---
title: "Create site-level WAN Routing and Basic Firewall policies"
canonical: "https://docs.aryaka.com/space/KNOW/1544191/Create%20site-level%20WAN%20Routing%20and%20Basic%20Firewall%20policies"
format: markdown
---
WAN Routing and Basic Firewall policies are used to identify traffic that is bound for a remote destination and to route the traffic to its destination based on the actions specified within the configured policies.  You can create WAN Routing and Basic Firewall policies at either the customer level or the site level: Customer-level policies—These policies apply to all the sites that include the zone that the policies were created for. This mechanism is provided as a convenient way to place the same set of policies for all sites. To create a customer-level policy, see the  Create customer-level WAN Routing and Basic Firewall policies  help topic.  Site-level policies—These policies can override or supplement the policies defined at the customer level for a specific site.  All WAN Routing and Basic Firewall policies are processed in a user-defined sequence until a policy matches the traffic being processed. The operation defined in the policy is then enforced on the traffic. If the action can not be enforced, then the policy configuration specifies whether the next policy must be looked up if or another action should be taken. To add site-level WAN Routing and Basic Firewall policies Open the page for the site you want to create a WAN routing and Basic Firewall policy for if it is not already open: Log in to MyAryaka. The Home page appears.  Click  Sites  in the left navigation pane. The Sites page appears and lists all existing sites. Click the name of the site for which you want to create a new policy. The selected site's page appears. In the Site Information section, click  View  on the Site Details tile. The Site Details page for the select site appears with the Site Information icon selected by default. Click the  Advanced Settings  icon. The Advanced Settings view of the page appears and displays the WAN Routing and Basic Firewall tile. Note : If the tile does  not  appear, you may be running a version that does not support this feature.  Contact customer support  to have your account upgraded. Click the  WAN Routing and Basic Firewall  tile. The page displays a tile for each of your configured zones.  Click the tile of the zone for which you want to create a new policy. The WAN Routing and Basic Firewall policy table appears and lists all existing policies. Click the  Edit  icon. The page appears in edit mode.  Click  Add New  on the policy table. The Policy (Add) pane appears. Enter a name and, optionally, a description for the policy in the corresponding fields in the Basic Information pane. Click the Match Rules toggle to set it to one of the following: Any—This policy matches  all  traffic entering the segment at the LAN. Explicit—The Match Rule Details table appears. You must add  preconfigured match rules  to define the traffic match criteria that the policy applies to traffic as follows: Click  Choose  then select a match rule from the drop-down list. Click the  Save  icon. (Optional) Click  Choose  again to add another rule. (Optional) Click the  Delete  icon to remove a rule. Click the  Operation  drop-down list and select one of the following operations for the policy to execute on matched traffic: Blackhole—Deny the flow and do  not  send a message to the sender. Unreachable—Deny the flow and send an ICMP Unreachable message code 1 to the sender. Prohibit—Deny the flow and send an ICMP Unreachable message code 13 to the sender. Forward (ANAP required)—Send the traffic to one of the following options: M1 Interface M2 Interface ITC—This is the interface decided by the Internet Traffic Controller as the healthier internet interface M1/M2.  Use Security Rules—Security rules decide what should happen to traffic as it crosses segments or zones. This operation allows the ANAP to directly refer to these policies to determine the required action. See  Create internet policies  for detailed information. Route Using Specified Order—This option is available for polices applied to segments. Route the traffic to the available networks in a user-defined sequence. When you select this operation, a list of available networks appears. You must select which networks to include, and prioritize them as follows: Click the  Move  icon next to each network that you want included in the rule, then click  Select/Deselect . Selected networks display a check in their row. Click the  Move  icon next to each network that you want to reposition in the table, then click  Move Up  or  Move Down . The rows of the table are read top down. If the destination of the traffic is reachable using the first selected network in the list, the traffic is routed there. If it is not reachable, the next selected network below it is used for routing if it is reachable. Route Parallel Cost—This option is available for polices applied to segments. Route the traffic to the available networks based on the lowest associated cost. When you select this operation, a list of available networks appears. You must select which networks to include as follows: Click the  Move  icon next to each network that you want included in the rule, then click  Select/Deselect . Selected networks display a check in their row. Click the  Move  icon next to each network that you want to reposition in the table, then click  Move Up  or  Move Down . The rows of the table are read top down. If a destination is reachable by multiple networks at the same cost, the network closer to the top of the table is used. Route Using Longest Prefix Match—This option is available for polices applied to segments. Route the traffic to the available networks based on the greatest number of matching digits in the subnet mask. When you select this operation, a list of available networks appears. You must select which networks to include as follows: Click the  Move  icon next to each network that you want included in the rule, then click  Select/Deselect . Selected networks display a check in their row. Click the  Move  icon next to each network that you want to reposition in the table, then click  Move Up  or  Move Down . The rows of the table are read top down. If two destinations have an identical number of matching digits, the network closer to the top of the table is used. Route Using IPSLA—This option is available for polices applied to segments. Route the traffic to the available networks based on the networks' health. When you select this operation, the VPN Path Aryaka and VPN Path Internet networks appear. You must select which networks to include as follows: Click the  Move  icon next to each network that you want included in the rule, then click  Select/Deselect . Selected networks display a check in their row. Note:  If Aryaka is selected from the list of available networks, and one of the following is enabled: Use L3 Private Core—Matching traffic is routed over the L3 Private Core. Use L2 Private Core—Matching traffic is routed over the L2 Private Core. Click the  Move  icon next to each network that you want to reposition in the table, then click  Move Up  or  Move Down . The rows of the table are read top down. If both networks are SLA compliant, the network closer to the top of the table is used. Then, use the IPSLA Profile drop-down list to select the  SLA profile  you want to use to determine network preference.  (Optional) Select one of the following  If Operation Fails  options to define what action is performed if the original operation is not successful (do  not  select the same operation you selected in the previous step): Aryaka Default—The default behavior is to cycle through all the policies until the last policy is reached. If no match has been found, the security rules are consulted. See  Create internet policies  for detailed information. Blackhole—Deny the flow and do  not  send a message to the sender. Unreachable—Deny the flow and send an ICMP Unreachable message to the sender. Continue Through Policies—Override the routing table lookup and send the traffic flow to the desired destination (another segment or DMZ, or local Internet). Use Security Rules—Security rules decide what should happen to traffic as it crosses segments or zones. This operation allows the ANAP to directly refer to these policies to determine the required action. See  Create internet policies  for detailed information. Click  OK . A draft of the policy is saved and the WAN Routing and Basic Firewall table is displayed. The newly created policy appears in the last row of the table. (Optional) Click  Add New  and repeat steps 8–12 to create another policy.  (Optional) Click the  Move  icon in the Action column of the policy table to reposition the corresponding policy. Policies in the table are searched for a match from the first (top) row to the last (bottom) row. Do one of the following: Click  Save Draft  to save a draft of the entries made on this page. Click the  Next  icon or the  Advanced Settings  icon to continue your site configuration on one of other Advanced Settings pages as described in  Configure Advanced Settings . Click  Submit  to send a change request with the entries made on this page to Aryaka support. Related topics Create customer-level WAN Routing and Basic Firewall policies Manage match rules Create internet policies Configure zones