---
title: "Create customer-level WAN Routing and Basic Firewall policies"
canonical: "https://docs.aryaka.com/space/KNOW/1510934/Create%20customer-level%20WAN%20Routing%20and%20Basic%20Firewall%20policies"
format: markdown
---
WAN Routing and Basic Firewall policies are used to identify traffic that is bound for a remote destination and to route the traffic to its destination based on the actions specified within the configured policies. You can create WAN Routing and Basic Firewall policies at either the customer level or the site level: Customer-level policies—These policies apply to all the sites that include the zone that the policies were created for. This mechanism is provided as a convenient way to place the same set of policies for all sites. Site-level policies—These policies can override or supplement the policies defined at the customer level for a specific site. To create a site-level policy, see the  Create site-level WAN Routing and Basic Firewall policies  help topic. All WAN Routing and Basic Firewall policies are processed in a user-defined sequence until a policy matches the traffic being processed. The operation defined in the policy is then enforced on the traffic. If the action can not be enforced, then the policy configuration specifies whether the next policy must be looked up if or another action should be taken.  To add customer-level WAN Routing and Basic Firewall policies Log in to MyAryaka. The Home page appears. Click  Security  >  Settings  in left navigation pane. The Settings page appears.  Click  Manage  in the Zones tile. The Zones page appears.   Click an existing zone's tile. The selected zone's details page appears. It displays information about the zone and the WAN Routing and Basic Firewall policy table, which includes any existing policies associated with the zone. Click the  Edit  icon. The page appears in edit mode. Click  Add New  in the policy table. The Policy (Add) page appears for the selected zone. Enter a name and, optionally, a description for the policy in the corresponding fields in the Basic Information pane. Click the  Match Rules  toggle to set it to one of the following: Any—This policy matches  all  traffic entering the zone at the LAN. Explicit—The Match Rule Details table appears.   You must add  preconfigured match rules  to define the traffic match criteria to apply to this policy as follows: Click  Choose  then select a match rule from the drop-down list. Click the  Save  icon. (Optional) Click  Choose  again to add another rule. (Optional) Click the  Delete  icon to remove a rule. Click the  Operation  drop-down list and select one of the following operations for the policy to execute on the matched traffic: Blackhole—Deny the flow and do  not  send a message to the sender. Unreachable—Deny the flow and send an ICMP Unreachable message code 1 to the sender. Prohibit—Deny the flow and send an ICMP Unreachable message code 13 to the sender. Use Security Rules—Security rules decide what should happen to traffic as it crosses segments or zones. This operation allows the ANAP to directly refer to these policies to determine the required action. See  Create internet policies  for detailed information. Route Using Specified Order—This option is available for polices applied to segments. Route the traffic to the available networks in a user-defined sequence. When you select this operation, a list of available networks appears. You must select which networks to include, and prioritize them as follows: Click the  Move  icon next to each network that you want included in the rule, then click  Select/Deselect . Selected networks display a Check icon in their row. Click the  Move  icon next to each network that you want to reposition in the table, then click  Move Up  or  Move Down . The rows of the table are read top down. If the destination of the traffic is reachable using the first selected network in the list, the traffic is routed there. If it is not reachable, the next selected network below it is used for routing if it is reachable. Route Parallel Cost—This option is available for polices applied to segments. Route the traffic to the available networks based on the lowest associated cost. When you select this operation, a list of available networks appears. You must select which networks to include as follows: Click the  Move  icon next to each network that you want included in the rule, then click  Select/Deselect . Selected networks display a Check icon in their row. Click the  Move  icon next to each network that you want to reposition in the table, then click  Move Up  or  Move Down . The rows of the table are read top down. If a destination is reachable by multiple networks at the same cost, the network closer to the top of the table is used. Route Using Longest Prefix Match—This option is available for polices applied to segments. Route the traffic to the available networks based on the greatest number of matching digits in the subnet mask. When you select this operation, a list of available networks appears. You must select which networks to include as follows: Click the  Move  icon next to each network that you want included in the rule, then click  Select/Deselect . Selected networks display a Check icon in their row. Click the  Move  icon next to each network that you want to reposition in the table, then click  Move Up  or  Move Down . The rows of the table are read top down. If two destinations have an identical number of matching digits, the network closer to the top of the table is used. Route Using IPSLA—This option is available for polices applied to segments. Route the traffic to the available networks based on the networks' health. When you select this operation, the VPN Path Aryaka and VPN Path Internet networks appear. You must select which networks to include as follows: Click the  Move  icon next to each network that you want included in the rule, then click  Select/Deselect . Selected networks display a Check icon in their row. Note:  If Aryaka is selected from the list of available networks, and one of the following is enabled:  Use L3 Private Core — Matching traffic is routed over the L3 Private Core. Use L2 Private Core — Matching traffic is routed over the L2 Private Core. Click the  Move  icon next to each network that you want to reposition in the table, then click  Move Up  or  Move Down . The rows of the table are read top down. If both networks are SLA compliant, the network closer to the top of the table is used. Then, use the IPSLA Profile drop-down list to select the  SLA profile  you want to use to determine network preference. (Optional) Select one of the following  If Operation Fails  options to define what action is performed if the original operation is not successful (do  not  select the same operation you selected in the previous step): Aryaka Default—The default behavior is to cycle through all the policies until the last policy is reached. If no match has been found, the security rules are consulted. See  Create internet policies  for detailed information. Blackhole—Deny the flow and do  not  send a message to the sender. Unreachable—Deny the flow and send an ICMP Unreachable message to the sender. Continue Through Policies—Override the routing table lookup and send the traffic flow to the desired destination (another segment or DMZ, or local Internet). Use Security Rules—Security rules decide what should happen to traffic as it crosses segments or zones. This operation allows the ANAP to directly refer to these policies to determine the required action. See  Create internet policies  for detailed information. Click  OK . A draft of the policy is saved and you are returned to the zone details page. The newly created policy appears in the last row of the WAN Routing and Basic Firewall policy table. (Optional) Click  Add New  and repeat steps 6–10 to create another policy.  (Optional) Click the  Move  icon in the Action column of the policy table to reposition the corresponding policy. Policies in the table are searched for a match from the first (top) row to the last (bottom) row. Click  Submit  to send your change request to Aryaka Support to process.   Related topics Configure zones Create site-level WAN Routing and Basic Firewall policies Manage match rules Create internet policies