PCNSE · Question #730
An administrator troubleshoots an issue that causes packet drops. Which log type will help the engineer verify whether packet buffer protection was activated?
The correct answer is D. Threat. Packet Buffer Protection (PBP) is a PAN-OS DoS defense mechanism that monitors the firewall's packet buffer utilization. When the buffer usage exceeds defined thresholds, PBP activates and can drop, block, or randomly discard packets to protect the dataplane. Activation events fo
Question
An administrator troubleshoots an issue that causes packet drops. Which log type will help the engineer verify whether packet buffer protection was activated?
Options
- AConfiguration
- BData Filtering
- CTraffic
- DThreat
How the community answered
(14 responses)- A7% (1)
- B14% (2)
- D79% (11)
Explanation
Packet Buffer Protection (PBP) is a PAN-OS DoS defense mechanism that monitors the firewall's packet buffer utilization. When the buffer usage exceeds defined thresholds, PBP activates and can drop, block, or randomly discard packets to protect the dataplane. Activation events for Packet Buffer Protection are recorded in the Threat log, not in the Traffic, Configuration, or Data Filtering logs. In the Threat log, you will see entries with a specific threat category related to DoS/PBP activation. The Threat log is the correct place to verify whether PBP was triggered and to gather details about the event, including timestamps, source zones, and the action taken.
Topics
Community Discussion
No community discussion yet for this question.