Aryaka · SASE / security engines

SASE Policy Actions

Software Engineer · C/C++ · NGFW · SWG · DNS · URL filtering · Reputation

Problem

SASE traffic must be enforced consistently at packet/session layer across multiple engines (firewall, secure web gateway, DNS, URL, reputation). Operators need rich actions — not only allow/deny — including monitor and content controls.

How it works

  • Policy objects map traffic selectors (including geo, users, apps, URLs, domains) to an action.
  • Actions are applied across NGFW, SWG, DNS, URL filtering, and IP/domain reputation engines.
  • Supported outcomes include permit, deny/drop/reject/refuse styles of block, and monitor/log-oriented paths; content paths can redact or mask sensitive data where required.
  • The zone/security engine evaluates flows and records policy outcomes for visibility and compliance.

What I built / owned

  • Implemented policy action handling in C/C++ across NGFW, SWG, DNS, URL filtering, and reputation paths.
  • Supported actions including Permit, Deny, Drop, Reject, Monitor, Redact, Mask, and Refuse.
  • Ensured secure, compliant data flow decisions at the packet/session layer.

Impact

Uniform, auditable enforcement across SASE engines — stronger security posture with flexible operational actions for different risk levels.

Tech

C/C++ · Policy engine · NGFW / SWG · DNS & URL filtering · Flow/session processing