---
title: "Match rule assets"
canonical: "https://docs.aryaka.com/space/KNOW/34177169/Match%20rule%20assets"
format: markdown
---
The Asset Management > Match Rules page allows you to manage your match rule assets. A  match rule asset  is a named collection of network identifiers that can be associated with your  security ,  WAN Routing and Basic Firewall , and  internet  rules to permit or deny traffic for specific sites. You can include the following network identifiers in match rule asset: Source IP—A specific IP, or all source IPs can be added in either IP or CIDR format. Network objects can also be referenced. Source Port—A specific port, a port range, or all ports can be added. Port objects can also be referenced. Destination IP—A specific IP, or all destination IPs can be added in either IP or CIDR format. Network objects can also be referenced. Destination Port—A specific port, a port range, or all ports can be added. Port objects can also be referenced. Protocol—TCP, UDP, and ICMP.  TOS—Any type of service (ToS) value that can be matched in a packet can be added. Follow the procedures in this topic to view, add, edit, or delete match rule assets. To view match rule assets Log in to MyAryaka. The Home page appears. Click  Security  >  Asset Management  in the left navigation pane. The Asset Management page appears and displays a series of tiles.  Click the  Match Rules  tile. The Match Rules page appears and displays a list of your configured match rule assets. (Optional) Click the name of a match rule asset to view configuration details.  To add a match rule asset Log in to MyAryaka. The Home page appears. Click  Security  >  Asset Management  in the left navigation pane. The Asset Management page appears and displays a series of tiles.  Click the  Match Rules  tile. The Match Rules page appears and displays a list of your configured match rule assets. Click the  Add  icon. The Add Match Rule page appears.  In the Basic Information pane, enter a name and, optionally, a description for the match rule asset. Define a source IP for this match rule by clicking the  Source IP  toggle, then selecting one of the following match criteria: Any—Matches every source IP. If you select this option, continue with step 7. Explicit—Matches only the specified IP, an IP in a specified range of IPs (separated by commas and hyphens, for example, 192.168.1.1-192.168.1.15, 192.168.1.40, 192.168.1.100), a CIDR, an IP object, or an IP group. If you select this option, the IP/CIDR/IP Object table appears. It displays the existing source IPs. If the source IP you want included in this rule does not appear in the table, add it as follows: Click  Add New . A blank field and a drop-down list appear in the first row of the table. The drop-down list displays the IP Groups you configured as described in  Manage Network Object groups . Select the appropriate IP Group from the drop-down list or enter it directly in the text field. Click the  Save  icon.  (Optional) Repeat these steps to add more source IP matches. Define a source port for this match rule by clicking the  Source Port  toggle, then selecting one of the following match criteria: Any—Matches every source port. If you select this option, continue with step 8. Explicit—Matches only the specified port, a port in a specified range of ports (separated by commas and hyphens, for example, 80, 443, 100-150), or a port group. If you select this option, the Port/Port Object table appears. It displays the existing source ports. If the source port you want included in this rule does not appear in the table, add it as follows: Click  Add New . A blank field and a drop-down list appear in the first row of the table. The drop-down list displays the port groups you configured as described in  Manage Network Object groups . Select the appropriate port group from the drop-down list or enter it directly in the text field. Click the  Save  icon.  (Optional) Repeat these steps to add more source port matches. Define a destination IP for this match rule by clicking the  Destination IP  toggle, then selecting one of the following match criteria: Any—Matches every destination IP. If you select this option, continue with step 9. Explicit—Matches only the specified IP, an IP in a specified range of IPs (separated by commas and hyphens), CIDR, IP object, or IP group. If you select this option, the IP/CIDR/IP Object table appears. It displays the existing destination IPs. If the destination IP you want included in this rule does not appear in the table, add it as follows: Click  Add New . A blank field and a drop-down list appear in the first row of the table. The drop-down list displays the IP groups you configured as described in  Manage Network Object groups . Select the appropriate IP group from the drop-down list or enter it directly in the text field. Click the  Save  icon.  (Optional) Repeat these steps to add more destination IP matches. Define a destination port for this match rule by clicking the  Destination Port  toggle, then selecting one of the following match criteria: Any—Matches every destination port. If you select this option, continue with step 10. Explicit—Matches only the specified port, a port in a specified range of ports (separated by commas and hyphens), or port group. If you select this option, the Port/Port Object table appears. It displays the existing destination ports. If the destination port you want included in this rule does not appear in the table, add it as follows: Click  Add New . A blank field and a drop-down list appear in the first row of the table. The drop-down list displays the port groups you configured as described in  Manage Network Object groups . Select the appropriate port group from the drop-down list or enter it directly in the text field. Click the  Save  icon.  (Optional) Repeat these steps to add more destination port matches. Enter one of the following protocols or Any (to match all protocols in the traffic) in the Protocol field.  TCP UDP ICMP Enter the type of service value—one that can be matched in a packet—in the TOS field. Click  Submit . You are prompted to select one of the following submit options:  Activate Later  or  Activate Now . See  Activate configuration updates  for details. The Match Rules page displays your new match rule asset in the list of configured match rule assets. To edit a match rule asset Log in to MyAryaka. The Home page appears. Click  Security  >  Asset Management  in the left navigation pane. The Asset Management page appears and displays a series of tiles.  Click the  Match Rules  tile. The Match Rules page appears and displays a list of your configured match rule assets. Click the name of the match rule asset you want to edit. The < match rule asset name > page appears in read-only mode. Click the  Edit  icon. The page appears in edit mode. Note:  To edit assets that are owned by Aryaka (denoted with a gray Owned by Aryaka label) you must first click  Change Ownership , confirm the ownership change, and then click the  Edit  icon that appears.  Perform any of the following actions to edit the match rule asset: Change the name, description, or both in the Basic Information pane. Edit any of the following network identifiers as described in the previous procedure: Source IP Source Port Destination IP Destination Port Protocol TOS Click  Submit . You are prompted to select one of the following submit options:  Activate Later  or  Activate Now . See  Activate configuration updates  for details. The Match Rules page displays your updated match rule asset in the list of configured match rule assets. To delete a match rule asset Log in to MyAryaka. The Home page appears. Click  Security  >  Asset Management  in the left navigation pane. The Asset Management page appears and displays a series of tiles.  Click the  Match Rules  tile. The Match Rules page appears and displays a list of your configured match rule assets. Click the name of a match rule asset that you want to delete. The selected  <matchRuleName>  page appears. Click the  Delete  icon. You are prompted confirm the deletion. Click  Activate Now . The selected match rule is deleted. Related Topics Asset management Create site-level WAN Routing and Basic Firewall policies Create customer-level WAN Routing and Basic Firewall policies Create internet policies Related videos Add traffic match rules