Thank you for your response.
So if I understand correctly, TCP/257 is seen as management traffic and hits the implied rules that take priority over whatever is manually defined. However, why is this behavior different for logging? I am able to NAT CPD and related services to the SMS just fine, but failed to find a solution to send logs without the use of a VPN tunnel.
When I was able to forward TCP/257, it was seen (only once) in the logfile, but the logs were not added to the SmartConsole log browser.
If sending the logs over the VPN tunnel would not be recommended, what would be the correct solution?
Thank you for your time!