Palo Alto Networks Certified Network Security Administrator (PCNSA)Initial Configuration and ManagementMedium
A network engineer is configuring a Palo Alto Networks firewall to forward logs to an external syslog server. After configuring the syslog server profile, they notice that no logs are being sent. Which of the following is a common reason for this issue related to initial configuration?
- AThe management interface has not been assigned a default gateway.
- BThe syslog server's IP address is configured with an incorrect port number.
- CThe syslog server profile is not associated with a log forwarding profile.
- DThe firewall clock is not synchronized with an NTP server.
Show answer & explanationAnswer & explanation
Correct answer: C. The syslog server profile is not associated with a log forwarding profile.
Even after creating a syslog server profile, logs will not be forwarded unless that profile is referenced and applied within a Log Forwarding Profile, which is then attached to security policies or other logging-enabled features.
Why the other options are wrong
- A. A missing default gateway on the management interface would prevent reachability to the syslog server if it's on a different subnet, but the question implies the profile is 'configured,' not necessarily that the server is unreachable. The most common configuration oversight is the forwarding profile.
- B. An incorrect port number would certainly prevent logs from being received by the syslog server, but the question is about logs 'not being sent' from the firewall, and the most common initial config error is the missing forwarding profile association.
- D. An unsynchronized clock can cause issues with log timestamps, but it doesn't prevent logs from being sent entirely.
Log Forwarding Profile
A configuration object on Palo Alto Networks firewalls that specifies which logs (traffic, threat, system, etc.) to forward and to which external destinations (syslog, SNMP, email, HTTP).
- Links log types to external server profiles.
- Applied to security rules or other logging features.
- Crucial for sending logs off the firewall.
Memory trick: Syslog knows the address, but needs the forwarding profile to mail the logs out!