---
title: "Monitor Next Generation Firewall security engine"
canonical: "https://docs.aryaka.com/space/KNOW/43319312/Monitor%20Next%20Generation%20Firewall%20security%20engine"
format: markdown
---
The Engine: Next Generation Firewall page allows you to monitor the amount of traffic that was permitted or denied by your Next Generation Firewall rules and the action that was taken based on your rule configuration for the selected scope and time period. If it is not already open, complete the following procedure to view the Engine: Next Generation Firewall page: To view the Engine: Next Generation Firewall page Log in to MyAryaka. The Home page appears. Click  Security  >  Monitor  in the left navigation pane. The Security: < siteName > page appears and displays a series of tables and graphs.  Click the  Scope  field and select the site or node for which you want to monitor the Next Generation Firewall security engine. Click the  Time  field and select the time period for which you want to monitor the Next Generation Firewall security engine. Click the  Next Generation Firewall  (NGFW) security engine in the Engine Sequencing diagram. The Engine: Next Generation Firewall page appears and displays an Engine Sequencing diagram and a series of graphs, which are described in detail later in this topic. Engine Sequencing diagram The Engine Sequencing diagram displays the security engine that the Next Generation Firewall engine receives traffic from and the engines that it sends traffic to after inspection. Click the source engine to view the  Monitor Domain Reputation security engine  page. Click a destination engine to view either the  Monitor SaaS Apps Access Control security engine  page or the  Monitor DNS Filtering security engine  page.  The following graphic shows an example of the Next Generation Firewall engine: The red value displayed on the Next Generation Firewall engine indicates the number of flows that were dropped or denied by the engine over the selected time period. Hover over the blue circle to the left of the Next Generation Firewall engine to view the number of inbound flows for the selected time period. Hover over the blue circle to the right of the Next Generation Firewall engine to view the number of outbound flows for the selected time period. Hover over the blue circle below the Next Generation Firewall engine to view the number of outbound flows that skipped further inspection after being inspected by the Next Generation Firewall engine.  Included graphs The sections that follow describe each of the graphs included on the Engine: Next Generation Firewall page. Flows This time series graph displays the total number of flows, the number of permitted flows, and the number of denied flows for the selected scope over the selected time period. A  flow  is a series of communications between two network endpoints from the time a connection is established until it is terminated. Actions This graph can be displayed as a donut graph (default) or as a table. It displays the total number of flows where the following actions were taken: Permit—Traffic is permitted and sent to the next security engine for inspection. Drop—Traffic is denied and the client does not receive a response. Log Only—Traffic is permitted and sent to the next security engine for inspection. This is intended as a temporary action while you evaluate traffic. After you have evaluated traffic, update the rule with one of the other actions. Skip All—Traffic is permitted and bypasses all other security engines. Reject—Traffic is denied and the TCP connection is reset. For non-TCP connections, the client receives an  ICMP Unreachable  response. Prohibit—Traffic is denied and the client receives an  ICMP Unreachable  response. Rule actions are configured in your  Next Generation Firewall rules . Blocked Sites This bar graph displays the top ten licensed sites that had flows blocked during the selected time period.  Blocked Nodes This bar graph displays the top ten private access nodes that had flows blocked during the selected time period.  The Blocked Sites graph is only displayed when the Scope field is Global or All Sites. The Blocked Nodes graph is only displayed when the Scope field is Global or All Nodes. In this topic Related topics Configure a Next Generation Firewall ruleset Monitor security