- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
Enhanced Security Measures in Place: To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.
10-05-2015 02:32 AM
We use the Syslog integration in the PAN Agents to forward User/IP-mappings from our wireless controllers to PA 5020 firewalls.
We are considering to move the Syslog integration to connect directly with the PA5020 instead of the PAN Agents. But i remember having read something about limitations on the built-in Syslog reciever. That we should still use the PA Agents for "large scale use".
I have now searched for hours for a document describing how many mappings (or other nubmers/limits) the built-in Syslog kan handle. But with no luck. Can anyone help with information about what can be expected by the built-in Syslog listener?
Our setup is: 30 PA agents in different Active Directory domains forwarding userinformation. 30 Wireless controllers forwarding userinformation to the seperate PA agents. In total there's about 50.000 IP mappings where about 35.000 comes from Syslog.
10-05-2015 02:48 AM
there is no built-in limit. What matters is logs/second you forward to it.
Dont use FW embedded agent in general : what will happen the day you start forwarding 10x or 100x more logs than usual when for example, your wifi controllers have issues and start re-authenticatiing people in a loop ?
10-05-2015 02:48 AM
there is no built-in limit. What matters is logs/second you forward to it.
Dont use FW embedded agent in general : what will happen the day you start forwarding 10x or 100x more logs than usual when for example, your wifi controllers have issues and start re-authenticatiing people in a loop ?
10-05-2015 03:34 AM
At peak hours we have about 300-400 syslog messages/second.
If there are no limits at all, then i guess using the built-in would be able to put the management plane to 100% usage if a loop occurs. And that would be a bad thing 🙂
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!