---
title: "Monitor WAN Routing and Basic Firewall engine"
canonical: "https://docs.aryaka.com/space/KNOW/43253859/Monitor%20WAN%20Routing%20and%20Basic%20Firewall%20engine"
format: markdown
---
The Engine: WAN Routing and Basic Firewall page allows you to monitor the action taken on your network traffic based on your configured WAN Routing and Basic Firewall policies for the selected scope and time period. If it is not already open, complete the following procedure to view the Engine: WAN Routing and Basic Firewall page: To view the Engine: WAN Routing and Basic Firewall page Log in to MyAryaka. The Home page appears. Click  Security  >  Monitor  in the left navigation pane. The Security: < siteName > page appears and displays a series of tables and graphs.  Click the  Scope  field and select the site or node for which you want to monitor the WAN Routing and Basic Firewall engine. Click the  Time  field and select the time period for which you want to monitor the WAN Routing and Basic Firewall engine. Click the  WAN Routing and Basic Firewall  security engine in the Engine Sequencing diagram. The Engine: WAN Routing and Basic Firewall page appears and displays an Engine Sequencing diagram and a series of graphs, which are described in detail later in this topic. Engine Sequencing diagram The Engine Sequencing diagram displays the security engines that the WAN Routing and Basic Firewall engine receives traffic from and the engines that it sends traffic to after inspection. Click the source engine to view the  Monitor LAN-Side Basic IPS security engine  page. Click a destination engine to view either the  Monitor Interzone Firewall engine  page or the  Monitor Domain Reputation security engine  page.  The following graphic shows an example of the outbound WAN Routing and Basic Firewall engine: The red value displayed on the WAN Routing and Basic Firewall engine indicates the number of flows that were dropped or denied by the engine over the selected time period. Hover over the blue circle to the left of the WAN Routing and Basic Firewall engine to view the number of inbound flows for the selected time period. Hover over the blue circle to the right of the WAN Routing and Basic Firewall engine to view the number of outbound flows for the selected time period. Included graphs The sections that follow describe each of the graphs included on the Engine: WAN Routing and Basic Firewall page. Flows This time series graph displays the total number of flows, the number of routed flows, the number of forwarded flows, the number of dropped flows, and the number of flows sent to the zone-based firewall for the selected scope over the selected time period. A  flow  is a series of communications between two network endpoints from the time a connection is established until it is terminated. Policy-based Route Actions This graph can be viewed as a donut graph (default) or a table and displays the total number of flows where the following actions were taken: Route using longest prefix match—Traffic is routed to the available networks based on the greatest number of matching digits in the subnet mask. Route using IPSLA—Traffic is routed to the available networks based on the networks' health. Route using cost—Traffic is routed to the available networks based on the lowest associated cost. Route using networks—Traffic is routed to the available networks in a user-defined sequence. Forward to interface—Traffic is sent to the ANAP's M1 or M2 interface. Blackhole—Traffic is denied and the sender does not receive a message. ICMP unreachable—Traffic is denied and the sender receives an ICMP Unreachable message code 1. Prohibit—Traffic is denied and the sender receives an ICMP Unreachable message code 13. Sent to interzone firewall—Traffic is sent to the interzone firewall and your configured  internet policies  determine what happens to traffic as it crosses segments and zones.  Policy actions are configured in your  WAN Routing and Basic Firewall policies . Blocked Sites This bar graph displays the top ten licensed sites that had flows blocked during the selected time period.  Blocked Nodes This bar graph displays the top ten private access nodes that had flows blocked during the selected time period.  The Blocked Sites graph is only displayed when the Scope field is Global or All Sites. The Blocked Nodes graph is only displayed when the Scope field is Global or All Nodes. In this topic Related topics Create site-level WAN Routing and Basic Firewall policies Create customer-level WAN Routing and Basic Firewall policies Monitor security