---
title: "Monitor WAN-Side Basic IPS security engine"
canonical: "https://docs.aryaka.com/space/KNOW/57180641/Monitor%20WAN-Side%20Basic%20IPS%20security%20engine"
format: markdown
---
The Engine: WAN-Side Basic IPS page allows you to monitor the amount of traffic that was permitted or denied by your WAN-Side Basic IPS rules and the action that was taken based on your rule configuration for the selected scope and time period. If it is not already open, complete the following procedure to view the Engine: WAN-Side Basic IPS page: To view the Engine: WAN-Side Basic IPS page Log in to MyAryaka. The Home page appears. Click  Security  >  Monitor  in the left navigation pane. The Security: < siteName > page appears and displays a series of tables and graphs.  Click the  Scope  field and select the site or node for which you want to monitor the WAN-Side Basic IPS security engine. The selected scope's Monitor > Security page appears with the Time filter set to the last hour and the Outbound view of the Engine Sequencing diagram selected by default. (Optional) Click the  Time  field and select the time period for which you want to monitor the WAN-Side Basic IPS security engine, then click  Apply . The filter is applied to the selected scope. Click  Inbound  on the Engine Sequencing diagram. The  WAN-Side Basic IPS  security engine appears in the in the Engine Sequencing diagram. Click the  WAN-Side Basic IPS  security engine in the Engine Sequencing diagram. The Engine: WAN-Side Basic IPS page appears and displays an Engine Sequencing diagram and a series of graphs, which are described in detail later in this topic. Engine Sequencing diagram The Engine Sequencing diagram displays the source that the WAN-Side Basic IPS engine receives traffic from and the engine that it sends traffic to after inspection. Click the destination engine to view the  Monitor WAN Routing and Basic Firewall engine  page. The following graphic shows an example of the WAN-Side Basic IPS engine: The red value displayed on the WAN-Side Basic IPS engine indicates the number of flows that were dropped or denied by the engine over the selected time period. Hover over the blue circle to the left of the WAN-Side Basic IPS engine to view the number of inbound flows for the selected time period. Hover over the blue circle to the right of the WAN-Side Basic IPS engine to view the number of outbound flows for the selected time period. Included graphs The sections that follow describe each of the graphs included on the Engine: WAN-Side Basic IPS page. Flows This time series graph displays the total number of flows, the number of permitted flows, and the number of denied flows for the selected scope over the selected time period. A  flow  is a series of communications between two network endpoints from the time a connection is established until it is terminated. IPS Verdict by Action This sunburst graph displays the distribution of WAN-Side Basic IPS verdicts and the actions taken as a result of those verdicts for all traffic flows. The inner ring shows the total number of flows, the middle ring shows the distribution of flows with different WAN-Side Basic IPS verdicts (alerted, passed, dropped, rejected, or unknown), and the outer ring shows the actions that were taken (enforce, ignore, skip, or log) for each WAN-Side Basic IPS verdict.  Rule actions are configured in your  WAN-Side Basic IPS rules . IPS Rule Action by Verdict This sunburst graph displays the distribution of WAN-Side Basic IPS rule actions that were taken as a result of WAN-Side Basic IPS verdicts for all traffic flows. The inner ring shows the total number of flows, the middle ring shows the distribution of flows to which different rule actions were applied (enforce, ignore, skip, or log) based on the WAN-Side Basic IPS verdicts, and the outer ring shows the verdict (alerted, passed, dropped, rejected, or unknown) of the traffic flow that had the rule action applied to it.  Rule actions are configured in your  WAN-Side Basic IPS rules . Risky Sites This bar graph displays the top ten licensed sites that had flows classified as risky during the selected time period.  Blocked Sites This bar graph displays the top ten licensed sites that had flows blocked during the selected time period.  The Risky Sites and Blocked Sites graphs are only displayed when the Scope field is Global or All Sites. Risky Nodes This bar graph displays the top ten private access nodes that had flows classified as risky during the selected time period.  Blocked Nodes This bar graph displays the top ten private access nodes that had flows blocked during the selected time period.  The Risky Nodes and Blocked Nodes graphs are only displayed when the Scope field is Global or All Nodes. In this topic Related topics Configure a WAN-Side Basic IPS ruleset Monitor security