A security operations engineer is setting up a centralized SIEM server to aggregate system logs and security events from enterprise core switches. To ensure standard unencrypted syslog traffic successfully reaches the collector, which port and transport protocol combination must be permitted on the network firewalls?
- UDP port 514Cevap
- BTCP port 514
- CUDP port 162
- DUDP port 161
Cevap
Standard Syslog messages require UDP port 514 to be allowed through network firewalls.
Standard Syslog utilizes User Datagram Protocol (UDP) on port 514 to transmit event notification messages to a central log server without session establishment overhead.
Adım Adım Çözüm
Anahtar Kavram
Syslog Protocol and Port Number
Tahmini Süre:1m 0s