wiki/spaces/KNOW/pages/1542320) for more information.
</details>

<details>
<summary>Are Day 0 professional services included in the one-time fee for site activation?</summary>

No. Day 0 professional services for security rule and configuration migration is a paid service that is separate from the one-time fee for site activation.
</details>

# Compliance

<details>
<summary>How frequently are updates made to address new and evolving threats?</summary>

Aryaka Unified SASE leverages industry-leading threat intelligence solutions to provide the latest and most insightful threat intelligence feeds. Aryaka uses a server to manage these feeds and ensure the network is equipped with the latest threat intelligence.

To classify traffic by IP and web reputation, Aryaka uses [Webroot](https://www.webroot.com/us/en). The reputation database is updated daily, but network queries and real-time updates are available every five minutes. 

Aryaka’s IPS offering uses signature sets from [Proofpoint](https://www.proofpoint.com/sites/default/files/pfpt-us-ds-et-pro-ruleset.pdf), which are updated daily. The Aryaka server checks for updates every hour and downloads updates as soon as they are available. This ensures that all ANAPs and POPs receive the latest update the next time they synchronize, which occurs every six hours.
</details>

<details>
<summary>Does Aryaka Unified SASE include a Security Operations Center (SOC)?</summary>

No. SOCs are crucial for maintaining a robust cybersecurity posture, as they combine technology, processes, and skilled personnel to detect, respond to, and mitigate security threats. Although Aryaka Unified SASE does not include a SOC, as an open platform for converged network and security, we support log export so that you can send your logs to solutions, such as SIEMs, that are used by SOCs.
</details>

<details>
<summary>Which regulatory standards does Aryaka Unified SASE comply with?</summary>

Regulatory compliance is essential for SASE vendors to meet legal obligations, build trust with customers, mitigate risks, and maintain a competitive edge in the dynamic and evolving landscape of cybersecurity. Aryaka maintains a high standard of trust and transparency for our customers through industry compliance and certifications that align with recognized standards designed to demonstrate legal and ethical conduct, protect sensitive data, mitigate risks, foster transparency, and meet customer expectations. As the Aryaka Unified SASE portfolio expands, Aryaka plans to pursue additional industry compliance and certifications to ensure the highest standards of security and reliability. For information about our current compliance and certifications, visit [Aryaka Trust Center](https://trustcenter.aryaka.com/).
</details>

<details>
<summary>What measures are in place to ensure data privacy and protection?</summary>

Aryaka Unified SASE uses the Zero Trust model. This means that no entity—whether inside or outside the network—is trusted by default. Access is verified and validated continuously, and the principle of least privilege is applied. As part of this, the Aryaka Identity Management (AIM) module serves to authenticate, authorize, and detect users and to control traffic to and from users. 

Additionally, customer data is encrypted wherever needed, both in transit and at rest. The Aryaka Unified SASE infrastructure is built on a global private network, which reduces the risk of exposure of customer data to the public internet. Aryaka also offers an Advanced Security product, which includes DLP and CASB, to further enhance data privacy and protection and comply with stringent industry regulations, such as GDPR and HIPPA.
</details>