Soru

Zorluk: OrtaNetworking Ports and Protocols

A network administrator is setting up a centralized network monitoring and logging server. The server needs to collect system event log messages forwarded from network appliances and receive asynchronous alert notifications sent directly from managed switches. Which of the following port and protocol combinations must be opened on the firewall to support these two services? (Select TWO.)

  1. UDP port 514Cevap
  2. UDP port 162Cevap
  3. C
    UDP port 161
  4. D
    UDP port 67

Cevap

UDP port 514 (Syslog) and UDP port 162 (SNMP Trap) must be opened on the firewall.
Centralized log collection requires Syslog, which communicates via UDP port 514. Receiving asynchronous alert notifications requires an SNMP trap collector listening on UDP port 162. Opening both UDP port 514 and UDP port 162 allows the logging and monitoring server to fulfill both functional requirements.

Adım Adım Çözüm

1
Identify the protocol required for system event log forwarding.
Syslog is the standard protocol for forwarding event logs, which utilizes UDP port 514.
Centralized log management relies on UDP port 514 to accept message streams from routers, switches, and firewalls.
2
Identify the protocol required for receiving un-solicited monitoring alerts from managed switches.
SNMP Traps are asynchronous alerts sent to a management station, operating on UDP port 162.
While general SNMP queries use port 161 on the target device, trap receiver listening services require port 162.

Anahtar Kavram

Port assignments for Syslog (UDP 514) and SNMP Traps (UDP 162) vs SNMP Queries (UDP 161)
Bu soruyu puanla