Palo Alto Networks Certified Network Security Engineer (PCNSE)Manage and OperateMedium
A security auditor requires a daily report of all blocked connections originating from the 'Guest-WiFi' zone to any internal network resources. The report should include the source IP, destination IP, application, and the reason for blocking. Which Panorama reporting feature would best fulfill this requirement?
- APredefined Reports from the ACC tab.
- BUser-ID Logs for guest user activity.
- CCustom Reports based on Traffic logs.
- DThreat Logs for blocked connections.
Show answer & explanationAnswer & explanation
Correct answer: C. Custom Reports based on Traffic logs.
Custom Reports in Panorama (or on the firewall) allow administrators to filter specific log types (like Traffic logs), define custom time ranges (e.g., daily), select desired columns (source IP, destination IP, application), and sort/group the data to meet specific auditing requirements.
Why the other options are wrong
- A. Predefined reports in the ACC are often too general and may not provide the specific filtering or column selection required for this detailed audit.
- B. User-ID Logs provide user authentication events and user-to-IP mappings, not details about blocked network connections themselves.
- D. Threat Logs primarily capture threats detected by security profiles (viruses, spyware etc.). While some blocked traffic might appear here, the 'reason for blocking' for general policy blocks (e.g., policy deny) is found in Traffic logs.
Palo Alto Networks Custom Reports
Custom Reports in Palo Alto Networks allow administrators to create highly specific reports by filtering various log types, selecting desired data fields, specifying time ranges, and defining grouping/sorting criteria.
- Highly customizable log analysis.
- Can be scheduled for regular delivery.
- Supports various log types (Traffic, Threat, URL, etc.).
Memory trick: Reporting: Custom Reports for Specific Needs, Logs are the Source.