---
title: "Configure global IPS settings"
canonical: "https://docs.aryaka.com/space/KNOW/73662468/Configure%20global%20IPS%20settings"
format: markdown
---
The Security > IPS Settings page allows you to modify the named IP address and port variables included in the signatures that are used to enforce intrusion prevention system (IPS) security rules at all of your sites. A signature is a specific pattern that defines malicious activity or was attributed to a previous security attack. Aryaka’s IPS uses three collections of signatures that are updated daily by  Proofpoint  to monitor network traffic and identify any patterns that indicate a potential security threat. Aryaka modifies these signature collections so that they can be used by the three IPS security engines (LAN-Side Basic IPS, WAN-Side Basic IPS, and Advanced IPS). The resulting nine signature collections are referred to as signature  feeds  and they are displayed in a table on the  IPS Feeds  page. The IPS security engines use variables included in the signatures to identify and respond to potential security threats in a targeted manner. These variables represent your network environment. The combination of these variables is used to match incoming packets to the signatures included in the signature feed that is applied to the given site. Although you cannot add or delete signature feeds, you can change the following variables included in the signatures: IP Address variables—These variables define source and destination IP addresses. You can configure IP Address variables to include or exclude a subnet or a list of subnets. You can also configure the following two IP Address variables for individual sites: Home Network—This variable defines the statically or dynamically learned local subnets for a site. This is your trusted network. External Network—This variable defines the subnets that are not part of your local subnets. Port variables—These variables define source and destination ports. You can configure Port variables to include or exclude a port or list of ports.  You can configure IP address and Port variables globally (applies to all sites) using the procedure in this topic. However, the Home Network and External Network variables must be configured at the site level. See the  Configure site-level security features  topic for details on configuring site-level variables.  To edit global IPS settings Log in to MyAryaka. The Home page appears. Click  Security  >  IPS  in the left navigation pane. The IPS page appears. Click  Manage  in the IPS Settings tile. The IPS Settings page appears and displays the current IPS settings in read-only mode. Click the  Edit  icon. The IPS Settings page appears in edit mode. Click the  Customize global settings  toggle. A tile appears for each of the IP Address and Port variables that you can configure.  Note:  Home Network and External Network are IP Address variables that cannot be configured globally. Follow the procedure on the  Configure site-level security features  page to configure IPS settings for a specific site.  Complete the following procedure for each of the variables you want to configure:   Click the  Condition  drop-down list and select a condition for the variable. Click the  Add  icon. The Add < variable > dialog appears.  Enter one or more values you want to include for the variable. Click  Add Selected . The IPS Settings page displays the entered values for each variable.  Click  Submit . You are prompted to activate your configuration updates now or later. See  Activate configuration updates  for details. Related topics View IPS signature feeds Configure site-level security features Configure IPS Signature templates Configure IPS Modification policies IPS