---
title: "NGFW-SWG"
canonical: "https://docs.aryaka.com/space/KNOW/1275462073/NGFW-SWG"
format: markdown
---
SD-WAN subscriptions include  Basic Firewall  by default, but the included Next Generation Firewall (NGFW) has limited functionality—it cannot control traffic based on reputation score, web category, or users and user groups. With Aryaka Unified SASE, Aryaka offers a Next Generation Firewall - Secure Web Gateway (NGFW-SWG) for additional security. Unified SASE also includes  Anti-Malware  and  Intrusion Prevention System (IPS)  services. For additional security, you can purchase Aryaka’s Advanced Security offering, which includes  Cloud Access Security Broker (CASB)  and  Data Loss Prevention (DLP)  security controls. See the linked topics for details about these additional services.  With NGFW-SWG, your sites and remote users have their traffic inspected by a sequence of security engines that apply user-defined controls to network traffic. To identify and control traffic, you can also configure a secure identity access portal to authenticate authorized users and block unauthorized users, generate dynamic server certificates, and manage your certificate authority for SSL interception. This document provides an overview of the Aryaka NGFW-SWG security offering and describes how to get started with  configuring your service  and  monitoring your service  in MyAryaka.  Prerequisites A site or remote user license for Unified SASE. Use cases The following are the two primary use cases for Aryaka NGFW-SWG:  Replace your third-party on-premises firewall.  The Aryaka NGFW-SWG uses a series of security engines to inspect network traffic and apply user-defined controls. This security stack is included on both ANAPs and POPs, and allows you to monitor and protect your organization’s sites and remote users from evolving cyber threats.  Replace your cloud-native SIA or SWG vendor.  The Aryaka NGFW-SWG allows you to define security rules to monitor, filter, and block internet traffic for your sites and remote users.  Features Aryaka NGFW-SWG includes the following functionality: Identity management and secure identity access portal Internet breakout from the Aryaka POP Domain and URL classification Domain Reputation-based filtering Next generation firewall DNS filtering SSL inspection of web traffic URL Reputation-based filtering Secure web gateway Each of these features is described in a section that follows. See the  Security  topic for a high-level overview of the Aryaka security framework. Identity management and secure identity access portal Aryaka Identity Management (AIM) is a centralized, integrated Aryaka service that can be connected to your directory service or external identity provider (IdP). After it is configured, AIM can perform the following functions: Retrieve a list of users and user groups from your directory service, which can be used as match criteria in security rule tables. Authenticate the network user against the directory service or redirect them to an external IdP, such as Microsoft Entra or Okta. Identify the user groups associated with a remote user accessing the network using Aryaka Private Access. To configure AIM in MyAryaka, navigate to  Global Settings  >  Identity Management . For detailed configuration instructions, see the  Aryaka Identity Management  topic. Secure identity access portal uses browser-based activity to intercept network users' traffic and present them with a login page that allows them to identify themselves to the network. The secure identity access portal allows users to log in as a known user with their username or to access the network as a guest. When users choose to log in as a known user, the secure identity access portal works with AIM to authenticate them or to redirect them to your external IdP. After users log in as a known user or a guest, they can connect to the internet and their traffic is subject to all relevant security rules. When you configure the secure identity access portal, you can also create rules to allow network devices or activities to bypass the secure identity access portal. To configure secure identity access portal in MyAryaka, navigate to  Security  >  Settings  >  Secure Identity Access Portal . For a detailed configuration procedure, see the  Configure secure identity access portal  help topic. Remote users that access the network using Aryaka Private Access are identified when they log in to an NCP VPN client. This login activity initiates a network event that is logged and ultimately sent to the security and routing engines on the POP, allowing a user's private IP address to be mapped to the username used to log in. This allows you to write security rules for any engine that supports user-based match criteria. For more details about identity management and secure identity access portal, see the  Network user identity management  topic. Internet breakout from the Aryaka POP Sites with an ANAP access the internet by locally breaking out using ISPs. Users at sites without an ANAP, and remote users, can access the internet by breaking out from the POP. Internet breakout is an optional feature and you can enable it for your sites and remote users as needed. When enabled, this features allows internet traffic to be sent through the POP tunnel to the Internet while site-to-site traffic is sent over the Aryaka core network. The following graphic depicts the three connection types: A unique public IP address is reserved on the POP for each site and private access concentrator with internet breakout enabled. This IP is used to  port address translate  (PAT) all users to access the internet. You can also define specific local subnets in the PAT rule to control the internet access. Additionally, all security rules for the internet traffic applicable to sites  with  an ANAP can be applied to a site without an ANAP or to remote user regions. Sites with internet breakout enabled on the POP receive additional bandwidth called  internet bandwidth  in addition to their existing subscribed bandwidth. This bandwidth is used for internet traffic exclusively and is applicable in each direction. To enable internet breakout for a remote user region in MyAryaka, navigate to  Universal ZTNA  >  Settings , select the region you want to enable internet breakout for, and then edit the User Count & Features pane. To enable internet breakout for a site without an ANAP,  contact Aryaka support . Domain and URL classification Aryaka uses  Webroot  to classify traffic for your sites and remote users. Webroot databases maintain domain information and URL information. This information is downloaded to the ANAP and to the POP to which the sites connect. This database is checked for updates every five minutes. Domain and URL classification The Webroot database maintains a record of domain names and URLs and their related reputation information in the form of a  score  and a  category . Score is a number ranging from 1 to 100. Risk is assigned to domains and URLs as follows: High risk: score of 1-20 Suspicious: score of 21-40 Moderate risk: score of 41-60 Low risk: score of 61-80 Trustworthy: score of 81-100 Category is an identifier published by Webroot that groups domains and URLs into approximately 80 named categories, for example, Malware, Streaming Media, and Social Networking. If a domain cannot be classified, the category is returned as  Unclassified . You can create rules in the Domain Reputation security engine or the URL Reputation security engine that specify whether to permit or drop traffic that corresponds with a specific score range or category. The Aryaka NGFW-SWG includes a Domain Reputation security engine and a URL Reputation security engine that inspects network traffic and executes user-defined security rules based on the reputation score or category. When you create these security rules, you can choose whether to permit or deny traffic that corresponds with a reputation score or category (including  Unclassified ). See the  Domain reputation-based filtering  and  URL reputation-based filtering  sections later in this document for details. Domain Reputation-based filtering Traffic routed or permitted by one or more of the  Basic Firewall  security engines is forwarded to the Domain Reputation security engine. The following graphic depicts the Domain Reputation security engine in the NGFW-SWG processing sequence where traffic is received from one of Basic Firewall security engines and is forwarded to the next NGFW-SWG security engine in the sequence after inspection: The Domain Reputation security engine includes a rule table that reads rules from top to bottom. The first rule that matches the client’s traffic is applied and all subsequent rules are ignored. The Domain Reputation security engine uses the following match criteria to permit, drop, or log flows: Source IP Source zone User Application Domain category (HTTP or HTTPS flows only) Domain name or server name indication (SNI) (HTTP or HTTPS flows only) Domain score (HTTP or HTTPS flows only) Destination IP Destination network Schedule For more information, see the  Security rule match criteria  topic. Based on your configured rules, the Domain Reputation security engine performs one of the following actions on matched flows: Permit—Traffic is permitted and sent to the next security engine. DNS flows (on UDP port 53) are sent to the DNS Filtering security engine. All other permitted flows are processed by the Next Generation Firewall security engine. Drop—Traffic is denied and the client does no receive a response. Log Only—Traffic is permitted and sent to the next security engine for inspection. This is intended as a temporary action for traffic that needs to be evaluated. After evaluation, update the rule to perform one of the other four actions (permit, drop, reject, or prohibit). Reject—Traffic is denied and the TCP connection is reset. For non-TCP connections, the client receives an  ICMP Unreachable  response.  Prohibit—Traffic is denied and the client receives an  ICMP Unreachable  response. Default rule The default rule in the Domain Reputation rule table matches any traffic that arrives at the Domain Reputation security engine with a web reputation score of 20 or lower and drops it. Flows with a score above 20 are permitted. To modify the Domain Reputation rule table in MyAryaka, you can  add site-level Domain Reputation rules  or  create a Domain Reputation ruleset  that can apply rules to multiple sites. Next generation firewall Traffic permitted by the Domain Reputation security engine arrives at the Next Generation Firewall (NGFW) security engine. The NGFW security engine is the Layer 3/Layer 4 firewall that performs additional traffic inspection. The following graphic depicts the NGFW security engine in the NGFW-SWG processing sequence:  The NGFW security engine includes a rule table that reads rules from top to bottom. The first rule that matches the client’s traffic is applied and all subsequent rules are ignored. The NGFW security engine uses the following match criteria to permit, drop, skip additional inspection, or log flows: Source IP Source port Source zone Source geolocation User Application Destination port Domain category Domain name or server name indication (SNI) Protocol Destination IP Destination network Destination geolocation Schedule For more information, see the  Security rule match criteria  topic. The NGFW security engine performs one of the following actions on matched flows: Permit—Traffic is permitted and sent for further inspection. If this is HTTPS traffic, SSL interception is performed. If this is DNS traffic, DNS filtering is performed Drop—Traffic is denied and the client does not receive a response. Log Only—Traffic is permitted and sent to the next security engine for inspection. This is intended as a temporary action for traffic that needs to be evaluated. After evaluation, update the rule to perform one of the other five actions (permit, drop, skip all, reject, or prohibit). Skip All—Traffic is permitted and bypasses all subsequent security engines. Traffic is sent to have network address translation (NAT) performed or be routed depending on which output interface is specified in the WAN Routing or Internet Routing rule tables. Reject—Traffic is denied and the TCP connection is reset. For non-TCP connections, the client receives an  ICMP Unreachable  response.  Prohibit—Traffic is denied and the client receives an  ICMP Unreachable  response. Default rule The default rule in the NGFW rule table matches any traffic that arrives at the NGFW security engine and applies the  Skip All  action to it. To modify the NGFW rule table in MyAryaka, you can  add site-level NGFW rules  or  create a NGFW ruleset  that can apply rules to multiple sites. DNS filtering DNS traffic that is permitted by the NGFW security engine arrives at the DNS Filtering security engine. DNS traffic is UDP traffic on port 53. If the DNS Filtering security engine encounters traffic on port 53 that cannot be parsed as a DNS packet, it is dropped. The following graphic depicts the DNS Filtering security engine in the NGFW-SWG processing sequence:  The DNS Filtering security engine includes a rule table that reads rules from top to bottom. The first rule that matches the client’s traffic is applied and all subsequent rules are ignored. On a DNS request, the domain being queried is extracted and its category and reputation score are evaluated. If the DNS response comprises an A Record, the IP address in the response is extracted and its reputation score is evaluated. Alternatively, if the DNS response comprises a CNAME, then the domain name is extracted and its category and reputation score are evaluated. The request and response are each evaluated against the rule table to determine if they should be permitted. The DNS Filtering security engine uses the following match criteria to permit, drop, refuse, or log flows: Source zone Domain name Domain category Domain reputation score Schedule For more information, see the  Security rule match criteria  topic. The DNS Filtering security engine performs one of the following actions on matched flows: Permit—Traffic is permitted and sent to its destination. Drop—Traffic is denied and the client does not receive a response. Refuse—Traffic is denied and the client receives DNS error code REFUSED. Log Only—Traffic is permitted and sent to its destination. This is intended as a temporary action for traffic that needs to be evaluated. After evaluation, update the rule to perform one of the other three actions (permit, drop, or refuse). Default rule The default rule in the DNS Filtering rule table matches any traffic that arrives at the DNS Filtering security engine and applies the  Permit  action to it. To modify the DNS Filtering rule table in MyAryaka, you can  add site-level DNS Filtering rules   or  create a DNS Filtering ruleset  that can apply rules to multiple sites. SSL inspection of web traffic HTTPS traffic that is permitted by the NGFW security engine is processed by the Aryaka Advanced Security engine. This engine inspects traffic to determine if it is HTTPS, and, if it is, intercepts the traffic to perform SSL inspection. To bypass SSL inspection for specific types of traffic, you can write a NGFW rule with the action  Skip All . See the  SSL interception for security and SD-WAN optimization  section of the  Dynamic certificate generation and SSL interception  topic for more information. URL Reputation-based filtering HTTPS traffic that is permitted by the NGFW security engine arrives at the URL Reputation security engine. The following graphic depicts the URL Reputation security engine in the NGFW-SWG processing sequence: The URL Reputation security engine includes a rule table that reads rules from top to bottom. The first rule that matches the client’s traffic is applied and all subsequent rules are ignored. The URL Reputation security engine uses the following match criteria to permit, drop, or log traffic: Source IP Source zone User Application URL category (HTTP or HTTPS flows only) URL score (HTTP or HTTPS flows only) URL (HTTP or HTTPS flows only) Destination IP Destination network Schedule For more information, see the  Security rule match criteria  topic. The URL Reputation security engine performs one of the following actions on matched traffic: Permit—Traffic is permitted and sent to the Secure Web Gateway security engine. Drop—Traffic is denied and the client does not receive a response. Log Only—Traffic is permitted and sent to the Secure Web Gateway security engine for inspection. This is intended as a temporary action for traffic that needs to be evaluated. After evaluation, update the rule to perform one of the other four actions (permit, drop, forbidden, or block). Forbidden—Traffic is denied and the client receives a  403 Forbidden  error.  Block—Traffic is denied and the user is presented with the Blocking page. Default rule The default rule in the URL Reputation rule table matches any traffic that arrives at the URL Reputation security engine with a web reputation score of 20 or lower and drops it. Flows with a score above 20 are permitted. To modify the URL Reputation rule table in MyAryaka, you can  add site-level URL Reputation rules  or  create a URL Reputation ruleset  that can apply rules to multiple sites. Secure web gateway Traffic permitted by the URL Reputation security engine arrives at the Secure Web Gateway (SWG) security engine. The SWG security engine is the Layer 7 firewall that performs additional traffic inspection. The following graphic depicts the SWG security engine in the NGFW-SWG processing sequence: The SWG security engine includes a rule table that reads rules from top to bottom. The first rule that matches the client’s traffic is applied and all subsequent rules are ignored. The SWG security engine uses the following match criteria to permit, drop, skip, or log traffic: Source IP Source zone Source geolocation User Application HTTP method HTTP header URL category URL Destination IP Destination network Destination site Destination geolocation Schedule For more information, see the  Security rule match criteria  topic. The SWG security engine performs one of the following actions on matched traffic: Permit—Traffic is permitted and sent to the Anti-Malware security engine for further inspection. Drop—Traffic is denied and the client does not receive a response. Log Only—Traffic is permitted and sent to the next security engine for inspection or to its destination. This is intended as a temporary action for traffic that needs to be evaluated. After evaluation, update the rule to perform one of the other five actions (permit, drop, skip all, forbidden, or block). Skip All—Traffic is permitted and bypasses all subsequent engines. Traffic is sent to have network address translation (NAT) performed or be routed depending on which output interface is specified in the WAN Routing or Internet Routing rule tables. Forbidden—Traffic is denied and the client receives a  403 Forbidden  error.  Block—Traffic is denied and the user is presented with the Blocking page. Default rule The default rule in the SWG rule table matches any traffic that arrives at the SWG security engine and applies the  Skip All  action to it. To modify the SWG rule table in MyAryaka, you can  add site-level SWG rules  or  create a SWG ruleset  that can apply rules to multiple sites. Best practices Consider the following best practices when configuring your Aryaka NGFW-SWG service: Configure all necessary features.  Consider your organization’s requirements and configure all necessary security features to optimize your organization’s network security. Develop rule tables based on your organization’s needs.  Each security engine includes a default rule that is designed to provide a minimum level of security. Aryaka recommends that you create additional security rules based on your organization's security requirements, objectives, and compliance obligations. Test new rules . Test rules you want to add to your security configuration in a safe environment before applying them to your network.  Leverage all identity verification mechanisms.  Use secure identity access portal to authenticate network users and leverage granular access control to apply rules based on their identity, role, and context. Only grant access to resources that are necessary for users to perform their tasks.  Enable SSL inspection.  Do not bypass SSL inspection for your sites' traffic for performance reasons. Identify any issues and adjust your configuration accordingly to maintain your organization’s network security.  Monitor network traffic.  When creating new rules to permit traffic, choose the  Log Only  rule action and then regularly audit your security logs to ensure your rules are operating as expected. If you discover that you need to block a certain type of traffic or create a rule exception due to a false positive, you can modify the rule or create additional rules as needed. See the  Security  topic for general best practices for managing your SASE service.  Configuration The Aryaka security rule framework is designed to allow you to achieve your organization’s security and routing requirements using simple workflows. You can configure each of the features of your NGFW-SWG service to your organization’s specifications in MyAryaka. Complete the procedures included in the following topics to configure your NGFW-SWG service in MyAryaka: 1. Enable NGFW-SWG If you purchased a Unified SASE or Advanced Security license (part of a 2025 Enterprise Billing plan), this entitlement is enabled by default and this step is not necessary.  To enable NGFW-SWG for a site in MyAryaka, click  Sites  in the left navigation pane. On the Sites page, select a site and then click  View  on the Site Details tile. The Site-Add-Ons pane allows you to toggle on entitlements for the site. To enable NGFW-SWG for a remote user region in MyAryaka, click  Universal ZTNA  >  Settings  in the left navigation pane, and then select a region. The User Count & Features pane allows you to toggle on entitlements for the region. See the  Getting Started with Aryaka Unified SASE  guide for a more detailed procedure on enabling entitlements. If the options to enable entitlements are unavailable,  contact Aryaka support  to upgrade your service. 2. Configure Aryaka Secrets Manager Aryaka Secrets Manager (ASM) is a secure, redundant private key store that uses  HashiCorp Vault . This provides the foundation for dynamic certificate generation, which is used for SSL interception of traffic.  To manage your certificate authority, trust store, or dynamic certificates in MyAryaka, click  Config  in the top navigation pane, then  Vault  in the left navigation pane. On the Vault page, click the tile for the feature you want to manage. For detailed information about managing these features, see the  Vault  help topic. 3. Configure AIM To configure AIM in MyAryaka, navigate to  Global Settings  >  Identity Management . For a detailed configuration procedure, see the  Aryaka Identity Managemet  topic. 4. Configure secure identity access portal To configure secure identity access portal and create secure identity access portal rules in MyAryaka, navigate to  Security  >  Settings  >  Secure Identity Access Portal . For a detailed configuration procedure, see the  Configure secure identity access portal  help topic. 5. Configure rule tables, assets, and rulesets To create a security rule for a site in MyAryaka, click  Sites  in the left navigation pane. On the Sites page that appears, select the site that you want to configure a security rule for. On the  siteName  page, the  Security  pane includes a tile for each security engine. Click a tile to view the associated  securityEngine  page where you can add or edit security rules for the selected site. For detailed information about creating site-level security rules, and for an example  rule , see the  Configure site-level security features  help topic. When you add a security rule to a rule table you can leverage  assets  and  rulesets —components that can be created and then reused in your security configuration. The following sections provide more detail on these reusable components. To create an asset that you can reuse as match criteria when creating security rules in MyAryaka, click  Security  >  Asset Management  in the left navigation pane. The Asset Management page includes a tile for each of the asset types that you can create. For detailed information about creating assets, see the  Asset management  help topic. To create a ruleset in MyAryaka, click  Security  in the left navigation pane, then select the security engine you want to create a security  rule  for. The  securityEngine  page allows you to add or edit security rulesets. For detailed information about creating rulesets, and for an example ruleset, see the  Security engine rulesets  help topic. 6. Start security engines Security engines are stopped by default. Once you have configured an engine’s rule table to your specifications, you can start the security engine. Rules included in the engine’s rule table are then applied to network traffic. To start security engines for a site or remote user region in MyAryaka, click  Sites  in the left navigation pane. On the Sites page that appears, select the site that you want to turn on a rule table for. On the  siteName  page, the Security pane includes a tile for each security engine. Click  View  on the tile of the rule table you want to start. On the  ruleTableName  page, click  Start Engine . Monitoring MyAryaka allows you to monitor the usage of the security engines included in your service and to view the security logs for any security events in your network. To monitor your security offering in MyAryaka, navigate to the  Security  >  Monitor  page.   The Security > Monitor page displays a diagram of the security engines in the order in which they receive and inspect traffic. The following is an example of an Engine Sequencing diagram: The Security > Monitor page also displays a series of tables and graphs that provide statistics about permitted and denied traffic in your network. The following is an example of a graph that displays the  number of total, permitted, and denied HTTP requests over one hour: For detailed information about the functionality included on the Security > Monitor page, see the  Monitor security  help topic. To view your security logs in MyAryaka, navigate to the  Security  >  Monitor  page and then use the Quicklink toolbar floating at the bottom of the page to access the Security Logs page. The following graphic displays two security logs where traffic was permitted and one where it was denied: For detailed information about security logs, see the  View security logs  help topic. In this topic Related topics Configure a Next Generation Firewall ruleset Configure a DNS Filtering ruleset Configure a Secure Web Gateway ruleset