---
title: "Firewall monitoring service - YODA"
canonical: "https://docs.aryaka.com/space/KNOW/1275592735/Firewall%20monitoring%20service%20-%20YODA"
format: markdown
---
Aryaka's on-cloud firewall monitoring service includes the following components: APE (additional polling engine)—On-premises polling engine that resides at the customer site and monitors the health of your managed firewalls. It sends SNMP, log, and configuration information to Aryaka's on-cloud monitoring service. YODA—Aryaka's on-cloud monitoring tool that comprises an SQL DB and monitoring UI running on the SolarWinds Orion platform. High-level architecture To maintain the highest standard of security and multi-tenancy, a customer-specific APE polling engine is deployed at the customer's site. All firewalls in the customer environment send SNMP, log, and configuration information to the APE polling engine. This on-premises polling engine then sends all this information to YODA—the Aryaka cloud-based monitoring tool. APE polling engine APE is a SolarWinds Orion platform management server that is responsible for performing the following tasks: Monitor status of all firewalls. Collect SNMP statistics from all firewalls. Download configuration details from all firewalls and store it as backup data. All of the customer's firewalls are to have access to the APE and the APE is connected to Aryaka's main polling engine. This provides Aryaka with centralized firewall monitoring and management requiring only connectivity to the APE from our infrastructure. APE hardware requirements This section lists the polling engine hardware requirements (from solarwinds.com): Amazon Web Service: m5.xlarge Microsoft Azure: D4s_v3 On premises: Quad core processor or better 32 GB RAM Storage: 150 GB, 15,000 RPM 1 x 1 Gb dedicated NIC Windows Server 2019, 2016 or 2012 R2, Standard or Datacenter Edition  APE software requirements This section lists the polling engine software and user account requirements: APE's Windows machines must run SolarWinds Scalability Engine software provided by Aryaka Networks. APE hostname must contain the customer name at the end. APE must be in UTC timezone. APE must have a static IP address configured. APE must be in a subnet assigned by Aryaka. Customers can create a separate VLAN for the APE to isolated it from other devices. APE requires an Aryaka service account created locally on the APE by an Aryaka Engineer as follows: This must not be an administrator account so that remote login is  not  possible. Set the password so it does  not  expire. The password for this user account is  not  shared with the customer. Ports that must be opened on the server for inbound traffic: TCP: 22, 1801, 5671, 17777, 17778 UDP: 162 ICMP  Packet flow The following graphic shows the packet flow between the cloud monitoring service components. Health parameters monitored by YODA The following health statistics are monitored and logged: Node status Software version Node uptime Network latency and packet loss from Jumphost Availability statistics Disk usage CPU usage Memory usage Interface status Interface bytes in/out Panorama connectivity (for Palo Alto Networks integrations) HA mode and status (for Palo Alto Networks integrations) TCP/UDP/ICMP sessions Total/Max sessions Login failure Trap and configuration logging Traps are logged and are retained for one week. Configuration backups are taken weekly, and are retained for one month. Alerts The following events result in an alert being sent to Aryaka's Managed Firewall Service personnel who can then take the appropriate corrective action. High CPU High memory Node is down Node rebooted Interface down APE management communications The following graphic shows the communications sent between the cloud monitoring service components. APE to firewall communications over Aryaka The following graphic shows the communications sent between two Palo Alto Networks firewalls and the YODA on-cloud polling engine. In this topic Related topics APE implementation guidelines  ( solarwinds.com )