Palo Alto Networks Certified Network Security Engineer (PCNSE) flashcards
160 free flashcards. Tap a card to flip it.
flow_np_sess_alloc_fail
Flip cardA Palo Alto Networks packet drop reason indicating that the firewall failed to allocate a new session, often due to the session table being full or exceeding the new session rate limit.
- Indicates session table exhaustion or rate limit.
- Occurs during new session setup.
- Requires investigation into firewall capacity or traffic patterns.
Memory trick: No session allocated? Check your session table, it's overloaded!
Palo Alto Networks HA Session Synchronization
Flip cardSession synchronization in Palo Alto Networks High Availability (HA) ensures that connection state information is replicated between active and passive firewalls, enabling seamless traffic flow during a failover event.
- Replicates session table entries, NAT sessions, and IPSec Security Associations.
- Prevents interruption of existing connections upon failover.
- Requires dedicated HA control and data links.
Memory trick: Synchronized sessions make failover 'Seamless' like a smooth transition.
Palo Alto Packet Flow - Session Setup
Flip cardDuring the Session Setup stage of the Palo Alto Networks packet flow, the firewall performs a comprehensive lookup against its security policies and creates a session if traffic is allowed, or drops it if denied.
- Occurs for the first packet of a new connection.
- App-ID, Content-ID, User-ID are applied.
- Determines allow/deny based on security policies.
Memory trick: First, Setup the Session, then Speed on the Fast Path.
URL Filtering Profile
Flip cardA URL Filtering Profile in Palo Alto Networks firewalls is used to control user access to websites based on predefined categories, custom URL lists, or real-time classification, preventing access to malicious or inappropriate content.
- Controls web access based on URL categories.
- Can block, allow, or alert on specific categories.
- Essential for web security and compliance.
Memory trick: Profiles are the Guards: URL for Websites, AV for Files, Vuln for Exploits.
Source NAT Identification
Flip cardIf a server receives traffic and the source IP address is the firewall's egress interface IP, it indicates that Source NAT (SNAT) has been applied to the traffic.
- SNAT changes the source IP of packets.
- Often used for outbound internet access.
- Can be dynamic (PAT) or static (1:1).
Memory trick: NAT is a 'Name Changer' for IPs, check 'Source' if it's wrong.
Custom App-ID
Flip cardCustom App-ID allows administrators to create signatures for internally developed or niche applications that are not recognized by Palo Alto Networks' standard App-ID database.
- Identifies applications based on payload/behavior, not just port.
- Maintains deep packet inspection capabilities.
- Requires knowledge of application traffic characteristics.
Memory trick: Custom signatures teach the firewall new tricks.
Palo Alto pkt-proc-delay
Flip cardThe 'pkt-proc-delay' metric in the Palo Alto Networks firewall session browser indicates the time a packet spends being processed by the firewall's dataplane.
- High values suggest firewall resource exhaustion.
- Identifies bottlenecks within the firewall itself.
- Often points to CPU, session, or memory limits.
Memory trick: Packet Processing Delay: The 'Processor' is the 'Problem'.
IKE Phase 1 Mismatch
Flip cardIKE Phase 1 (Internet Key Exchange Phase 1) is the initial negotiation stage of a VPN tunnel where security parameters are agreed upon to establish a secure channel for subsequent negotiations.
- Establishes the ISAKMP SA.
- Negotiates encryption, authentication, DH group, and lifetime.
- Common error: 'No proposal chosen'.
Memory trick: VPN tunnels need a strong handshake before they can talk secrets.
GlobalProtect SSL Failure
Flip cardGlobalProtect 'SSL negotiation failed' usually points to issues with the SSL/TLS Service Profile on the gateway, such as certificate problems or cipher suite mismatches.
- Occurs during SSL handshake.
- Check gateway's SSL/TLS Service Profile.
- Certificate validity and trust are critical.
Memory trick: You can knock on the gate, but if the guard's ID is bad, you're not getting in.
Log Forwarding Configuration
Flip cardFor Palo Alto Networks firewalls to forward logs to external syslog servers, a logging profile must be created, configured to send logs to a syslog server profile, and then attached to the relevant security policies.
- Logging profile links policies to syslog server.
- Syslog server profile defines server details (IP, port, protocol).
- Without attachment, logs remain local (or are not generated).
Memory trick: Syslog needs a 'Profile Pointer' to send the 'Paper'.
Panorama Disconnected Firewall
Flip cardA firewall appearing 'Disconnected' in Panorama often indicates an authentication failure, preventing Panorama from establishing a management session with the device.
- Ping success indicates network reachability.
- Administrative credentials are key for Panorama management.
- Password changes on the firewall require Panorama update.
Memory trick: Panorama's view needs proper 'Pass' to connect.
Decryption Internal Cert Trust
Flip cardFor SSL decryption to work seamlessly with internal applications using self-signed certificates, the Palo Alto Networks firewall must trust those certificates.
- Firewall acts as a proxy during decryption.
- Must validate server certificate before re-signing.
- Importing the server's root CA to the firewall's trusted store resolves warnings.
Memory trick: Decryption needs Trust, both Ways for Warnings to Cease.
IKE Local ID
Flip cardThe Local IKE Gateway Identification is a unique identifier used by an IKE gateway to identify itself to its peer during Phase 1 negotiation.
- Must match the remote peer's configured remote ID.
- Can be IP address, FQDN, or user FQDN.
- Crucial for successful IKE Phase 1 establishment.
Memory trick: Identify the ID to untie the VPN knot.
External Auth Connectivity
Flip cardTroubleshooting external authentication connectivity involves verifying network reachability and basic communication between the firewall and the authentication server (e.g., RADIUS, LDAP).
- Connection Timeout = no network path.
- Authentication Failed = bad credentials/config.
- Firewall rules can block auth traffic.
Memory trick: Before you can knock, you need to find the door.
External Auth Connectivity Test
Flip cardWhen external authentication (e.g., RADIUS, LDAP) timeouts occur, verifying basic IP connectivity from the firewall's perspective, especially from the correct source interface, is a critical initial troubleshooting step.
- Use 'ping source <interface> host <server-ip>' for basic reachability.
- Ensure routing, firewall rules, and ACLs allow traffic.
- Timeouts often indicate network path issues, not protocol errors.
Memory trick: Ping the source to solve the timeout's course.
HA Version Mismatch
Flip cardPalo Alto Networks firewalls in an HA pair must run the identical software version to ensure proper synchronization and functionality.
- Required for active/passive and active/active HA.
- Mismatched versions can lead to 'non-functional' or 'partial' states.
- Always upgrade both devices to the same version.
Memory trick: High Availability needs Harmonic Alignment of versions.
IKE Phase 2 Proposal Mismatch
Flip cardThe 'No proposal chosen' error during IKE Phase 2 (IPsec SA negotiation) indicates that the IPsec Crypto Profiles on both VPN peers do not have a mutually acceptable set of security parameters.
- Commonly due to mismatches in encryption algorithm, authentication algorithm, or DH group.
- Phase 1 must be successful for Phase 2 to begin.
- Check IPsec Crypto Profile settings on both sides.
Memory trick: Phase 2 needs a perfect pair, or it won't share.
IKE Phase 1 Proposal Mismatch
Flip cardIKE Phase 1 requires both VPN peers to agree on a common set of cryptographic algorithms (encryption, authentication, DH group) defined in their IKE Crypto Profiles.
- Error 'No proposal chosen' indicates this mismatch.
- Occurs during IKE Phase 1, before authentication.
- All parameters (encryption, auth, DH group) must have at least one common value.
Memory trick: IKE Phase 1: Key Exchange, Keep Everything Consistent.
Threat Prevention False Positive Mitigation
Flip cardWhen legitimate application traffic is incorrectly flagged by threat prevention signatures, the most effective immediate mitigation is to create a targeted exception for the specific signature(s) and application.
- Aims for minimal security posture reduction.
- Exceptions are granular, not global.
- Allows continued protection for other traffic.
Memory trick: False Positives: 'Fine-tune' the 'Filters', don't 'Flee'.
NAT & Security Policy
Flip cardWhen troubleshooting NAT and Security policy, remember that Security policy evaluation occurs *after* NAT. Ensure your Security policy rules match the post-NAT addresses and zones.
- Security policy evaluates post-NAT addresses.
- 'Default-deny' after NAT implies missing allow rule.
- NAT order is critical for correct translation.
Memory trick: Change the address, then check the guest list for the new address.
HA Link State Group
Flip cardA High Availability feature that monitors the operational status of grouped interfaces and can trigger state changes (e.g., non-functional, failover) if a defined threshold of links go down.
- Ensures the firewall only stays active if critical interfaces are up.
- Configured under Network > High Availability > Link State Group.
- Interfaces are added to a group, and a threshold is set.
Memory trick: Link State Groups keep the heart of HA beating.
test routing-flow
Flip cardA Palo Alto Networks CLI command that simulates a packet flow through the firewall's routing engine to determine the egress interface and next-hop.
- Useful for diagnosing routing issues.
- Can specify source/destination IP, port, protocol, and ingress interface.
- Shows the exact routing decision the firewall would make.
Memory trick: Test the flow to know where the packets go.
SSL Decryption Performance
Flip cardSSL decryption can be CPU-intensive. Troubleshooting involves identifying specific traffic causing bottlenecks and selectively excluding it from decryption to optimize firewall performance.
- High CPU is a common symptom.
- Targeted exclusion is preferred over broad disabling.
- Consider sensitive or unneeded traffic for exclusion.
Memory trick: Decrypting everything is like trying to read every book in the library at once; focus on the important ones.
Return Traffic Policy
Flip cardFor successful communication through a firewall, both inbound and outbound (return) traffic must be explicitly allowed by security policies, especially when crossing zone boundaries.
- Palo Alto firewalls are stateful, but policies still apply to new sessions.
- Return traffic for initiated sessions is typically allowed by the stateful inspection.
- However, if the server initiates a *new* connection or a policy explicitly blocks the return path, issues arise.
Memory trick: DMZ traffic needs a 'Return Ticket' policy.
GlobalProtect RADIUS Source Interface
Flip cardFor external authentication like RADIUS, a Palo Alto Networks firewall must have a correctly configured source interface and an allowing security policy to send authentication requests.
- Even if pingable, authentication traffic might be blocked.
- Source interface in RADIUS profile dictates egress zone.
- Security policy must allow UDP 1812/1813 from firewall to RADIUS server.
Memory trick: GlobalProtect needs a 'Right Path' for RADIUS requests.
L3 Subinterface Troubleshooting
Flip cardVerifying the operational status and configuration of a Layer 3 subinterface on a Palo Alto Networks firewall is essential for initial connectivity troubleshooting.
- Subinterfaces require VLAN tags.
- Must be up/up to pass traffic.
- IP address and zone assignment are critical.
Memory trick: Subinterface needs 'Status Check' for a Solid Link.
App-ID Incomplete/Unknown
Flip cardThe 'incomplete' and 'unknown-tcp' application identifications often indicate underlying network issues (like asymmetric routing) or the firewall not seeing the full session, hindering App-ID.
- 'incomplete' = firewall didn't see full handshake.
- 'unknown-tcp' = firewall can't identify app on known port.
- Asymmetric routing is a common cause.
Memory trick: App-ID is a detective; if it only gets half the clues, it can't solve the mystery.
App-ID Verification
Flip cardVerifying how the Palo Alto Networks firewall identifies specific applications in live traffic is crucial for troubleshooting security policy enforcement.
- App-ID identifies applications regardless of port.
- Policies rely on accurate App-ID.
- Misidentification can lead to policy bypass or incorrect blocking.
Memory trick: Identify the App, then Apply the Policy.
Security Policy Troubleshooting
Flip cardTroubleshooting Security policy involves verifying that traffic matches the intended rule by checking parameters like zones, addresses, applications, and service, and ensuring correct rule order.
- Rules are evaluated top-down.
- Default-deny catches unmatched traffic.
- Zones are critical for initial rule matching.
Memory trick: The firewall checks its checklist from top to bottom; miss one detail, and it's a no-go.
Firewall Management Access Control
Flip cardPalo Alto Networks firewalls restrict management access to specific IP addresses defined in the Management Interface Profile or 'Permitted IP Addresses' list under Device > Setup > Management.
- Prevents unauthorized management access.
- If source IP is not permitted, connections are refused.
- Crucial for Panorama to connect to managed firewalls.
Memory trick: Permitted IPs must open the door for Panorama's call.
User-ID Log Source
Flip cardPalo Alto Networks User-ID agents primarily gather user-to-IP mappings by monitoring Windows Security Event logs on domain controllers.
- Monitors Event ID 4624 (successful logon).
- Requires appropriate permissions for the User-ID agent service account.
- Key for accurate policy enforcement based on users.
Memory trick: Security logs secure the user's ID.
SSL Decryption Performance Optimization
Flip cardTo mitigate high CPU utilization from SSL decryption, selectively bypassing decryption for less critical traffic or trusted categories can provide immediate performance relief.
- Decryption is resource-intensive.
- Bypassing reduces CPU load.
- Start with categories like 'financial-services' (no-decrypt) or 'streaming-media' (decrypt-no-inspect).
Memory trick: Bypass the non-essentials to boost the firewall's essentials.
Firewall Panorama Registration
Flip cardFor a Palo Alto Networks firewall to be managed by Panorama, the Panorama server's IP address must be explicitly configured on the firewall under its Panorama Settings.
- Enables the firewall to initiate/accept connections from Panorama.
- Crucial for Panorama to push configurations and retrieve logs.
- Located at Device > Setup > Management > Panorama Settings on the firewall.
Memory trick: Tell the firewall where its Panorama home is.
SSL Inbound Inspection (Server Decryption)
Flip cardA decryption method used to inspect encrypted traffic destined for internal servers protected by the firewall. It requires the firewall to possess the private key of the server's certificate.
- Used for traffic flowing to internal servers.
- Requires the server's private key on the firewall.
- No client-side certificate installation is needed for internal clients.
Memory trick: Inbound is for the server, Forward is for the client's journey out.
User-ID Authentication Policy
Flip cardA feature that enforces user authentication against a directory service for network access, allowing granular control over who can access what.
- Requires an Authentication Profile pointing to a directory service.
- Can be applied to specific zones, source/destination IPs, or users/groups.
- Challenges users with a login prompt (e.g., Captive Portal or transparent authentication).
Memory trick: Users need a key to the web gate.
Palo Alto Networks Destination NAT
Flip cardA NAT type that modifies the destination IP address of incoming packets, typically used to translate public IP addresses to private internal server IP addresses.
- Applied to traffic entering the firewall from an external network.
- Original Packet fields reflect the incoming packet's headers.
- Translated Packet fields show the modifications made by the NAT rule.
Memory trick: Original is public view, Translated is private reality.
GlobalProtect Gateway Redundancy
Flip cardImplementing multiple GlobalProtect Gateways to provide high availability and load balancing for remote user VPN connections, ensuring continuous access to internal resources.
- Ensures continuous connectivity for remote users.
- Supports load balancing across multiple gateways.
- Requires configuration of multiple gateways in the Portal.
Memory trick: The Gateway is the gatekeeper to your network; make sure you have more than one!
GlobalProtect RADIUS 2FA
Flip cardConfiguring GlobalProtect to authenticate users using a RADIUS server, commonly for two-factor authentication, by defining the RADIUS server and an authentication profile.
- RADIUS Server Profile defines connectivity to the RADIUS server.
- Authentication Profile references the RADIUS Server Profile.
- Authentication Profile is applied to the GlobalProtect Portal and/or Gateway.
Memory trick: RADIUS is the server, Profile is the method.
Panorama Policy Rule Hierarchy
Flip cardPanorama manages policy rules in a hierarchical structure, including Shared Policies, Device Group Policies (pre-rules, rules, post-rules), and Local Device Rules, with evaluation order from top to bottom.
- Shared policies apply globally to all managed firewalls.
- Device group policies apply only to firewalls within that specific device group.
- Rules are evaluated from Shared Pre-Rules, then Device Group Pre-Rules, Device Group Rules, Device Group Post-Rules, Shared Post-Rules, and finally Local Rules.
Memory trick: Global rules first, then specific group rules, then local device rules.
Application Override for Proprietary Apps
Flip cardUsing an Application Override policy to ensure custom or proprietary applications, especially those on non-standard ports or misidentified by App-ID, are correctly classified by the firewall.
- Provides granular control for specific traffic flows.
- Forces App-ID classification, overriding default signatures.
- Essential for maintaining security while supporting unique applications.
Memory trick: When the custom gear is unknown, give it a specific override label.