---
title: "Getting Started with Aryaka Unified SASE as a Service"
canonical: "https://docs.aryaka.com/space/KNOW/136773659/Getting%20Started%20with%20Aryaka%20Unified%20SASE%20as%20a%20Service"
format: markdown
---
Aryaka Unified SASE as a Service integrates networking and security to provide optimal performance in a flexible and cost-effective solution. The security component of this solution is Aryaka Next Generation Firewall and Secure Web Gateway (NGFW-SWG), which protects both on premises and remote users by inspecting all network traffic and applying user-defined security controls. This also includes Intrusion Prevention System (IPS) and Anti-Malware security controls. For additional security, you can add Advanced Security, which includes Cloud Access Security Broker (CASB) and Data Loss Prevention (DLP) security controls.  This document provides an overview of the key features included with each of these services and describes how to get started with  configuring your service  and  monitoring your service  in MyAryaka.  Aryaka Unified SASE as a Service entitlements The security component of Aryaka Unified SASE as a Service currently comprises the following services: NGFW-SWG IPS Anti-Malware You can also opt for Aryaka’s Advanced Security, which comprises the following services: CASB DLP These entitlements are described in the sections that follow. NGFW-SWG NGFW-SWG protects users from internet-born threats and evolving cyber threats by intercepting user traffic and applying various security controls to network traffic. Inbound and outbound traffic is routed through a series of security engines that control traffic based on user-defined rule tables. When you configure your rule tables you can leverage reusable components to accommodate complex and scalable configurations. You can also identify and control network user access by configuring an identity provider and secure identity access portal to authenticate authorized users and block unauthorized users.  IPS IPS provides additional security by monitoring the events occurring in your network to identify and prevent security threats and attacks. The three IPS security engines (LAN-Side Basic IPS, WAN-Side Basic IPS, and Advanced IPS) identify potential security threats using  signatures —unique patterns and identifiers that were present in past security incidents. Anti-Malware Anti-Malware provides additional security by inspecting inbound and outbound traffic for known malware, viruses, and file-based threats. The Anti-Malware security engine classifies a file's reputation as either good, bad, or unknown. Files are separated into sections of data that are classified one at a time to reduce the bandwidth required for classifying large files. If a Bad section is detected, the transfer of the file can be blocked without the rest of the file needing to be classified.  CASB Aryaka’s Advanced Security offering includes CASB, which provides visibility and control for SaaS application traffic. The two CASB security engines (SaaS Apps Access Control and Tenant Restriction) enforce access control and, if required, tenant restriction on network traffic to SaaS applications. You can also identify unsanctioned SaaS applications that are being accessed by your users and block this access if desired. DLP Aryaka’s Advanced Security offering includes DLP, which protects your organization from inadvertent and malicious data exposure. The DLP security engine inspects network traffic for data patterns indicative of sensitive information. This allows your organization to prevent unauthorized access and transmission of information such as financial, healthcare, and intellectual property. Configure Aryaka Unified SASE as a Service Complete the procedures in each of the following sections to configure Aryaka Unified SASE as a Service to your specifications.  Enable entitlements Configure Aryaka Secrets Manager Configure Aryaka Identity Management Configure secure identity access portal Configure rule tables Create assets  (optional) Create rulesets  (optional) Enable rule tables We recommend performing the configuration in the order listed. Note that if you enable a rule table before you configure it, the Aryaka default rule is applied to your traffic. 1. Enable entitlements Each Aryaka Unified SASE as a Service entitlement can be enabled or disabled for each of your sites or UZTNA regions.  To enable entitlements for a site in MyAryaka Click  Sites  in the left navigation pane. The Sites page appears. Click the name of the site you want to enable entitlements for. The Site: <s iteName > page appears.  In the Site Information pane, click  View  on the Site Details tile. The Site Details: <s iteName > page appears in read-only mode.  Click the  Edit  icon. The page appears in edit mode.  In the Site Add-Ons pane, click the toggles for the entitlements you want to turn on for the site.  Click  Submit .  To enable entitlements for a UZTNA region Click  Universal ZTNA  >  Settings  in the left navigation pane. The Settings page appears. Click the name of the region you want to enable entitlements for. The < regionName > page appears in read-only mode.  In the Region Entitlements pane, click  Edit . The pane displays in edit mode. Click the toggles for the entitlements you want to turn on for the region. Click the  Apply Changes  drop-down list to specify whether the configuration should apply only to new entities or to all existing entities. Click  Submit .  2. Configure Aryaka Secrets Manager Aryaka performs SSL interception of traffic that matches user-defined rules. To achieve this, Aryaka performs on-demand dynamic generation of server certificates. Aryaka Secrets Manager (ASM) is a secure, redundant private key store that uses  HashiCorp Vault  and provides the foundation for dynamic certificate generation.  Each Aryaka customer is assigned a Customer Certificate Authority by default. ASM generates the private key for the customer and stores it securely. This private key is used to generate a certificate signing request (CSR). By default, the CSR is signed by an Aryaka intermediate certificate authority for ease of onboarding. If you prefer, the CSR can be signed by a customer-selected certificate authority. For more details about ASM, dynamic certificate generation, and SSL interception, see the  Dynamic certificate generation and SSL interception  topic.  To manage your certificate authority, trust store, or dynamic certificates in MyAryaka, click  Global Settings  in the left navigation pane. On the Gloabl Settings page, click the feature you want to manage in the Vault tile. For detailed information about managing these features, see the  Vault  help topic. 3. Configure Aryaka Identity Management Aryaka Identity Management (AIM) is a centralized, integrated Aryaka service that can be connected to your directory service. After it is configured, AIM can perform the following functions: Retrieve a list of users and user groups from your directory service, which can be used as match criteria in security rules. Authenticate the network user against the directory service. Redirect the network user to an external identity provider (IdP), such as Azure or Okta. Identify the user groups associated with a remote user accessing the network using Aryaka Private Access, explicit proxy, or Aryaka Agent. To configure AIM in MyAryaka, click  Global Settings  in the left navigation pane. On the Global Settings page, click  Manage  in the Aryaka Identity Management tile. For a detailed configuration procedure, see the  AIM overview  and related topics.  4. Configure secure identity access portal Secure identity access portal uses browser-based activity to intercept network users' traffic and present them with a login page that allows them to identify themselves to the network. The secure identity access portal allows users to log in as a known user with their email address or to access the network as a guest. When users choose to log in as a known user, the secure identity access portal works with Aryaka Identity Management to authenticate them or to redirect them to your external identity provider. After users log in as a known user or a guest, they can connect to the internet and their traffic is subject to all relevant security rules. When you configure the secure identity access portal, you can also create policies to allow network devices or activities to bypass the secure identity access portal.   For more details about secure identity access portal, see the  Network user identity management  topic.  To configure secure identity access portal and create secure identity access portal policies in MyAryaka, click  Security  >  Settings  in the left navigation pane. On the Settings page, click  Manage  in the Secure Identity Access Portal tile. For a detailed configuration procedure, see the  Configure secure identity access portal  help topic.  5. Configure rule tables Security engines provide controls on user traffic, such as flow filtering based on IP, domain, URL, and file reputation. Each security engine has its own rule table that allows you to define context-appropriate match criteria and specify the actions to take on matched traffic. For example, if you want to block high risk domains at a site, you can modify the NGFW rule table for that site without being concerned about rules in other tables. Each rule table can contain multiple user-defined security rules, but, at minimum, each table contains a default rule that is designed to account for traffic that does not match other rules. Rules are evaluated in a top-down manner (that is, from the first table row to the last table row, which contains the default rule) until a match is found for the traffic. If traffic matches a user-defined rule, the action associated with the rule is performed on the traffic. In general, the action can be to allow, drop, or log the traffic. If traffic does not match a user-defined rule, the following default rules are applied to traffic:  Rule table Default rule DNS Filtering Traffic is permitted. Next Generation Firewall Traffic is allowed to bypass all subsequent processing. Secure Web Gateway Traffic is allowed to bypass all subsequent processing. Anti-Malware File reputations are not verified and traffic is permitted. LAN-Side Basic IPS Traffic is not inspected by the IPS engine and is permitted. WAN-Side Basic IPS Traffic is not inspected by the IPS engine and is permitted. Advanced IPS Traffic is not inspected by the IPS engine and is permitted. SaaS Apps Access Control Traffic is permitted. Tenant Restriction Header manipulation is not performed and traffic is permitted.  Data Loss Prevention Traffic is permitted.  For more details about security engines and rule tables, see the  Security ,  NGFW-SWG ,  IPS ,  Anti-Malware ,  CASB , and  DLP  topics.  To create a security rule for a site in MyAryaka, click  Sites  in the left navigation pane. On the Sites page that appears, select the site that you want to configure a security rule for. On the < siteName > page, the  Security  pane includes a tile for each security engine. Click a tile to view the associated  securityEngine  page where you can add or edit security rules for the selected site. For detailed information about creating site-level security rules, see the  Configure site-level security features  help topic. When you add a security rule to a rule table you can leverage  assets  and  rulesets —components that can be created and then reused in your security configuration. The following sections provide more detail on these reusable components. Create assets You can use assets as match criteria in your security rules. For example, you can define a User Group asset with a list of network users and then use that asset in a security rule to permit or deny certain types of traffic for the users included in the group. Configured assets can be reused in different security rules. The following table lists the types of assets you can define and reuse: Asset Types Zones Domains Web Categories Reputation scores Schedules IPs Ports Protocols URLs Users User groups Geolocations Site classes Match rules HTTP headers SaaS applications SaaS application categories SaaS organizations SaaS suites SaaS application user functions For more details about the types of match criteria you can create assets for, see the  Security rule match criteria  topic. To create an asset that you can reuse as match criteria when creating security rules in MyAryaka, click  Security  >  Asset Management  in the left navigation pane. The Asset Management page includes a tile for each of the asset types that you can create. For detailed information about creating assets, see the  Asset management  help topic. Create rulesets When you create security rules, you can create a rule for an individual site or you can create a ruleset that can apply one or more rules to multiple sites. For details about rulesets, see the  Security  topic.  To create a ruleset in MyAryaka, click  Security  in the left navigation pane, then select the security engine you want to create a ruleset for. For detailed information about creating rulesets, see the  Security engine rulesets  help topic. 6. Enable rule tables After you have configured a rule table to your specifications, you can enable the rule table for a site or private access node. To enable rule tables for a site or private access node in MyAryaka, click  Sites  in the left navigation pane. On the Sites page that appears, select the site that you want to enable a rule table for. On the  siteName  page, the  Security  pane includes a tile for each security engine. Click  View  on the tile of the rule table you want to enable. On the < ruleTableName > page, click  Start Engine .  Monitor Aryaka Unified SASE as a Service To monitor the usage of the security engines included in your service, navigate to the  Security  >  Monitor  page of MyAryaka. The Security page displays an Engine Sequencing diagram, which displays the security engines in the order in which they receive and inspect traffic, and a series of tables and graphs, which display statistics about permitted and denied traffic for the various security engines. You can select a specific scope (a site or a node) and time period to view the associated data.  The following graphic shows the top section of the Security > Monitor page for a site named Bangalore (click to enlarge): The following graphic shows the bottom section of the Security > Monitor page for the same Bangalore site (click to enlarge): For detailed information about the functionality included on the Security page, see the  Monitor security  help topic. To view the Security Logs page, click the  Security Logs  icon in the Quicklink toolbar at the bottom of the Security page. The Security Logs page displays a timeseries graph and a table of the network events that required a security action to be taken. For detailed information about security logs, see the  View security logs  help topic.  Send feedback to:  docs@aryaka.com   Get more information:  sales@aryaka.com In this topic