Palo Alto Networks Certified Network Security Engineer (PCNSE)Deploy and ConfigureHard

A network administrator is troubleshooting an issue where internal users are unable to access a specific external web service. Packet captures on the firewall show that the initial SYN packet from the internal user is leaving the firewall, but no SYN-ACK is being received. Upon checking the security policy, the administrator confirms that an 'allow' rule exists for the application and source/destination zones. What is the MOST likely root cause of this connectivity issue, assuming external reachability is confirmed?

  1. AThe external web service is blocking the connection or its return traffic.
  2. BThe firewall's virtual router is missing a route to the external web service.
  3. CThe NAT policy is incorrectly configured or missing, preventing the external service from responding to the internal IP.
  4. DThe security policy is missing a specific service (port) for the application.
Show answer & explanation

Correct answer: C. The NAT policy is incorrectly configured or missing, preventing the external service from responding to the internal IP.

If the SYN packet leaves the firewall but no SYN-ACK returns, and external reachability is confirmed, an incorrect or missing NAT policy is a common culprit. The external service might receive the internal IP (if NAT is missing) or an incorrect public IP (if NAT is misconfigured), leading it to either drop the packet or send the SYN-ACK to an unreachable address.

Why the other options are wrong

  • A. While possible, the question asks for the 'MOST likely root cause' related to firewall configuration, given the 'allow' rule exists and external reachability is confirmed. A NAT issue on the firewall is more probable than the external service coincidentally blocking only this specific connection.
  • B. If a route was missing, the SYN packet would not leave the firewall's egress interface, contradicting 'SYN packet ... leaving the firewall'.
  • D. If the security policy was missing the service, the 'allow' rule would not match, and the SYN packet would be dropped by the firewall, not allowed to leave.

NAT Policy Troubleshooting (Outbound)

Diagnosing issues where internal hosts cannot reach external resources due to incorrect or missing Network Address Translation (NAT) configurations on the firewall.

  • Initial SYN leaves firewall, but no SYN-ACK returns.
  • Security policy allows traffic.
  • External reachability to destination is verified.
  • Commonly indicates missing or misconfigured Source NAT.

Memory trick: SYN goes out, SYN-ACK's a doubt, NAT's the key to figure it out!

More Deploy and Configure questions