Configure Syslog to use a DMZ on the FirewallThis option configures your router to send syslog messages to a syslog server residing in a DMZ off your firewall.
Positives - Allows use of a hardened syslog server, allows firewall to filter traffic to syslog server.
Negatives - You have to configure a syslog server and have to configure your firewall to allow and analyze the traffic.
Note: You should probably choose this option if you don't have a DMZ but do have a syslog server on your local network.
Configuring syslog to use a DMZ on the firewall is recommended.