PCNSE · Question #147
Refer to exhibit. An organization has Palo Alto Networks NGFWs that send logs to remote monitoring and security management platforms. The network team has reported excessive traffic on the corporate…
The correct answer is A. Forward logs from firewalls only to Panorama and have Panorama forward logs to other external. To reduce WAN traffic from firewalls sending logs to multiple platforms, centralize log forwarding by sending all logs to Panorama first, and then have Panorama distribute those logs to other external monitoring platforms.
Question
Refer to exhibit. An organization has Palo Alto Networks NGFWs that send logs to remote monitoring and security management platforms. The network team has reported excessive traffic on the corporate WAN. How could the Palo Alto Networks NGFW administrator reduce WAN traffic while maintaining support for all existing monitoring platforms?
Exhibit
Options
- AForward logs from firewalls only to Panorama and have Panorama forward logs to other external
- BForward logs from external sources to Panorama for correlation, and from Panorama send them to
- CConfigure log compression and optimization features on all remote firewalls.
- DAny configuration on an M-500 would address the insufficient bandwidth concerns.
How the community answered
(25 responses)- A88% (22)
- B4% (1)
- D8% (2)
Why each option
To reduce WAN traffic from firewalls sending logs to multiple platforms, centralize log forwarding by sending all logs to Panorama first, and then have Panorama distribute those logs to other external monitoring platforms.
By having firewalls forward logs *only* to Panorama, and then configuring Panorama to distribute those logs to other external monitoring platforms, you consolidate log traffic over the WAN, preventing multiple streams of identical logs from each firewall to each platform, thereby reducing overall WAN bandwidth consumption.
This option describes forwarding logs *from* external sources *to* Panorama, which is incorrect for the scenario of firewalls generating logs and consuming WAN bandwidth to send them out.
While log compression and optimization features might exist and could help, the most significant reduction in WAN traffic for a scenario involving multiple firewalls and multiple external platforms is achieved through consolidation via Panorama, which eliminates redundant log streams.
An M-500 is a Panorama appliance, but simply stating "Any configuration on an M-500" is too vague and doesn't specify a method to address the excessive WAN traffic; the specific configuration of centralizing log forwarding is key.
Concept tested: Centralized log forwarding with Panorama
Source: https://docs.paloaltonetworks.com/panorama/11-1/panorama-admin/manage-logs/configure-log-forwarding-to-external-destinations-from-panorama.html
Topics
Community Discussion
No community discussion yet for this question.
