Palo Alto Networks Certified Network Security Engineer (PCNSE)Deploy and ConfigureMedium
A security auditor discovers that a critical web server in the DMZ is still accessible via HTTP (port 80) despite a security policy intending to restrict access to HTTPS (port 443) only. Upon inspection, the security policy is configured as follows: Source Zone: Any, Destination Zone: DMZ, Application: web-browsing, Service: application-default, Action: Allow. What is the most likely reason for HTTP traffic still being allowed?
- AThe web server is explicitly configured to listen on port 80, bypassing the firewall.
- BThe security policy is placed below another policy that explicitly allows HTTP.
- CThere is a hidden implicit allow rule for HTTP traffic.
- DThe 'Service: application-default' setting includes both HTTP and HTTPS for the 'web-browsing' application.
Show answer & explanationAnswer & explanation
Correct answer: D. The 'Service: application-default' setting includes both HTTP and HTTPS for the 'web-browsing' application.
The 'web-browsing' application in Palo Alto Networks, when used with 'Service: application-default', includes both HTTP (port 80) and HTTPS (port 443) by default. To restrict access to HTTPS only, the 'Service' field should be explicitly set to 'ssl' or 'tcp/443' instead of 'application-default'.
Why the other options are wrong
- A. While the server listens on port 80, the firewall should still block it if configured correctly; this is a firewall misconfiguration issue.
- B. While possible, the most direct and common reason for this specific scenario with 'web-browsing' and 'application-default' is the default behavior of that service.
- C. There are no hidden implicit allow rules for specific application traffic; implicit rules are for inter-zone deny and intra-zone allow.
Application-Default Service
The 'application-default' service setting in a Palo Alto Networks security policy allows traffic on the standard ports associated with a specified application.
- Simplifies policy creation by mapping apps to common ports.
- Can inadvertently allow unwanted services if not carefully reviewed.
- For granular control, specify custom service objects (e.g., 'tcp/443').
Memory trick: Policy Rules: Order, Source, Dest, App, Service, Action.