---
title: "Configure a WAN-Side Basic IPS ruleset"
canonical: "https://docs.aryaka.com/space/KNOW/57147850/Configure%20a%20WAN-Side%20Basic%20IPS%20ruleset"
format: markdown
---
This topic describes how to create or edit a WAN-Side Basic IPS ruleset. WAN-Side Basic IPS rules are used to permit or deny a site's inbound traffic at the public-facing perimeter by inspecting the traffic for signatures that indicate a potential threat. You can add multiple WAN-Side Basic IPS rules to a ruleset and then apply the ruleset to one or more sites. If you want to create a WAN-Side Basic IPS rule that applies only to one site, see the  Configure site-level security features  help topic.  WAN-Side Basic IPS The Aryaka intrusion prevention system (IPS) aims to prevent security threats and attacks. The IPS monitors the events occurring in your network for potential security incidents. Any potential incidents are logged and an attempt is made to stop the incident. Potential security incidents are identified using unique patterns and identifiers from previous incidents called signatures. Aryaka regularly updates a database of known malicious signatures maintained by  Proofpoint . The IPS security engine monitors network traffic for these known signatures and generates one of the following verdicts for the traffic, which includes a recommended action: Pass—Permit traffic.  Drop—Deny traffic and generate an IPS event log. Reject—Deny traffic, send a message to the client, and generate an IPS event log.  Alert—Permit traffic and generate an IPS event log. See the  IPS  topic for additional details on the WAN-Side Basic IPS security engine and the other IPS security engines. Create a ruleset The WAN-Side Basic IPS page displays a table of WAN-Side Basic IPS rulesets. Rulesets are associated with one or more of your sites and include one or more rules that permit or deny traffic based on configured match criteria. See the  Security engine rulesets  topic for an overview of the different types of security rulesets. Complete the procedures later in this topic to create or edit a WAN-Side Basic IPS ruleset.  Default rule If you do not configure any WAN-Side Basic IPS rulesets or  site-level rules , the WAN-Side Basic IPS Default template is applied to traffic for all sites. The Default template includes a rule that matches all traffic and permits it. Manage the Rules table The Rules table within a ruleset displays a list of configured rules that are evaluated when traffic is inspected by the associated security engine for any sites that the ruleset is applied to. Each table row includes the following details: Rule ID—Identification number for the rule, used in security logs. Name—User-defined name for the rule. Source—Match criteria related to the source of the traffic (for example, source IP address or user).  Destination—Match criteria related to the destination of the traffic (for example, destination IP address or domain). Services—Match criteria related to traffic protocol and destination port. Schedule—Match criteria related to a defined schedule. Action—Action applied to matched traffic (for example, permit or drop).  Note the following when interacting with the Rules table: If a single match criteria has more than four entires, click  Show More  to view all entires.  If an asset is used as match criteria, click the asset name to display an in-page view of what the asset includes. The Rules table also includes the following components: Detailed View toggle—Turn this toggle on to display details on the type of match criteria (for example, IP or URL) and the required condition (for example, is or is not) included in a rule. When this toggle is turned off, only the specific match criteria are displayed.  Download Table icon—Download the rule table as a CSV file. Configure table icon—Select whether to display the columns related to match criteria (for example, source, destination, and schedule) in the table. Reorder button—Reorder the rules in the table. See step 11 of the  Add a WAN-Side Basic IPS ruleset  procedure for details.  Note that Rule tables are evaluated from top to bottom. If a more specific rule appears above a more generic rule, and the traffic matches the more specific rule, the rule's corresponding action is executed and the next (more generic) rule is not evaluated. When you configure the WAN-Side Basic IPS rules within a ruleset, you can use the following match criteria to permit or deny file transfers in your network: Source IPs Source zones Source ports Protocols Destination IPs Destination ports Schedule These match criteria can be specified individually when you create a rule or as part of a named asset, defined on the  Asset Management  page. Assets can be reused in your security rules, but must be configured  before  you create the rule in which you want to use it.  To add a WAN-Side Basic IPS ruleset Open the WAN-Side Basic IPS page is if it not already open: Log in to MyAryaka. The Home page appears. Click  Security  >  IPS  in the left navigation pane. The IPS page appears. Click  Manage  in the   WAN-Side Basic IPS tile. The WAN-Side Basic IPS page appears and displays a list of configured rulesets. Click the  Add  icon. The Add a Template page appears and displays the Ruleset Details pane and the Rules table.  In the Ruleset Details pane, enter a name and, optionally, a description for your new ruleset, then click the  Type  drop-down list and select one of the following options:  High Priority Custom Template—Define a set of high priority rules for a specific site or group of sites. Only rules in the Global Non-Overridable Template take precedence over the rules in this ruleset. You can only configure one ruleset of this type for a given site.  Normal Priority Custom Template—Define a set of rules for a specific site or group of sites. Rules in this ruleset are evaluated after all rules in Global Non-Overridable and High Priority Custom rulesets. The rules in this ruleset can be overridden by  site-level  rules  and rules in other Normal Priority Custom templates, based on your configured evaluation order. Note:  You cannot add a Global Non Overridable template, but you can edit the existing one. You cannot add a Default template or edit the existing one. See the  Security engine rulesets  topic for an overview of the different types of security rulesets. Click  Add  on the Rules table. The Add a Policy page appears and displays a Details pane and a Match Criteria pane. In the Details pane, enter a name for your rule, then click the  Actions  drop-down list and select one of the following actions to take when a condition of the rule is met: Skip IPS—Traffic is not inspected by the IPS engine and is instead passed to the next security engine for inspection. Enforce Verdict—Traffic is inspected by the IPS engine and the verdict is enforced. Only traffic with a verdict of  Pass  or  Alert  is permitted and sent to the next security engine for inspection. Complete step 6 to specify what action to take when traffic is denied. Ignore Verdict—Traffic is inspected by the IPS engine and the verdict is not enforced. All traffic is permitted and sent to the next security engine for inspection. Log Only—Traffic is inspected by the IPS engine and the verdict is not enforced. All traffic is permitted and sent to the next security engine for inspection. This is intended as a temporary action while you evaluate traffic. After you have evaluated the traffic, update the rule with one of the other actions.  (Conditional) If you selected  Enforce Verdict  as the rule action, the Drop Action drop-down list appears. Click the  Drop Action  drop-down list and select one of the following actions to take when traffic is denied by the WAN-Side Basic IPS security engine: Aryaka Default (Drop)—Traffic is denied and the client does not receive a response. Reject—Traffic is denied and the TCP connection is reset. For non-TCP connections, the client receives an  ICMP Unreachable  response.  Prohibit—Traffic is denied and the client receives an  ICMP Unreachable  response.  In the Match Criteria pane, complete the following procedure for each of the criterion you want to include in the rule:  Click the  Condition  drop-down list and select a condition for the criterion. Complete one of the following procedures to add match criteria: Type a criterion into the appropriate field and hit Enter. The criterion is added. Click the  Add  icon. The Add < criterion > dialog appears. Depending on the type of match criteria selected, do one of the following: Click one or more entities you want to include as match criteria for the rule. The selected entities are highlighted in green and display a check. Click  Add Selected . The page displays the selected entities for each criterion.  Enter one or more entities you want to include as match criteria for the rule. Click  Add Selected . The page displays the selected entities for each criterion.  Click  Continue . The Add a Template page appears with the rule you added included in the Rules table. (Optional) Repeat steps 4–8 to add additional rules to your ruleset.  Note:  Rules are evaluated in a top-down manner based on the Rules. The first rule that matches the traffic is executed and the rest are ignored.   Do one of the following: Click  Save as Draft  to save a draft of the ruleset. Click  Submit  to save the ruleset. You are prompted to select one of the following options:  Activate Later  or  Activate Now . See  Activate configuration updates  for details. When your update is activated, the WAN-Side Basic IPS page displays your new ruleset in the list of WAN-Side Basic IPS rulesets. Note:  The rules included in the ruleset are not applied to network traffic until the ruleset is associated with at least one site. Complete the  Associate a WAN-Side Basic IPS ruleset with a site  procedure to associate a ruleset with one or more sites.  (Optional) Complete the following procedure to reorder the Rules table: Note:  Rules are evaluated in a top-down manner based on the table. The first rule that matches the traffic is executed and the rest are ignored.  Click  Reorder  in the rule table. The displayed table now includes the Precedence column, which indicates the evaluation order for the rule, and the Reorder column, which displays the following actions: Move Down—Move the selected rule down one row in the table. Move Up—Move the selected rule up one row in the table. Move to Bottom—Move the selected rule to the bottom of the table. This rule is now evaluated last.  Move to Top—Move the selected rule to the top of the table. This rule is now evaluated first.  Change Precedence—Use the Reorder dialog to enter a new precedence value for the selected rule. For example, if your rule list contains five rules and you want the selected rule to be evaluated third, enter 3 in the Reorder dialog, then click  Update . Click  Submit . The Rules table is updated according to the modified rule order. To associate a WAN-Side Basic IPS ruleset with a site Open the WAN-Side Basic IPS page is if it not already open: Log in to MyAryaka. The Home page appears. Click  Security  >  IPS  in the left navigation pane. The IPS page appears. Click  Manage  in the   WAN-Side Basic IPS tile. The WAN-Side Basic IPS page appears and displays a list of configured rulesets. Click the name of the ruleset you want to associate with a site. The  <rulesetName>  page appears and displays two tiles: Ruleset Details—Displays the number of rules included in the ruleset and the current status of the ruleset. This tile is selected by default. Site Associations—Displays the number of sites and site classes associated with the ruleset and the current status of the site associations. Click the  Site Associations  tile. The  <rulesetName>  page displays the Associated Sites pane and the Associated Site Classes pane in read-only mode. Click  Edit . The Site Associations page appears. Complete at least one of the following procedures to associate the ruleset with a site or a group of sites: To associate the ruleset with a site:  In the Associated Sites pane, click  Add . The Add Site dialog displays the sites that you can associate with this WAN-Side Basic IPS ruleset.  Note:  Sites must have an Aryaka SmartSecure IPS Add-on subscription to be associated with this ruleset. Click one or more sites you want to associate with this WAN-Side Basic IPS ruleset. The selected sites are highlighted in green and display a check. Click  Add Selected . The Add a Template page displays the selected sites in the Associated Sites table.  To associate the ruleset with a group of sites: In the Associated Site Classes pane, click  Add . The Add Site Class dialog displays the site classes that you can associate with this WAN-Side Basic IPS ruleset. Click one or more site classes you want to associate with this WAN-Side Basic IPS ruleset. The selected site classes are highlighted in green and display a check. Click  Add Selected . The Add a Template page displays the selected site classes in the Associated Site Classes table. Click  Submit . You are prompted to select one of the following options:  Activate Later  or  Activate Now . See  Activate configuration updates  for details. When your update is activated, the rules included in the WAN-Side Basic IPS ruleset are now used to permit or deny traffic for the sites the ruleset is associated with. To edit a WAN-Side Basic IPS ruleset Open the WAN-Side Basic IPS page is if it not already open: Log in to MyAryaka. The Home page appears. Click  Security  >  IPS  in the left navigation pane. The IPS page appears. Click  Manage  in the   WAN-Side Basic IPS tile. The WAN-Side Basic IPS page appears and displays a list of configured rulesets. Click the name of the WAN-Side Basic IPS ruleset you want to edit. The < rulesetName > page appears and displays two tiles: Ruleset Details—Displays the number of rules included in the ruleset and the current status of the ruleset. This tile is selected by default. Site Associations—Displays the number of sites and site classes associated with the ruleset and the current status of the site associations. (Optional) Click  Disable  to render the ruleset inactive. The ruleset can be enabled again later.  (Optional) Click the  Delete  icon to remove the ruleset. You are prompted to select one of the following options:  Activate Later  or  Activate Now . See  Activate configuration updates  for details. When your update is activated, the ruleset is removed from the list of WAN-Side Basic IPS rulesets. Note:  You cannot delete the global or default templates. (Optional) Click  Reorder  in the Rules table. The displayed table now includes the Precedence column, which indicates the evaluation order for the rule, and the Reorder column, which displays the following actions: Move Down—Move the selected rule down one row in the table.  Move Up—Move the selected rule up one row in the table. Move to Bottom—Move the selected rule to the bottom of the table. This rule is now evaluated last.  Move to Top—Move the selected rule to the top of the table. This rule is now evaluated first.  Change Precedence—Use the Reorder dialog to enter a new precedence value for the selected rule. For example, if your rule list contains five rules and you want the selected rule to be evaluated third, enter 3 in the Reorder dialog, then click  Update . Click  Edit  in the Ruleset Details pane. The < rulesetName > page appears in edit mode. Use the following options to modify rules as needed: Edit —Displays the match criteria in edit mode. Add, edit, or remove entities from any of the match criteria. Complete step 7 of the  Add a WAN-Side Basic IPS ruleset  procedure to add or edit the entities included in a criterion, then click  Continue . Add Below —Adds a new blank rule below the selected rule. Options  >  Clone —Adds a new rule with the same match criteria as the cloned rule. The new rule is added to the rule table directly after the rule it was cloned from. Options  >  Disable —Renders the rule inactive, but does not remove it from the rule table. The rule can be reenabled later.  Options  >  Delete —Removes the rule from the site's rule table.  Do one of the following: Click  Save as Draft  to save a draft of the ruleset changes. Click  Submit  to save the ruleset changes. You are prompted to select one of the following options:  Activate Later  or  Activate Now . See  Activate configuration updates  for details. When your update is activated, the changes to the WAN-Side Basic IPS ruleset are saved. Click the  Site Associations  tile. The  <rulesetName>  page displays the Associated Sites pane and the Associated Site Classes pane in read-only mode. Click  Edit . The Site Associations page appears. Complete the  Associate a WAN-Side Basic IPS ruleset with a site  procedure to edit the sites with which the ruleset is associated.  Click  Submit  to save the ruleset changes. You are prompted to select one of the following options:  Activate Later  or  Activate Now . See  Activate configuration updates  for details. When your update is activated, the changes to the WAN-Side Basic IPS ruleset are saved.  In this topic Related topics IPS Security engine rulesets Configure site-level security features Asset management Monitor WAN-Side Basic IPS security engine