PCNSA · Question #15
Your company requires positive username attribution of every IP address used by wireless devices to support a new compliance requirement. You must collect IP-to-user mappings as soon as possible…
The correct answer is A. syslog. Syslog is the correct answer. Wireless infrastructure (access points and controllers) from various manufacturers can nearly universally send syslog messages containing authentication events (including username and IP address) without requiring changes to the wireless client…
Question
Your company requires positive username attribution of every IP address used by wireless devices to support a new compliance requirement. You must collect IP-to-user mappings as soon as possible with minimal downtime and minimal configuration changes to the wireless devices themselves. The wireless devices are from various manufactures. Given the scenario, choose the option for sending IP-to-user mappings to the NGFW.
Options
- Asyslog
- BRADIUS
- CUID redistribution
- DXFF headers
How the community answered
(36 responses)- A72% (26)
- B3% (1)
- C8% (3)
- D17% (6)
Explanation
Syslog is the correct answer. Wireless infrastructure (access points and controllers) from various manufacturers can nearly universally send syslog messages containing authentication events (including username and IP address) without requiring changes to the wireless client devices themselves. The NGFW's User-ID syslog listener can parse these messages to build IP-to-user mappings immediately. RADIUS (choice B) would require the firewall to act as an intermediary in the authentication path - a larger architectural change. UID redistribution (choice C) is for sharing mappings between Palo Alto firewalls, not collecting them from wireless infrastructure. XFF headers (choice D) are for web proxy scenarios, not wireless.
Topics
Community Discussion
No community discussion yet for this question.