---
title: "Configure a Next Generation Firewall ruleset"
canonical: "https://docs.aryaka.com/space/KNOW/28019878/Configure%20a%20Next%20Generation%20Firewall%20ruleset"
format: markdown
---
This topic describes how to create or edit a Next Generation Firewall ruleset. Next Generation Firewall rules are used to permit or deny traffic, or allow traffic to bypass all subsequent processing. This allows you to control the devices and users that can access your network. You can add multiple Next Generation Firewall rules to a ruleset and then apply the ruleset to one or more sites. If you want to create a Next Generation Firewall rule that applies only to one site, see the  Configure site-level security features  help topic.  Next generation firewall Next Generation Firewall rules provide access control for pre-SSL traffic, allowing you to ensure that only authorized devices and users can access network resources. This is a Layer 3/Layer 4 firewall, which provides more comprehensive network security.  See the  NGFW-SWG  topic for additional details on the Next Generation Firewall security engine and the other security engines that are used to inspect network traffic. Create a ruleset The Next Generation Firewall page displays a table of Next Generation Firewall rulesets. Rulesets are associated with one or more of your sites and include one or more rules that permit or deny traffic based on configured match criteria. See the  Security engine rulesets  topic for an overview of the different types of security rulesets.  Complete the procedures later in this topic to create or edit a Next Generation Firewall ruleset.  Default rule If you do not configure any Next Generation Firewall rulesets or  site-level rules , the Next Generation Firewall Default template is applied to traffic for all sites. The Default template includes a rule that matches all traffic and allows it to bypass all subsequent inspection. Manage the Rules table The Rules table within a ruleset displays a list of configured rules that are evaluated when traffic is inspected by the associated security engine for any sites that the ruleset is applied to. Each table row includes the following details: Rule ID—Identification number for the rule, used in security logs. Name—User-defined name for the rule. Source—Match criteria related to the source of the traffic (for example, source IP address or user).  Destination—Match criteria related to the destination of the traffic (for example, destination IP address or domain). Services—Match criteria related to traffic protocol and destination port. Schedule—Match criteria related to a defined schedule. Action—Action applied to matched traffic (for example, permit or drop).  Note the following when interacting with the Rules table: If a single match criteria has more than four entires, click  Show More  to view all entires.  If an asset is used as match criteria, click the asset name to display an in-page view of what the asset includes. The Rules table also includes the following components: Detailed View toggle—Turn this toggle on to display details on the type of match criteria (for example, IP or URL) and the required condition (for example, is or is not) included in a rule. When this toggle is turned off, only the specific match criteria are displayed.  Download Table icon—Download the rule table as a CSV file. Configure table icon—Select whether to display the columns related to match criteria (for example, source, destination, and schedule) in the table. Reorder button—Reorder the rules in the table. See step 10 of the  Add a Next Generation Firewall ruleset  procedure for details.  Note that Rule tables are evaluated from top to bottom. If a more specific rule appears above a more generic rule, and the traffic matches the more specific rule, the rule's corresponding action is executed and the next (more generic) rule is not evaluated. When you configure your Next Generation Firewall rules, you can use the following match criteria to permit or deny traffic: Source IPs Source ports Source zones Source geolocations Users Applications Destination ports Domain categories Domain names Protocols Destination IPs Destination networks Destination sites Destination geolocations Schedule These match criteria can be specified individually when you create a rule or as part of a named asset, defined on the  Asset Management  page. Assets can be reused in your security rules, but must be configured  before  you create the rule in which you want to us To add a Next Generation Firewall ruleset Open the Next Generation Firewall page if it is not already open: Log in to MyAryaka. The Home page appears. Click  Security  >  NGFW  in the left navigation pane. The NGFW page appears and displays a list of configured rulesets. Click the  Add  icon. The Add a Template page appears and displays the Ruleset Details pane and the Rules table.  In the Ruleset Details pane, enter a name and, optionally, a description for your new ruleset, then click the  Type  drop-down list and select one of the following options: High Priority Custom Template—Define a set of high priority rules for a specific site or group of sites. Only rules in the Global Non-Overridable Template take precedence over the rules in this ruleset. You can only configure one ruleset of this type for a given site.  Normal Priority Custom Template—Define a set of rules for a specific site or group of sites. Rules in this ruleset are evaluated after all rules in Global Non-Overridable and High Priority Custom templates. The rules in this ruleset can be overridden by  site-level rules  and rules in other Normal Priority Custom templates, based on your configured evaluation order. Note:  You cannot add a Global Non Overridable template, but you can edit the existing one. You cannot add a Default template or edit the existing one. See the  Security engine rulesets  topic for an overview of the different types of security rulesets. Click  Add  on the Rules table. The Add a Policy page appears and displays a Details pane and a Match Criteria pane. In the Details pane, enter a name for your rule, then click the  Actions  drop-down list and select one of the following actions to take when a condition of the rule is met: Permit—Traffic is permitted and sent to the next security engine for inspection. Drop—Traffic is denied and the client does not receive a response.  Log Only—Traffic is permitted and sent to the next security engine for inspection. This is intended as a temporary action while you evaluate traffic. After you have evaluated traffic, update the rule with one of the other actions.  Skip All—Traffic is permitted and bypasses all subsequent security engines. Traffic is sent to have network address translation (NAT) performed or to be routed depending on which output interface was specified in the WAN Routing and Basic Firewall or Internet Routing rule tables. Reject—Traffic is denied and the TCP connection is reset. For non-TCP connections, the client receives an  ICMP Unreachable  response. Prohibit—Traffic is denied and the client receives an  ICMP Unreachable  response.  In the Match Criteria pane, complete the following procedure for each of the criterion you want to include in the rule:  Click the  Condition  drop-down list and select a condition for the criterion. Complete one of the following procedures to add match criteria: Type a criterion into the appropriate field and hit Enter. The criterion is added. Click the  Add  icon. The Add < criterion > dialog appears. Depending on the type of match criteria selected, do one of the following: Click one or more entities you want to include as match criteria for the rule. The selected entities are highlighted in green and display a check. Click  Add Selected . The page displays the selected entities for each criterion.  Enter one or more entities you want to include as match criteria for the rule. Click  Add Selected . The page displays the selected entities for each criterion.  Click  Continue . The Add a Template page appears with the rule you added included in the Rules table. (Optional) Repeat steps 4–7 to add additional rules to your ruleset. Do one of the following: Click  Save as Draft  to save a draft of the ruleset. Click  Submit  to save the ruleset. You are prompted to select one of the following options:  Activate Later  or  Activate Now . See  Activate configuration updates  for details. When your update is activated, the Next Generation Firewall page displays your new ruleset in the list of Next Generation Firewall rulesets. Note:  The rules included in the ruleset are not applied to network traffic until the ruleset is associated with at least one site. Complete the  Associate a Next Generation Firewall ruleset with a site  procedure to associate a ruleset with one or more sites.  (Optional) Complete the following procedure to reorder the Rules table: Note:  Rules are evaluated in a top-down manner based on the table. The first rule that matches the traffic is executed and the rest are ignored.  Click  Reorder  in the rule table. The displayed table now includes the Precedence column, which indicates the evaluation order for the rule, and the Reorder column, which displays the following actions: Move Down—Move the selected rule down one row in the table. Move Up—Move the selected rule up one row in the table. Move to Bottom—Move the selected rule to the bottom of the table. This rule is now evaluated last.  Move to Top—Move the selected rule to the top of the table. This rule is now evaluated first.  Change Precedence—Use the Reorder dialog to enter a new precedence value for the selected rule. For example, if your rule list contains five rules and you want the selected rule to be evaluated third, enter 3 in the Reorder dialog, then click  Update . Click  Submit . The Rules table is updated according to the modified rule order.  To associate a Next Generation Firewall ruleset with a site Open the Next Generation Firewall page if it is not already open: Log in to MyAryaka. The Home page appears. Click  Security  >  NGFW  in the left navigation pane. The NGFW page appears. Click the name of the ruleset you want to associate with a site. The  <rulesetName>  page appears and displays two tiles: Ruleset Details—Displays the number of rules included in the ruleset and the current status of the ruleset. This tile is selected by default. Site Associations—Displays the number of sites and site classes associated with the ruleset and the current status of the site associations. Click the  Site Associations  tile. The  <rulesetName>  page displays the Associated Sites pane and the Associated Site Classes pane in read-only mode. Click  Edit . The Site Associations page appears. Complete at least one of the following procedures to associate the ruleset with a site or a group of sites: To associate the ruleset with a site:  In the Associated Sites pane, click  Add . The Add Site dialog displays the sites that you can associate with this Next Generation Firewall ruleset.  Click one or more sites you want to associate with this Next Generation Firewall ruleset. The selected sites are highlighted in green and display a check. Click  Add Selected . The Add a Template page displays the selected sites in the Associated Sites table.  To associate the ruleset with a group of sites: In the Associated Site Classes pane, click  Add . The Add Site Class dialog displays the site classes that you can associate with this Next Generation Firewall ruleset. Click one or more site classes you want to associate with this Next Generation Firewall ruleset. The selected site classes are highlighted in green and display a check. Click  Add Selected . The Add a Template page displays the selected site classes in the Associated Site Classes table. Click  Submit . You are prompted to select one of the following options:  Activate Later  or  Activate Now . See  Activate configuration updates  for details. When your update is activated, the rules included in the Next Generation Firewall ruleset are now used to permit or deny traffic for the sites the ruleset is associated with. To edit a Next Generation Firewall ruleset Open the Next Generation Firewall page if it is not already open: Log in to MyAryaka. The Home page appears. Click  Security  >  NGFW  in the left navigation pane. The NGFW page appears. Click the name of the Next Generation Firewall ruleset you want to edit. The < rulesetName > page appears and displays two tiles: Ruleset Details—Displays the number of rules included in the ruleset and the current status of the ruleset. This tile is selected by default. Site Associations—Displays the number of sites and site classes associated with the ruleset and the current status of the site associations. (Optional) Click  Disable  to render the ruleset inactive. The ruleset can be enabled again later.  (Optional) Click the  Delete  icon to remove the ruleset. You are prompted to select one of the following options:  Activate Later  or  Activate Now . See  Activate configuration updates  for details. When your update is activated, the ruleset is removed from the list of Next Generation Firewall rulesets. Note:  You cannot delete the global or default rulesets. (Optional) Click  Reorder  in the Rules table. The displayed table now includes the Precedence column, which indicates the evaluation order for the rule, and the Reorder column, which displays the following actions: Move Down—Move the selected rule down one row in the table.  Move Up—Move the selected rule up one row in the table. Move to Bottom—Move the selected rule to the bottom of the table. This rule is now evaluated last.  Move to Top—Move the selected rule to the top of the table. This rule is now evaluated first.  Change Precedence—Use the Reorder dialog to enter a new precedence value for the selected rule. For example, if your rule list contains five rules and you want the selected rule to be evaluated third, enter 3 in the Reorder dialog, then click  Update . Click  Edit  in the Ruleset Details pane. The < rulesetName > page appears in edit mode. Use the following options to modify rules as needed: Edit —Displays the match criteria in edit mode. Add, edit, or remove entities from any of the match criteria. Complete step 6 of the  Add a Next Generation Firewall ruleset  procedure to add or edit the entities included in a criterion, then click  Continue . Add Below —Adds a new blank rule below the selected rule. Options  >  Clone —Adds a new rule with the same match criteria as the cloned rule. The new rule is added to the rule table directly after the rule it was cloned from. Options  >  Disable —Renders the rule inactive, but does not remove it from the rule table. The rule can be reenabled later.  Options  >  Delete —Removes the rule from the site's rule table.  Do one of the following: Click  Save as Draft  to save a draft of the ruleset changes. Click  Submit  to save the ruleset changes. You are prompted to select one of the following options:  Activate Later  or  Activate Now . See  Activate configuration updates  for details. When your update is activated, the changes to the Next Generation Firewall ruleset are saved. Click the  Site Associations  tile. The  <rulesetName>  page displays the Associated Sites pane and the Associated Site Classes pane in read-only mode. Click  Edit . The Site Associations page appears. Complete the  Associate a Next Generation Firewall ruleset with a site  procedure to edit the sites with which the ruleset is associated.  Click  Submit  to save the ruleset changes. You are prompted to select one of the following options:  Activate Later  or  Activate Now . See  Activate configuration updates  for details. When your update is activated, the changes to the Next Generation Firewall ruleset are saved.  In this topic Related topics Configure site-level security features Security engine rulesets Asset management NGFW-SWG