---
title: "Configure IPS Signature templates"
canonical: "https://docs.aryaka.com/space/KNOW/57148270/Configure%20IPS%20Signature%20templates"
format: markdown
---
The IPS > Signature Templates page allows you to create and modify templates that determine the signature feeds used to enforce intrusion prevention system (IPS) security rules at each of your sites. IPS Signature templates A signature is a specific pattern that defines malicious activity or was attributed to a previous security attack. Aryaka SmartSecure IPS uses three collections of signatures that are updated daily by  Proofpoint  to monitor network traffic and identify any patterns that indicate a potential security threat. The three signature collections correspond to the following profiles:  Basic—Provides a high level of security while ensuring optimized system performance. Includes approximately 17,000 signatures. Moderate—Provides a balance between the basic and advanced profiles. Includes approximately 19,000 signatures.   Advanced—Provides the highest level of security protection against known and emerging threats. System performance can be impacted due to increased examination of traffic. Includes approximately 22,000 signatures.   Aryaka modifies these signature collections so that they can be used by the three IPS security engines (LAN-Side Basic IPS, WAN-Side Basic IPS, and Advanced IPS). The resulting nine signature collections are referred to as signature  feeds . To view details of the signatures in each feed, follow the procedure in the  View IPS signature feeds  topic.  By default, each IPS security engine uses the basic signature feed. To change the signature feed for an IPS security engine, you must create a Signature template and apply it to one or more sites, as described in this topic. To view the Signature templates applied to an individual site, follow the procedure in the  Configure site-level security features  topic.  Signature templates also allow you to apply your  IPS Modification policies  to a a site. IPS Modification policies allow you to enable, disable, or change the verdict for one or more signatures included in a signature feed. By applying IPS Modification policies to a Signature template, those policies are applied to traffic at any site that the Signature template is associated with.  Complete the procedures later in this topic to add or edit a Signature template.  Use cases The following are the two primary use cases for IPS Signature templates: Change the signature feed that an IPS security engine uses for your sites.  By default, each IPS security engine uses the Basic signature feed to monitor network traffic and identify any patterns that indicate a potential security threat. If you want one of the IPS security engines to use the Moderate or Advanced signature feed for one or more of your sites, you can create a Signature template to specify this and then associate it with a site or group of sites. The IPS security engines can support multiple signature feeds, which means you can assign multiple IPS Signature templates to an IPS engine for an individual site.  Apply IPS Modification policies to your sites.  IPS Modification policies allow you to enable, disable, or change the verdict for individual signatures. You can apply these policies to Signature templates. Then, when you associate the Signature template with a site or group of sites, the IPS Modification policies are applied to that site's traffic. Example Signature template The following graphic displays three IPS Signature templates: The templates have the status  Configured , meaning that they are being applied to traffic for sites they are associated with. If a template had the status  Provisioning , it would mean that the configuration is in the process of being propagated to the network or has been submitted to Aryaka for provisioning and the template is not yet being applied to traffic for sites the template is associated with. The templates included in this example is for instructional purposes only. You should configure your IPS Signature templates based on your organization's needs. The following graphic displays the details of the IPS Signature template named  Adv protection for LAN-Side Basic IPS : This IPS Signature template includes one IPS Modification policy, but it is not associated with any sites. Once applied to a site, this template is configured such that the LAN-Side Basic IPS security engine uses the Advanced signature feed to inspect traffic for the sites that the template is associated with. It also applies the IPS Modification policy named  Policy - test  to the two sites that the Signature template is associated with. To add an IPS Signature template Log in to MyAryaka. The Home page appears. Click  Security  >  IPS  in the left navigation pane. The IPS page appears. Click  Manage  in the IPS Signature Management. The IPS Signature Management page appears. Click the  Signature Templates  tile. The Signature Templates page appears and displays a list of your configured Signature templates. Click the  Add  icon. The Add a Template page appears and displays the Template Details pane and the Policy List table. The Policy List table displays the IPS Modification policies that are associated with the Signature template. After you create a template, you can  apply IPS Modification policies  to it.  In the Template Details pane, enter a name and, optionally, a description for your new template. Click the  Policy Engine  drop-down list and select the IPS security engine that you want the template to apply to. Note:  A template can only be applied to one security engine, but a security engine can have multiple templates assigned to it. Click the  Feed  drop-down list and select the signature feed that you want the security engine you selected in step 7 to use. The following three types of signature feeds are displayed for the selected IPS security engine:  Basic—Provides a high level of security while ensuring optimized system performance. Includes approximately 17,000 signatures. Moderate—Provides a balance between the basic and advanced profiles. Includes approximately 19,000 signatures.  Advanced—Provides the highest level of security protection against known and emerging threats. System performance can be impacted due to increased examination of traffic. Includes approximately 22,000 signatures.   Do one of the following: Click  Save as Draft  to save a draft of the template. Click  Submit  to save the template. You are prompted to select one of the following options:  Activate Later  or  Activate Now . See  Activate configuration updates  for details. When your update is activated, the Signature Templates page displays your new template in the list of IPS Signature templates. Note:  The template and the policies included in it are not applied to network traffic until the template is associated with at least one site. Complete the  Associate an IPS Signature template with a site  procedure to associate the template with one or more sites.  To associate an IPS Signature template with a site Open the Signature Templates page if it is not already open: Log in to MyAryaka. The Home page appears. Click  Security  >  IPS  in the left navigation pane. The IPS page appears. Click  Manage  in the IPS Signature Management. The IPS Signature Management page appears. Click the  Signature Templates  tile. The Signature Templates page appears and displays a list of your configured Signature templates. Click the name of the template you want to associate with a site. The  <templateName>  page appears and displays two tiles: Template Details—Displays the number of IPS Modification policies applied to the template and the current status of the template. This tile is selected by default. Site Associations—Displays the number of sites and site classes associated with the template and the current status of the site associations. Click the  Site Associations  tile. The  <templateName>  page displays the Associated Sites pane and the Associated Site Classes pane in read-only mode. Click  Edit . The Site Associations page appears. Complete at least one of the following procedures to associate the template with a site or a group of sites: To associate the template with a site:  In the Associated Sites pane, click  Add . The Add Site dialog displays the sites that you can associate with this Signature template.  Note:  Sites must have an Aryaka SmartSecure IPS Add-on subscription to be associated with a Signature template. Click one or more sites you want to associate with this template. The selected sites are highlighted in green and display a check. Click  Add Selected . The Add a Template page displays the selected sites in the Associated Sites table.  To associate the template with a group of sites: In the Associated Site Classes pane, click  Add . The Add Site Class dialog displays the site classes that you can associate with this Signature template. Click one or more site classes you want to associate with this template. The selected site classes are highlighted in green and display a check. Click  Add Selected . The Add a Template page displays the selected site classes in the Associated Site Classes table. Click  Submit . You are prompted to select one of the following options:  Activate Later  or  Activate Now . See  Activate configuration updates  for details. When your update is activated, the Signature template is used to enforce IPS rules for the sites the template is associated with. To edit an IPS Signature template Log in to MyAryaka. The Home page appears. Click  Security  >  IPS  in the left navigation pane. The IPS page appears. Click  Manage  in the IPS Signature Management. The IPS Signature Management page appears. Click the  Signature Templates  tile. The Signature Templates page appears and displays a list of your configured Signature templates. Click the name of the Signature template you want to edit. The < templateName > page appears and displays two tiles: Template Details—Displays the number of IPS Modification policies included in the template and the current status of the template. This tile is selected by default. Site Associations—Displays the number of sites and site classes associated with the template and the current status of the site associations.  (Optional) Click the  Delete  icon to remove the template. You are prompted to select one of the following options:  Activate Later  or  Activate Now . See  Activate configuration updates  for details. When your update is activated, the template is removed from the list of Signature templates. (Optional) Click  Reorder  in the Policy List table. The displayed Policy List table now includes the Precedence column, which indicates the evaluation order for the rule, and the Reorder column, which displays the following actions: Move Down—Move the selected policy down one row in the table.  Move to Bottom—Move the selected policy to the bottom of the table. This policy is now evaluated last.  Change Precedence—Use the Reorder dialog to enter a new precedence value for the selected rule. For example, if your policy list contains five rules and you want the selected rule to be evaluated third, enter 3 in the Reorder dialog, then click  Update . Note:  IPS Modification policies are evaluated from top to bottom in the order in which they are listed. However,  all  policies in the list are evaluated and any policies that match the traffic are executed.  Click  Edit  in the Template Details pane. The < templateName > page appears in edit mode. Edit the Template Details fields as needed. You can change the name and description of the template or change the signature feed that the selected security engine uses to enforce IPS security rules. However, you cannot change the security engine that the template is associated with.  Do one of the following: Click  Save as Draft  to save a draft of the template changes. Click  Submit  to save the template changes. You are prompted to select one of the following options:  Activate Later  or  Activate Now . See  Activate configuration updates  for details. When your update is activated, the changes to the Signature template are saved. Click the  Site Associations  tile. The  <templateName>  page displays the Associated Sites pane and the Associated Site Classes pane in read-only mode. Click  Edit . The Site Associations page appears. Complete the  Associate an IPS Signature template with a site  procedure to edit which sites the template is associated with.  Click  Submit  to save the template changes. You are prompted to select one of the following options:  Activate Later  or  Activate Now . See  Activate configuration updates  for details. When your update is activated, the changes to the Signature template are saved.  In this topic Related topics View IPS signature feeds Configure global IPS settings Configure site-level security features IPS