---
title: "Create internet policies"
canonical: "https://docs.aryaka.com/space/KNOW/1544110/Create%20internet%20policies"
format: markdown
---
Internet policies act on traffic flows between zones or on flows to the internet (either directly or using cloud connectors). There are two types of internet policies: Interzone Firewall policies—Process traffic destined for local segments or DMZs.  Internet Routing policies—Process traffic destined for unknown destinations (that is, any destination with a prefix that is not in any of the routing tables for the site).  The configuration of these two policy types is described in this topic. The following internet policy rules are configured by default: If traffic that is sourced from a zone and is destined for another local zone, the default rule results in the traffic being  blackholed  (that is, the traffic is denied and no message is sent to the sender). You must explicitly configure rules to permit traffic to flow between zones. If traffic that is sourced from a segment is destined for an unknown IP, the default rule results in the traffic being sent to the internet interface. This allows for internet access from a segment without explicit configuration. If traffic that is sourced from a DMZ is destined for an unknown IP, the default rule results in the traffic being blackholed. You must explicitly configure rules to send the traffic to a known interface. To configure an Interzone Firewall policy Open the page for the site you want to create an Interzone Firewall policy for if it is not already open: Log in to MyAryaka. The Home page appears. Click  Sites  in the left navigation pane. The Sites page appears and lists all existing sites. Click the name of the site for which you want to create an Interzone Firewall policy. The selected site's page appears. In the Site Information section, click  View  on the Site Details tile. The Site Details page for the select site appears with the Site Information icon selected by default. Click the  Advanced Settings  icon. The Advanced Settings view of the page appears, which should display the Internet Policies tile. If the tile is  not  present, it may be because you are running a version that does not support the feature.  Contact customer support  to have your account upgraded. Click the  Internet Polices  tile. The page displays the Interzone Firewall policy table and the Internet Routes policy table. Click the  Edit  icon. The page appears in edit mode. Click  Add New  in the Interzone Firewall policy table (this table does not appear if you have not configured a custom zone for the site). The Policy (Add) pane appears. Enter a name and, optionally, a description for the policy in the corresponding fields in the Basic Information pane. Click the  Match Rules  toggle to set it to one of the following: Any—This policy matches  all  traffic entering the zone at the LAN. Explicit—The Match Rule Details table appears. You must add  preconfigured match rules  to define the traffic match criteria to apply to this policy as follows: Click  Choose  then select a match rule from the drop-down list. Click the  Save  icon. (Optional) Click  Choose  again to add another rule. (Optional) Click the  Delete  icon to remove a rule. Click the  Input Zone  drop-down list and select one of the following traffic sources: <customDMZname> —The drop-down list includes the user-defined name of each custom DMZ that you have configured as described in  Configure routing . Select the custom DMZ traffic source to which this policy applies. Any DMZ Zone—Select this option to specifies that the policy applies to all DMZs as the traffic source. This includes the default DMZ and all custom DMZs. <customSegmentName> —The drop-down list includes the user-defined name of each custom segment that you have configured for the site as described in  Configure routing . Select the custom segment traffic source to which this policy applies. Any Segment—Select this option to specify that the policy applies to all segments as the traffic source. This includes the default segment and all custom segments. Any—Select this option to specify that the policy applies to all default and custom sources and DMZs as the traffic source. Click the  Output Zone  drop-down list and select one of the following traffic destinations: <customDMZname> —The drop-down list includes the user-defined name of each custom DMZ that you have configured for the site as described in  Configure routing . Select the custom DMZ traffic source to which this policy applies. Any DMZ Zone—Select this option to specifies that the policy applies to all DMZs as the traffic source. This includes the default DMZ and all custom DMZs. <customSegmentName> —The drop-down list includes the user-defined name of each custom segment that you have configured for the site as described in  Configure routing . Select the custom segment traffic source to which this policy applies. Any Segment—Select this option to specify that the policy applies to all segments as the traffic source. This includes the default segment and all custom segments. Any—Select this option to specify that the policy applies to all default and custom sources and DMZs as the traffic source. Click the  Operation  drop-down list and select the appropriate operation to execute on the traffic flow: Blackhole—Deny the flow and do  not  send a message to the sender. Unreachable—Deny the flow and send an ICMP Unreachable message to the sender. Prohibit—Deny the flow and send an ICMP Prohibit message to the sender. Permit—Allow the flow. Click  OK . The policy is created and is added to the last row of the Interzone Firewall policy table. (Optional) Click  Add New  and repeat steps 7–12 to create another policy. (Optional) Click the  Arrow  icon in the Action column of the table to reposition the corresponding policy. Policies in the table are searched for a match from the first (top) row to the last (bottom) row.  Do one of the following: Click  Save Draft  to save a draft of the entries made on this page. Click the  Next  icon or the  Advanced Settings  icon to continue your site configuration on one of other Advanced Settings pages as described in  Configure Advanced Settings . Click  Submit  to send a change request with the entries made on this page to Aryaka support. To configure an Internet Routing policy Open the page for the site you want to create an Internet Routing policy for if it is not already open: Log in to MyAryaka. The Home page appears. Click  Sites  in the left navigation pane. The Sites page appears and lists all existing sites. Click the name of the site for which you want to create an Internet Routing policy. The selected site's page appears. In the Site Information section, click  View  on the Site Details tile. The Site Details page for the select site appears with the Site Information icon selected by default. Click the  Advanced Settings  icon. The Advanced Settings view of the page appears, which should display the Internet Policies tile. If the tile is  not  present, it may be because you are running a version that does not support the feature.  Contact customer support  to have your account upgraded. Click the  Internet Polices  tile. The page displays the Interzone Firewall policy table and the Internet Routes policy table. Click the  Edit  icon. The page appears in edit mode. Click  Add New  in the Internet Routes policy table. The Policy (Add) pane appears. Enter a name and, optionally, a description for the policy in the corresponding fields in the Basic Information pane. Click the  Match Rules  toggle to set it to one of the following: Any—This policy matches  all  traffic entering the zone at the LAN. Explicit—The Match Rule Details table appears. You must add  preconfigured match rules  to define the traffic match criteria to apply to this policy as follows: Click  Choose  then select a match rule from the drop-down list. Click the  Save  icon. (Optional) Click  Choose  again to add another rule. (Optional) Click the  Delete  icon to remove a rule. Click the  Input Zone  drop-down list and select one of the following traffic sources: <customDMZname> —The drop-down list includes the user-defined name of each custom DMZ that you have configured for the site as described in  Configure routing . Select the custom DMZ traffic source to which this policy applies. Any DMZ Zone—Select this option to specify that the policy applies to all DMZs as the traffic source. This includes the default DMZ and all custom DMZs. <customSegmentName> —The drop-down list includes the user-defined name of each custom segment that you have configured for the site as described in  Configure routing . Select the custom segment traffic source to which this policy applies. Any Segment—Select this option to specify that the policy applies to all segments as the traffic source. This includes the default segment and all custom segments. Any—Select this option to specify that the policy applies to all default and custom sources and DMZs as the traffic source. Click the  Operation  drop-down list and select the appropriate operation to execute on the traffic flow: Blackhole—Deny the flow and do  not  send a message to the sender. Unreachable—Deny the flow and send an ICMP Unreachable message to the sender. Prohibit—Deny the flow and send an ICMP Prohibit message to the sender. Permit—Allow the flow. (Optional) Click the  If Operations Fails  drop-down list and select and operation to execute on the traffic flow if the previously-selected operation fails (do  not  select the same operation you selected in the previous step): Aryaka Default—The default behavior is to cycle through all the Internet Routing policies until the last policy is reached. If no match has been found, the traffic is blackholed. Blackhole—Deny the flow and do  not  send a message to the sender. Unreachable—Deny the flow and send an ICMP Unreachable message to the sender. Continue Through Policies—Override the routing table lookup and send the flow to the desired destination (another segment or DMZ, or internet locally). Use Security Rules—Use either Interzone Firewall or Internet Routing policies. This operation allows the ANAP to directly reference these policies to determine the required action. If you do not create custom internet policies, the default policy is used. Click  OK . The policy is created and is added to the last row of the Internet Routes policy table. (Optional) Click  Add New  and repeat steps 7–12 to create another policy. (Optional) Click the  Arrow  icon in the Action column of the table to reposition the corresponding policy. Policies in the table are searched for a match from the first (top) row to the last (bottom) row.  Do one of the following: Click  Save Draft  to save a draft of the entries made on this page. Click the  Next  icon or the  Advanced Settings  icon to continue your site configuration on one of other Advanced Settings pages as described in  Configure Advanced Settings . Click  Submit  to send a change request with the entries made on this page to Aryaka support. Related topics Configure routing Create site-level WAN Routing and Basic Firewall policies Create customer-level WAN Routing and Basic Firewall policies Related videos Add an internet policy