NETSEC-ANALYST · Question #425
What is the best-practice approach to logging traffic that traverses the firewall?
The correct answer is C. Enable log at session end only.. The best-practice approach to logging traffic that traverses the firewall is to enable log at session end only. This option allows the firewall to generate a log entry only when a session ends, which reduces the load on the firewall and the log storage. The log entry contains inf
Question
What is the best-practice approach to logging traffic that traverses the firewall?
Options
- AEnable both log at session start and log at session end.
- BEnable log at session start only.
- CEnable log at session end only.
- DDisable all logging options.
How the community answered
(53 responses)- A2% (1)
- B13% (7)
- C77% (41)
- D8% (4)
Explanation
The best-practice approach to logging traffic that traverses the firewall is to enable log at session end only. This option allows the firewall to generate a log entry only when a session ends, which reduces the load on the firewall and the log storage. The log entry contains information such as the source and destination IP addresses, ports, zones, application, user, bytes, packets, and duration of the session. The log at session end option also provides more accurate information about the session, such as the final application and user, the total bytes and packets, and the session end reason. To enable log at session end only, you need to: Create or modify a Security policy rule that matches the traffic that you want to log. Select the Actions tab in the policy rule and check the Log at Session End option. Commit the changes to the firewall or Panorama and the managed firewalls.
Topics
Community Discussion
No community discussion yet for this question.