PCNSE · Question #512
A company is using wireless controllers to authenticate users. Which source should be used for User-ID mappings?
The correct answer is A. Syslog. Wireless LAN controllers (WLCs) generate authentication event logs when users associate and authenticate (typically via 802.1X/RADIUS). The Palo Alto Networks User-ID framework can consume these logs via syslog: the firewall or User-ID agent listens for syslog messages from the…
Question
A company is using wireless controllers to authenticate users. Which source should be used for User-ID mappings?
Options
- ASyslog
- BXFF headers
- Cserver monitoring
- Dclient probing
How the community answered
(26 responses)- A88% (23)
- B4% (1)
- C4% (1)
- D4% (1)
Explanation
Wireless LAN controllers (WLCs) generate authentication event logs when users associate and authenticate (typically via 802.1X/RADIUS). The Palo Alto Networks User-ID framework can consume these logs via syslog: the firewall or User-ID agent listens for syslog messages from the WLC and parses them to extract username-to-IP mappings. Syslog is the appropriate source type for infrastructure devices like WLCs that cannot be directly queried (ruling out server monitoring and client probing). XFF headers are used for web proxy scenarios to identify the original client IP, not for mapping users from wireless controllers.
Topics
Community Discussion
No community discussion yet for this question.