Soru

Zorluk: OrtaNetwork Host Services and Server Roles

A field technician is troubleshooting a newly installed centralized log collector in an enterprise datacenter. Network switches and routers have been configured to forward event logs to this host, but no log entries are appearing in the collector console. Packet captures indicate inbound log messages reach the network interface but are dropped by the host-based firewall. Which firewall rule modification should the technician perform to allow standard Syslog traffic?

  1. Allow inbound traffic on UDP port 514Cevap
  2. B
    Allow inbound traffic on TCP port 514
  3. C
    Allow inbound traffic on UDP port 67
  4. D
    Allow inbound traffic on UDP port 169

Cevap

Allow inbound traffic on UDP port 514
Centralized Syslog servers act as network host collectors that accept system state, warning, and error messages from network infrastructure devices. Standard Syslog operates over UDP port 514. Permitting inbound traffic on UDP port 514 through the host firewall allows log messages to reach the collector daemon.

Adım Adım Çözüm

1
Identify the host service role requested in the scenario
The scenario describes a centralized log collection role (Syslog server).
The server's function is to receive system event logs from switches and routers.
2
Determine the default port and transport protocol for Syslog
Standard Syslog uses User Datagram Protocol (UDP) on port 514.
CompTIA A+ guidelines specify UDP 514 for Syslog message delivery across network hosts.
3
Select the host firewall configuration rule matching the service requirement
Configuring an inbound firewall rule allowing UDP port 514 resolves the dropped packet issue.
Opening UDP port 514 permits incoming log packets to pass through the host firewall to the Syslog daemon.

Anahtar Kavram

Syslog Server Role and Default Port Configuration
Bu soruyu puanla