nerdexam
Palo_Alto_Networks

PCNSE · Question #512

A company is using wireless controllers to authenticate users. Which source should be used for User-ID mappings?

The correct answer is A. Syslog. Wireless LAN controllers (WLCs) generate authentication event logs when users associate and authenticate (typically via 802.1X/RADIUS). The Palo Alto Networks User-ID framework can consume these logs via syslog: the firewall or User-ID agent listens for syslog messages from the…

Submitted by helene.fr· Apr 18, 2026Deploy and Configure

Question

A company is using wireless controllers to authenticate users. Which source should be used for User-ID mappings?

Options

  • ASyslog
  • BXFF headers
  • Cserver monitoring
  • Dclient probing

How the community answered

(26 responses)
  • A
    88% (23)
  • B
    4% (1)
  • C
    4% (1)
  • D
    4% (1)

Explanation

Wireless LAN controllers (WLCs) generate authentication event logs when users associate and authenticate (typically via 802.1X/RADIUS). The Palo Alto Networks User-ID framework can consume these logs via syslog: the firewall or User-ID agent listens for syslog messages from the WLC and parses them to extract username-to-IP mappings. Syslog is the appropriate source type for infrastructure devices like WLCs that cannot be directly queried (ruling out server monitoring and client probing). XFF headers are used for web proxy scenarios to identify the original client IP, not for mapping users from wireless controllers.

Topics

#User-ID#Syslog Integration#Wireless Authentication#Identity Mapping

Community Discussion

No community discussion yet for this question.

Full PCNSE Practice