Aryaka · SASE / security engines
SASE Policy Actions
Problem
SASE traffic must be enforced consistently at packet/session layer across multiple engines (firewall, secure web gateway, DNS, URL, reputation). Operators need rich actions — not only allow/deny — including monitor and content controls.
How it works
- Policy objects map traffic selectors (including geo, users, apps, URLs, domains) to an action.
- Actions are applied across NGFW, SWG, DNS, URL filtering, and IP/domain reputation engines.
- Supported outcomes include permit, deny/drop/reject/refuse styles of block, and monitor/log-oriented paths; content paths can redact or mask sensitive data where required.
- The zone/security engine evaluates flows and records policy outcomes for visibility and compliance.
What I built / owned
- Implemented policy action handling in C/C++ across NGFW, SWG, DNS, URL filtering, and reputation paths.
- Supported actions including Permit, Deny, Drop, Reject, Monitor, Redact, Mask, and Refuse.
- Ensured secure, compliant data flow decisions at the packet/session layer.
Impact
Uniform, auditable enforcement across SASE engines — stronger security posture with flexible operational actions for different risk levels.
Tech
C/C++ · Policy engine · NGFW / SWG · DNS & URL filtering · Flow/session processing