---
title: "IPS"
canonical: "https://docs.aryaka.com/space/KNOW/1275527252/IPS"
format: markdown
---
SD-WAN subscriptions include  Basic Firewall . For additional security, Aryaka offers Unified SASE, which includes Next Generation Firewall - Secure Web Gateway ( NGFW-SWG ),  Anti-Malware , and an Intrusion Prevention System (IPS). You can also purchase Advanced Security, which includes  Cloud Access Security Broker (CASB)  and  Data Loss Prevention (DLP) . IPS protects your sites and remote users by using signature-based detection to monitor network traffic for potential security incidents across 53 categories, including those related to Trojans, worms, shellcode exploits, and adware. With IPS, your sites and remote users have their inbound and outbound traffic inspected by three IPS security engines (LAN-Side Basic IPS, WAN-Side Basic IPS, and Advanced IPS) that apply user-defined controls to network traffic.  This document provides an overview of the Aryaka’s IPS security offering and describes how to get started with  configuring your service  and  monitoring your service  in MyAryaka.  Prerequisites A site or remote user license for Unified SASE. Use cases The following are the two primary use cases for IPS: Advanced threat protection.  IPS provides an extra layer of security to protect your sites and remote users from cyber attacks. It uses signature-based detection to detect and prevent security threats and attacks in real time, before they can harm your organization. Threat intelligence updates.  The signatures used to identify potential security events are automatically updated daily to provide protection from the latest threats.  Features IPS includes the following functionality: Signature-based detection—Traffic is continuously inspected for malicious intrusion activities. Potential threats are blocked before they can harm digital assets. Packet anomaly detection—Protocol deviations from expected standards are identified based on signatures. System administrators are then alerted so that they can perform remediation. Common vulnerability exposure (CVE) protection—Known vulnerabilities and exploits are mitigated to reduce an enterprise's attack surface. Command and control (C2) protection—Communication with C2 servers and botnet activities are detected and blocked to protect internal assets. DoS and DDoS protection—Signature-based detection and rate-limiting mechanisms are used to protect an enterprise’s network assets from DoS and DDoS attacks and to prevent downtime. These security functions are performed by the following IPS security engines: LAN-Side Basic IPS—Monitors outbound traffic at the LAN perimeter. WAN-Side Basic IPS—Monitors inbound traffic at the public-facing perimeter. Advanced IPS—Determines if SSL inspection is required and inspects outbound traffic. The following sections provide an overview of IPS classification and describes each of the IPS security engines. IPS classification IPS aims to prevent security threats and attacks by monitoring the events occurring in your network for potential security incidents. Any potential incidents are logged and and attempt is made to stop the incident. Potential security incidents are identified using signatures—unique patterns and identifiers that were present in past security incidents. Aryaka has partnered with a third-party provider, Proofpoint, for the commercial use of their  Emerging Threat Pro (ET Pro) Ruleset , which is updated daily to provide protection from the latest threats. The ET Pro Ruleset is maintained using a global malware exchange, automated sandboxing, a global sensor network, decades of threat intelligence experience, and community input. The ruleset is optimized for Suricata, and Proofpoint is a platinum Open Information Security Foundation sponsor and Suricata contributor. Aryaka uses three collections of signatures from Proofpoint to monitor network traffic and identify any patterns that indicate a potential security threat. The three signature collections correspond to the following profiles: Basic—Provides a high level of security while ensuring optimized system performance. Includes approximately 17,000 signatures.   Moderate—Provides a balance between the basic and advanced profiles. Includes approximately 19,000 signatures.   Advanced—Provides the highest level of security protection against known and emerging threats. System performance can be impacted due to increased examination of traffic. Includes approximately 22,000 signatures.   Aryaka modifies these signature collections so that they can be used by the three IPS security engines (LAN-Side Basic IPS, WAN-Side Basic IPS, and Advanced IPS). The resulting nine signature collections are referred to as signature  feeds . By default, each IPS security engine uses the basic signature feed. In MyAryaka, you can  view details of the signatures in each feed ,  change the signature feed that each IPS security engine uses ,  create IPS Modification policies  to disable or change the verdicts for specific signatures within a feed, and  change the variables included in each signature .  The IPS security engines monitor network traffic for these known signatures and generate one of the following verdicts for the traffic, which includes a recommended action: Pass—Permit traffic. Drop—Deny traffic and generate an IPS event log. Reject—Deny traffic, send a message to the sender, and generate an IPS event log.  Alert—Permit traffic and generate an IPS event log.  You can configure IPS security rules for each security engine to determine whether to enforce the verdict that is associated with the signature. LAN-Side Basic IPS security engine The LAN-Side Basic IPS security engine permits or denies a site's outbound traffic at the LAN perimeter by inspecting the traffic for signatures that indicate a potential threat. The following graphic depicts the processing sequence of the LAN-Side Basic IPS engine and the other NGFW-SWG engines:  This engine uses a rule table that contains rules that are read from top to bottom. The first rule that matches the client’s traffic is applied and all subsequent rules are ignored. This engine uses the following match criteria to skip inspection, permit, drop, or log flows: Source IP Source port Source zone Destination port Protocol Destination IP Schedule For more information about match criteria, see the  Security rule match criteria  topic. For more information about the security rule framework and rule tables, see the  Security  topic.  The LAN-Side Basic IPS security engine performs one of the following actions on matched flows: Skip IPS—Traffic is not inspected by the IPS engine and is instead passed to the next security engine. Enforce Verdict—Traffic is inspected by the IPS engine and the verdict is enforced. Only traffic with a verdict of  Pass  or  Alert  is permitted and passed to the next security engine. For traffic that is denied, you can select one of the following drop actions: Aryaka Default (Drop)—Traffic is denied and the client does not receive a response. Reject—Traffic is denied and the TCP connection is reset. For non-TCP connections, the client receives an  ICMP Unreachable  response. Prohibit—Traffic is denied and the client receives an  ICMP Unreachable  response.  Ignore Verdict—Traffic is inspected by the IPS engine, but the verdict is not enforced. All traffic is permitted and passed to the next security engine.  Log Only—Traffic is inspected by the IPS engine, but the verdict is not enforced. All traffic is permitted and passed to the next security engine. This is intended as a temporary action for traffic that needs to be evaluated. After evaluation, update the rule to perform one of the other three actions (skip IPS, enforce verdict, or ignore verdict). Default rule The default LAN-Side Basic IPS rule matches any traffic that arrives at the rule table and applies the  Log Only  action to it. To modify the LAN-Side Basic IPS rule table, you can  add site-level LAN-Side Basic IPS rules  or  create a LAN-Side Basic IPS ruleset . WAN-Side Basic IPS security engine The WAN-Side Basic IPS security engine permits or denies a site's inbound traffic at the public-facing perimeter by inspecting the traffic for signatures that indicate a potential threat. The following graphic depicts the processing sequence of the WAN-Side Basic IPS engine: This engine uses a rule table that contains rules that are read from top to bottom. The first rule that matches the client’s traffic is applied and all subsequent rules are ignored. This engine uses the following match criteria to skip inspection, permit, drop, or log flows: Source IP Source port Source zone Destination port Protocol Destination IP Schedule For more information about match criteria, see the  Security rule match criteria  topic. For more information about the security rule framework and rule tables, see the  Security  topic. The WAN-Side Basic IPS security engine performs one of the following actions on matched flows: Skip IPS—Traffic is not inspected by the IPS engine and is instead passed to the next security engine. Enforce Verdict—Traffic is inspected by the IPS engine and the verdict is enforced. Only traffic with a verdict of  Pass  or  Alert  is permitted and passed to the next security engine. For traffic that is denied, you can select one of the following drop actions: Aryaka Default (Drop)—Traffic is denied and the client does not receive a response. Reject—Traffic is denied and the TCP connection is reset. For non-TCP connections, the client receives an  ICMP Unreachable  response. Prohibit—Traffic is denied and the client receives an  ICMP Unreachable  response.  Ignore Verdict—Traffic is inspected by the IPS engine, but the verdict is not enforced. All traffic is permitted and passed to the next security engine. Log Only—Traffic is inspected by the IPS engine, but the verdict is not enforced. All traffic is permitted and passed to the next security engine. This is intended as a temporary action for traffic that needs to be evaluated. After evaluation, update the rule to perform one of the other three actions (skip IPS, enforce verdict, or ignore verdict). Default rule The default WAN-Side Basic IPS rule matches any traffic that arrives at the rule table and applies the  Log Only  action to it. To modify the WAN-Side Basic IPS rule table, you can  add site-level WAN-Side Basic IPS rules  or  create a WAN-Side Basic IPS ruleset . Advanced IPS security engine The Advanced IPS security engine permits or denies outbound traffic by inspecting it for signatures that indicate a potential threat. The following graphic depicts the processing sequence of the Advanced IPS engine, which receives traffic after inspection by the Anti-Malware security engine: This engine uses a rule table that contains rules that are read from top to bottom. The first rule that matches the client’s traffic is applied and all subsequent rules are ignored. This engine uses the following match criteria to to skip inspection, permit, drop, or log flows: Source IP Source port Source zone User Application Destination port Domain name Protocol Destination IP Schedule For more information about match criteria, see the  Security rule match criteria  topic. For more information about the security rule framework and rule tables, see the  Security  topic. The Advanced IPS security engine performs one of the following actions on matched flows: Skip IPS—Traffic is not inspected by the IPS engine and is instead passed to the next security engine. Enforce Verdict—Traffic is inspected by the IPS engine and the verdict is enforced. Only traffic with a verdict of  Pass  or  Alert  is permitted and passed to its destination. Ignore Verdict—Traffic is inspected by the IPS engine, but the verdict is not enforced. All traffic is permitted and passed to its destination.  Log Only—Traffic is inspected by the IPS engine, but the verdict is not enforced. All traffic is permitted and passed to the next security engine. This is intended as a temporary action for traffic that needs to be evaluated. After evaluation, update the rule to perform one of the other three actions (skip IPS, enforce verdict, or ignore verdict). Default rule The default Advanced IPS rule matches any traffic that arrives at the rule table and applies the  Log Only  action to it. To modify the Advanced IPS rule table, you can  add site-level Advanced IPS rules  or  create an Advanced IPS ruleset . Best practices Develop rule tables based on your organization’s needs.  The IPS security engines include default rules that continuously monitor network traffic and generate verdicts based on whether traffic matches known signatures. These default rules are meant to inspect all traffic and detect intrusions, without dropping traffic. Aryaka recommends that you review the verdicts generated by the IPS security engines and create additional security rules based on your organization's needs. Start the IPS security engines for your sites.  Once you have configured rule tables based on your organization’s needs, start the three IPS security engines for each of your subscribed sites. Do not disable the engines for performance reasons. If you are experiencing issues, determine the source of the problem and adjust your configuration accordingly. Enable SSL decryption for your sites.  The Advanced IPS security engine receives decrypted HTTPS traffic. You must enable SSL decryption for your sites to ensure it is inspected by this engine. See the  Dynamic certificate generation and SSL interception  topic for details about how Aryaka implements SSL interception.  Test new rules . Test rules you want to add to your IPS configuration in a safe environment before applying them to your network. Monitor network traffic.  When creating new rules to permit traffic, choose the  Log Only  rule action and then regularly audit your security logs to ensure your rules are operating as expected. If you discover that you need to block a certain type of traffic or create a rule exception due to a false positive, you can modify the rule or create additional rules as needed. Verify that signatures are correctly applied to your sites.  When reviewing logs or testing new rules for a site, verify that expected signatures are included in the signature feed that is applied to the site. Signature feeds are applied to sites using a  Signature template . See the  Security  topic for general best practices for managing your SASE service. Configuration The Aryaka security rule framework is designed to allow you to achieve your organization’s security and routing requirements using simple workflows. You can configure your IPS service to your organizations’s specifications in MyAryaka by enabling the entitlement, configuring the rule tables for each of your sites, and then starting the security engines for each of your sites. If needed, you can also create an IPS Signature template to modify the signature feed that each IPS security engine uses when inspecting traffic for a site, configure IPS Modification policies to enable, disable, or change the verdict for one or more signatures included in the signature feed, and configure IPS settings to modify the variables included in each signature. These processes are described in the following sections. Enable your IPS entitlement If you purchased a Unified SASE or Advanced Security license (part of a 2025 Enterprise Billing plan), this entitlement is enabled by default and this step is not necessary.  To enable IPS for a site in MyAryaka, click  Sites  in the left navigation pane. On the Sites page, select a site and then click  View  on the Site Details tile. The Site Add-Ons pane allows you to toggle on entitlements for the site. To enable Aryaka IPS for a remote user region in MyAryaka, click  Universal ZTNA  >  Settings  in the left navigation pane, and then select a region. The User Count & Features pane allows you to toggle on entitlements for the region. See the  Getting Started with Aryaka Unified SASE  guide for a more detailed procedure on enabling entitlements.  Configure rule tables, assets, and rulesets To create an IPS security rule for a site in MyAryaka, click  Sites  in the left navigation pane. On the Sites page that appears, select the site that you want to configure a security rule for. On the  siteName  page, the  Security  pane includes a tile for each security engine. Click  View  on one of the IPS tiles (WAN-Side Basic IPS, LAN-Side Basic IPS, or Advanced IPS) to view the associated  securityEngine  page where you can add or edit security rules for the selected site. For detailed information about creating site-level security rules, and for an example  rule , see the  Configure site-level security features  help topic. When you add a security rule to a rule table you can leverage  assets  and  rulesets —components that can be created and then reused in your security configuration. The following sections provide more detail on these reusable components. To create an asset that you can reuse as match criteria when creating security rules in MyAryaka, click  Security  >  Asset Management  in the left navigation pane. The Asset Management page includes a tile for each of the asset types that you can create. For detailed information about creating assets, see the  Asset management  help topic. To create a ruleset in MyAryaka, click  Security  in the left navigation pane, then click the IPS security engine tile (WAN-Side Basic IPS, LAN-Side Basic IPS, or Advanced IPS) that you want to create a security rule for. The  securityyEngine  page allows you to add or edit security rulesets. For detailed information about creating rulesets for each IPS engine, see the  Configure a WAN-Side Basic IPS ruleset ,  Configure a LAN-Side Basic IPS ruleset , and the  Configure an Advanced IPS ruleset  help topics. For general information about rulesets, and to view an example, see the  Security engine rulesets  help topic.  Start security engines After you have configured the rule table for a site to your specifications, you can start the security engine in MyAryaka. Click  Sites  in the left navigation pane. On the Sites page that appears, select the site that you want to start the security engine for. On the  siteName  page, the Security pane includes a tile for each security engine. Click  View  on the tile of the IPS  rule  table you want to start (WAN-Side Basic IPS, LAN-Side Basic IPS, or Advanced IPS), then  Start Engine  on the  ruleTableName  page.  Create a Signature template By default, each IPS security engine uses the basic signature feed, which provides a high level of security while ensuring optimized system performance. This feed includes approximately 17,000 signatures. If you want an IPS security engine to use a different feed for one or more sites, you can create an IPS Signature template. To create an IPS Signature template in MyAryaka, click  Security  >  IPS  in the left navigation pane, click  Manage  in the  IPS Signature Management  tile, then click the  Signature Templates  tile. The Signature Templates page allows you to add or edit IPS Signature templates. For detailed information about creating an IPS Signature template, see the  Configure IPS Signature templates  help topic. Create IPS Modification policies Each signature included in a signature feed is assigned a status and verdict. A signature's status (either  Enabled  or  Disabled ) determines whether its verdict is applied to rule matches. A signature’s verdict (for example,  Pass  or  Drop ) is based on the type and severity of the threat that the signature is indicative of and it determines whether traffic is permitted or dropped. If you want to change a signature’s status or verdict, you can create an IPS Modification policy.  To create an IPS Modification policy in MyAryaka, click  Security  >  IPS  in the left navigation pane, click  Manage  in the  IPS Signature Management  tile, then click the  IPS Modification Policies  tile. The IPS Modification Policies page allows you to add or edit IPS Modification policies. For detailed information about creating IPS Modification policies, see the  Configure IPS Modification policies  help topic.  Configure IPS settings The IPS security engines use IP address and port variables to identify and respond to potential security threats in a targeted manner. These variables represent a collection of IP addresses and ports, respectively, that reflect your network environment. The combination of these variables is used to match incoming packets to the signatures included in the signature feed that is applied to the given site. Although you cannot add or delete signature feeds, you can change the variables included in the signatures by modifying IPS settings. This can be done globally (applies to all sites) for IP address and port variables, or for an individual site to modify the Home Network and External Network variables. To modify global IPS settings in MyAryaka, click  Security  >  IPS  in the left navigation pane, click  Manage  in the  IPS Settings  tile. The IPS Settings page allows you to edit global IPS settings. For detailed information about modifying global IPS settings, see the  Configure global IPS settings  help topic.  To modify site-level IPS settings in MyAryaka, Click  Sites  in the left navigation pane. On the Sites page that appears, select the site for which you want to modify IPS settings. On the  siteName  page, expand the  Security  section and click  View  on the IPS Settings tile. The IPS Settings page allows you to edit IPS settings for the selected site. For detailed information about modifying site-level IPS settings, see the  Configure site-level security features  help topic.  Monitoring MyAryaka allows you to monitor the usage of the IPS security engines included in your service and to view security logs for events in your network. To monitor your IPS security offering in MyAryaka, navigate to the  Security  >  Monitor  page. This page displays a diagram of the security engines in the order in which they receive and inspect traffic and a series of tables and graphs that provide statistics about permitted and denied traffic in your network. For detailed information about the functionality included on the Security page, see the  Monitor security  help topic. Click one of the IPS security engines (LAN-Side Basic IPS, WAN-Side Basic IPS, or Advanced IPS) in the Engine Sequencing diagram. The page displays an Engine Sequencing diagram and a series of graphs that are specific to the selected IPS security engine. For detailed information about the functionality included on these pages, see the  Monitor LAN-Side Basic IPS security engine ,  Monitor WAN-Side Basic IPS security engine , and the  Monitor Advanced IPS security engine  help topics. To view your security logs in MyAryaka, navigate to the  Security  >  Monitor  page and then use the Quicklink toolbar floating at the bottom of the page to access the Security Logs page. The following graphic displays two security logs where traffic was permitted and one where it was denied: You can use the advanced filter to display, for example, only logs where a specific action was taken after inspection by one of the IPS security engines. For detailed information about security logs, see the  View security logs  help topic. In this topic Related topics Configure a WAN-Side Basic IPS ruleset Configure a LAN-Side Basic IPS ruleset Configure an Advanced IPS ruleset