A field technician is troubleshooting a newly installed centralized log collector in an enterprise datacenter. Network switches and routers have been configured to forward event logs to this host, but no log entries are appearing in the collector console. Packet captures indicate inbound log messages reach the network interface but are dropped by the host-based firewall. Which firewall rule modification should the technician perform to allow standard Syslog traffic?
- Allow inbound traffic on UDP port 514Cevap
- BAllow inbound traffic on TCP port 514
- CAllow inbound traffic on UDP port 67
- DAllow inbound traffic on UDP port 169
Cevap
Allow inbound traffic on UDP port 514
Centralized Syslog servers act as network host collectors that accept system state, warning, and error messages from network infrastructure devices. Standard Syslog operates over UDP port 514. Permitting inbound traffic on UDP port 514 through the host firewall allows log messages to reach the collector daemon.
Adım Adım Çözüm
Anahtar Kavram
Syslog Server Role and Default Port Configuration