CompTIA Network+ (N10-009)Network OperationsMedium

A network engineer is configuring a new firewall and wants to ensure that all administrative access attempts, security alerts, and critical system events are sent to a centralized logging server for auditing and analysis. Which protocol should be configured on the firewall to forward these types of messages?

  1. ASyslog
  2. BNTP
  3. CNetFlow
  4. DSNMP
Show answer & explanation

Correct answer: A. Syslog

Syslog is the standard protocol for forwarding system log messages, including administrative access attempts, security alerts, and critical system events, from various network devices to a centralized logging server.

Why the other options are wrong

  • B. NTP is used for time synchronization, not for sending log messages.
  • C. NetFlow is used for collecting IP traffic flow statistics, not system event logs.
  • D. SNMP is used for monitoring and managing network devices, and while it can send traps for alerts, Syslog is more general for detailed log messages.

Syslog

A standard protocol used for sending system log or event messages from a network device to a centralized logging server. It allows for the collection and analysis of logs from various sources.

  • Standard for collecting diverse log messages.
  • Uses UDP port 514 by default.
  • Messages include facility and severity levels for categorization.

Memory trick: Logging needs a 'Sys'tematic 'Log' collector.

More Network Operations questions