---
title: "Configure site-level security features"
canonical: "https://docs.aryaka.com/space/KNOW/57148666/Configure%20site-level%20security%20features"
format: markdown
---
The Sites > Site: < siteName>  page enables you to manage the following security features for the selected site: Rule tables  for the following security engines: DNS Filtering—Rules that permit or deny DNS traffic based on domain reputation. Next Generation Firewall—Rules that permit, deny, or allow traffic to bypass all subsequent processing.  Secure Web Gateway—Rules that permit, deny, or allow SSL-inspected traffic to bypass all subsequent processing. Anti-Malware—Rules that permit or deny file transfers in your network. LAN-Side Basic IPS—Rules that permit or deny outbound traffic at the LAN perimeter by inspecting traffic for signatures that indicate a potential threat. WAN-Side Basic IPS—Rules that permit or deny inbound traffic at the public-facing perimeter by inspecting traffic for signatures that indicate a potential threat. Advanced IPS—Rules that determine if SSL inspection is required and permit or deny outbound traffic by inspecting it for signatures that indicate a potential threat. SaaS Apps Access Control—Rules that permit or deny SaaS application traffic. Tenant Restriction—Rules that manipulate the HTTP headers of SaaS application traffic to enforce tenant restrictions.  Data Loss Prevention—Rules that permit or deny traffic that contain sensitive data. Unknown Traffic Control Intrusion prevention system (IPS) Rule tables Security rules use user-defined criteria to control network traffic for each of your sites. When traffic matches criteria defined in a rule, it can be permitted or denied based on how you have configured the rule.  Match criteria, for example, sources and destinations, web categories and content, and URLs, can be specified individually when you create a rule or as part of a named asset, defined on the  Asset Management  page. Assets are reusable objects that can be included in your security rules. Some assets are automatically created by Aryaka when you purchase SASE services, and others are user-defined and managed. You must configure the assets you want to use in your security rules  before  you configure your security rules.  Security rules can be written at the site level, as described in the procedure in this section, or in a  ruleset  to associate one or more rules with a site or a group of sites. The list of configured rulesets and rules for a selected site will included a Global Non-Overridable template and a Default template, at minimum. When you configure additional security rules or rulesets, they are evaluated in the following order: Global Non-Overridable template High Priority Custom template Site-level rules Normal Priority Custom template Site-level rules Default template Note that a site’s rule table is evaluated from top to bottom. If a more specific rule appears above a more generic rule, and the traffic matches the more specific rule, the rule's corresponding action is executed and the next (more generic) rule is not evaluated. Manage a site’s rule table Each security engine has a configuration page where you can manage the security engine's rule table for a given site. This page includes the following components: Engine Sequencing diagram Engine details Rule table These components are described in the following sections. Engine Sequencing diagram The Engine Sequencing diagram displays the security engine that the selected engine receives traffic from and the engine that it sends traffic to after inspection. You can click a source or destination security engine to view its corresponding configuration page, click  Show All  to view the Engine Sequencing diagram for all security engines, or click the Collapse icon to hide the Engine Sequencing diagram.  Engine details The Engine Details section displays whether the selected security engine is currently started (running) or stopped (not running). If a security engine is stopped, the rule table for the site is not applied when traffic is inspected. Click  Start Engine  or  Stop Engine  in the top right of the page to change the engine’s state. Rule table The rule table displays a list of configured rulesets and rules for the selected security engine and site. Each table row includes the following details: Rule ID—Identification number for the rule, used in security logs. Name—User-defined name for the rule. Note that rulesets are displayed with a number next to their name, indicating the number of rules included in the ruleset. Type—Indicates whether the rule is specific to the selected site or if it is included in a ruleset. The following details are related to match criteria and are not included for all security engines: Source—Match criteria related to the source of the traffic (for example, source IP address or user).  Destination—Match criteria related to the destination of the traffic (for example, destination IP address or domain). Services—Match criteria related to traffic protocol and destination port. Payload—Match criteria related to HTTP method and HTTP header. Schedule—Match criteria related to a defined schedule. Action—Action applied to matched traffic (for example, permit or drop). Note that rulesets do not display an action, as each rule included in the ruleset can have its own action. Note the following when interacting with the rule table: If a single match criteria has more than four entires, click  Show More  to view all entires.  If an asset is used as match criteria, click the asset name to display an in-page view of what the asset includes. The rule table also includes the following components: Flatten Templates toggle—Turn this toggle on to display a row for each security rule that applies to the site for the selected security engine. When this toggle is off, the rules included in rulesets are not shown in separate rows.  Detailed View toggle—Turn this toggle on to display details on the type of match criteria (for example, IP or URL) and the required condition (for example, is or is not) included in a rule. When this toggle is turned off, only the specific match criteria are displayed.  Download icon—Download the rule table as a CSV file. Configure icon—Select whether to display the columns related to match criteria (for example, source, destination, and schedule) in the table. Reorder button—Complete the following procedure to reorder the rule table: Click  Reorder  in the rule table. The displayed table now includes the Precedence column, which indicates the evaluation order for the rule, and the Reorder column, which displays the following actions: Move Down—Move the selected rule down one row in the table. Move Up—Move the selected rule up one row in the table. Move to Bottom—Move the selected rule to the bottom of the table. This rule is now evaluated last.  Move to Top—Move the selected rule to the top of the table. This rule is now evaluated first.  Change Precedence —Use the Reorder dialog to enter a new precedence value for the selected rule. For example, if your rule list contains five rules and you want the selected rule to be evaluated third, enter 3 in the Reorder dialog, then click  Update . Note:  Rules are evaluated in a top-down manner based on the table. The first rule that matches the traffic is executed and the rest are ignored.  Click  Submit . The rule table is updated according to the modified rule order. Follow the procedures in this section to add site-level security rules or to view and edit existing site-level rules. To add a security rule to a site Navigate to the Sites > Site: < siteName>  page if it is not already open: Log in to MyAryaka. The Home page appears. Click  Sites  in the left navigation pane. The Sites page appears. It lists all existing sites. Click the name of the site for which you want to add a security rule. The selected site's page appears. Click the  Security  section to expand it. A series of security tiles appears. Click  View  on the tile of the security engine to which you want to add a security rule. The < securityEngine > page appears in read-only mode and displays an Engine Sequencing diagram, whether the security engine is currently enabled, and a table with all the configured security rules that apply to the site for the selected security engine. Click the  Edit  icon. The page appears in edit mode. Click  Add  on the rule table. The page displays a Details pane and a Match Criteria pane. In the Details pane, enter a name for your rule, then click the  Actions  drop-down list and select one of the following actions to take when a condition of the rule is met: Permit—Traffic is allowed to pass through. Drop—Traffic is blocked. Log Only—Traffic is allowed to pass through and is logged. Note:  These actions are different for some security engines. Select the security engine you want to view actions for on the  Security engine rulesets  page for additional details.  In the Match Criteria pane, complete the following procedure for each of the criterion you want to include in the rule:  Click the  Condition  drop-down list and select a condition for the criterion. Complete one of the following procedures to add match criteria: Type a criterion into the appropriate field and hit Enter. The criterion is added. Click the  Add  icon. The Add < criterion > dialog appears. Depending on the type of match criteria selected, do one of the following: Click one or more entities you want to include as match criteria for the rule. The selected entities are highlighted in green and display a check. Click  Add Selected . The page displays the selected entities for each criterion.  Enter one or more entities you want to include as match criteria for the rule. Click  Add Selected . The page displays the selected entities for each criterion.  Click  Continue . The < securityEngine > page appears with the rule you added included in the rule table. Do one of the following: Click  Save as Draft  to save a draft of the security rules. Click  Submit . You are prompted to select one of the following options:  Activate Later  or  Activate Now . See  Activate configuration updates  for details. When your update is activated, the rules you added are saved. To view or edit a site's security rules Navigate to the Sites > Site: < siteName>  page if it is not already open: Log in to MyAryaka. The Home page appears. Click  Sites  in the left navigation pane. The Sites page appears. It lists all existing sites. Click the name of the site for which you want to view or edit security rules. The selected site's page appears. Click the  Security  section to expand it. A series of security tiles appears. Click  View  on the tile of the security engine for which you want to view or edit rules. The < securityEngine > page appears in read-only mode. Click the  Edit  icon. The page appears in edit mode. Use the following options to modify a site-level rule as needed: Edit—Displays the match criteria in edit mode. Add, edit, or remove entities from any of the match criteria. Complete step 7 of the  Add a security rule to a site  procedure to add or edit the entities included in a criterion, then click  Continue . Add Below—Adds a new blank rule below the selected rule. More Options > Clone—Adds a new rule with the same match criteria as the cloned rule. The new rule is added to the rule table directly after the rule it was cloned from. More Options > Disable—Renders the rule inactive, but does not remove it from the rule table. The rule can be reenabled later.  More Options > Delete—Removes the rule from the site's rule table.  Do one of the following: Click  Save as Draft  to save a draft of the security rules. Click  Submit . You are prompted to select one of the following options:  Activate Later  or  Activate Now . See  Activate configuration updates  for details. When your update is activated, the changes to the rules are saved.  Example rule table The following graphic displays the Next Generation Firewall rule table for a site named WOS3: This rule table includes three rulesets and five site-level rules. The Global Non-Overridable template applies to all sites, is always evaluated first, and, in this example, includes one rule. The High Priority Custom template is always evaluated after the Global Non-Overridable template and, in this example, includes one rule. Of the five site-level rules, one has the  Log Only  action, which permits any traffic matched by this rule and logs it, one has the  Skip All  action, which allows traffic matched by these rules to bypass any further inspection by security engines, one has the  Drop  action, which blocks any traffic matched by this rule, and two have the  Permit  action, which permits any traffic matched by this rule. The Default template is evaluated last, cannot be edited, and includes one rule. The rules included in this example are for instructional purposes only. You should configure your security rules based on your organization's needs.  The following graphic displays the match criteria of two of the site-level rules—one is used drop traffic to religious websites and the other is used to allow traffic to a specific port: If traffic is evaluated by these rules, it means that it did not match any of the rules in the Global Non-Overridable template, the High Priority Custom template, or the preceding site-level rules. The first rule matches any traffic with a domain category of Religion and drops it. The second rule matches any traffic with a destination port of 53 and permits it. If traffic does not match these rules, the next site-level rule is applied. Then, if there is still no match, the rule included in the Default template is evaluated. Read more about rule evaluation order on the  Security engine rulesets  page. Unknown Traffic Control The Security section of the Site: < siteName>  page also includes an  Unknown Traffic Control  tile. For rules where traffic is inspected and classified according to reputation, traffic can be classified as Unknown. You can configure Unknown Traffic Control to determine whether to permit or deny files that are classified as Unknown by your Anti-Malware rules.  IPS management The Security section of the Site: < siteName>  page allows you to view the IPS Signature templates that are applied to the selected site and to configure site-level IPS settings. Aryaka’s IPS aims to prevent security threats and attacks by monitoring the events occurring in your network for potential security incidents. Potential security incidents are identified using signatures—unique patterns and identifiers that were present in past security incidents. IPS uses three collections of signatures that are updated daily by  Proofpoint  to monitor network traffic and identify any patterns that indicate a potential security threat. The three signature collections correspond to the following profiles: Basic—Provides a high level of security while ensuring optimized system performance. Includes approximately 17,000 signatures.   Moderate—Provides a balance between the basic and advanced profiles. Includes approximately 19,000 signatures.   Advanced—Provides the highest level of security protection against known and emerging threats. System performance can be impacted due to increased examination of traffic. Includes approximately 22,000 signatures.   Aryaka modifies these signature collections so that they can be used by the three IPS security engines (LAN-Side Basic IPS, WAN-Side Basic IPS, and Advanced IPS). The resulting nine signature collections are referred to as signature  feeds .  By default, each IPS security engine uses the basic signature feed. To change the signature feed for an IPS security engine, you must  create a Signature template . If you want to change the variables included in each signature, you must  configure global IPS settings  or follow the procedure in this topic to configure site-level IPS settings.  Follow the procedures in this section to view a list of the IPS Signature templates that are used to enforce IPS security rules at the selected site and to configure site-specific IPS settings.  To view a site's IPS Signature templates Log in to MyAryaka. The Home page appears. Click  Sites  in the left navigation pane. The Sites page appears. It lists all existing sites. Click the name of the site for which you want to view IPS Signature templates. The selected site's page appears. Click the  Security  section to expand it. A series of security tiles appears. Click  View  on the IPS Signature Template tile. The Signature Templates page appears in read-only mode and displays a list of all the configured IPS Signature templates that apply to the selected site. (Optional) To add a new Signature template or to edit an existing template, click  View Signature Templates . The Security > Signature Template page appears. Follow the procedures in the  Configure IPS Signature templates  topic to add or edit a Signature template.    To configure a site's IPS settings Log in to MyAryaka. The Home page appears. Click  Sites  in the left navigation pane. The Sites page appears. It lists all existing sites. Click the name of the site for which you want to configure IPS settings. The selected site's page appears. Click the  Security  section to expand it. A series of security tiles appears. Click  View  on the IPS Settings tile. The IPS Settings page appears in read-only mode and displays a table with all the configured signature variables that apply to the site. Click the  Edit  icon. The page appears in edit mode. Click the  Customize site-level settings  toggle. A tile appears for each of the variables that you can configure. Complete the following procedure for each of the variables you want to configure: Click the  Condition  drop-down list and select a condition for the variable. Click the  Add  icon. The Add < variable > dialog appears.  Enter one or more values you want to include for the variable. Click  Add Selected . The IPS Settings page displays the entered values for each variable.  Click  Submit . You are prompted to activate your configuration updates now or later. See  Activate configuration updates  for details.  (Optional) To edit a variable for all of your sites, click  Global Settings . The Security > IPS Settings page appears. Follow the procedure on the  Configure global IPS settings  page to configure the variable for all sites.    In this topic Related topics Getting Started with Aryaka Unified SASE Security engine rulesets Asset management