Palo Alto Networks Certified Network Security Engineer (PCNSE)Deploy and ConfigureMedium

A security auditor discovers that a critical web server in the DMZ is still accessible via HTTP (port 80) despite a security policy intending to restrict access to HTTPS (port 443) only. Upon inspection, the security policy is configured as follows: Source Zone: Any, Destination Zone: DMZ, Application: web-browsing, Service: application-default, Action: Allow. What is the most likely reason for HTTP traffic still being allowed?

  1. AThe web server is explicitly configured to listen on port 80, bypassing the firewall.
  2. BThe security policy is placed below another policy that explicitly allows HTTP.
  3. CThere is a hidden implicit allow rule for HTTP traffic.
  4. DThe 'Service: application-default' setting includes both HTTP and HTTPS for the 'web-browsing' application.
Show answer & explanation

Correct answer: D. The 'Service: application-default' setting includes both HTTP and HTTPS for the 'web-browsing' application.

The 'web-browsing' application in Palo Alto Networks, when used with 'Service: application-default', includes both HTTP (port 80) and HTTPS (port 443) by default. To restrict access to HTTPS only, the 'Service' field should be explicitly set to 'ssl' or 'tcp/443' instead of 'application-default'.

Why the other options are wrong

  • A. While the server listens on port 80, the firewall should still block it if configured correctly; this is a firewall misconfiguration issue.
  • B. While possible, the most direct and common reason for this specific scenario with 'web-browsing' and 'application-default' is the default behavior of that service.
  • C. There are no hidden implicit allow rules for specific application traffic; implicit rules are for inter-zone deny and intra-zone allow.

Application-Default Service

The 'application-default' service setting in a Palo Alto Networks security policy allows traffic on the standard ports associated with a specified application.

  • Simplifies policy creation by mapping apps to common ports.
  • Can inadvertently allow unwanted services if not carefully reviewed.
  • For granular control, specify custom service objects (e.g., 'tcp/443').

Memory trick: Policy Rules: Order, Source, Dest, App, Service, Action.

More Deploy and Configure questions