Palo Alto Networks Certified Network Security Engineer (PCNSE)Manage and OperateEasy
A network administrator needs to create a security policy rule that applies to all users located in the 'Internal-LAN' zone, regardless of their specific IP address. The rule should allow them to access external web services. Which object type should be used in the Source User field of the security policy rule to achieve this?
- AAn IP address object representing the Internal-LAN subnet.
- BThe 'any' keyword.
- CA custom URL category object.
- DA User-ID user group containing all internal users.
Show answer & explanationAnswer & explanation
Correct answer: D. A User-ID user group containing all internal users.
To apply a security policy rule to all users in a specific zone, regardless of their IP address, you should use a User-ID user group. Once User-ID is configured and mapping users to IP addresses, placing 'all-users' (or a specific user group that includes all relevant users) in the Source User field ensures the policy applies to identified users.
Why the other options are wrong
- A. An IP address object would apply to specific IP addresses, not necessarily all users regardless of their current IP.
- B. The 'any' keyword in the Source User field would apply the rule to any user, including unauthenticated or unknown users, which is not the specific intent of targeting 'all users' within a zone.
- C. A custom URL category object is used in the Service/URL Category field to control access to specific web content, not in the Source User field.
User-ID for Policy Enforcement
User-ID allows Palo Alto Networks firewalls to enforce security policies based on user identity rather than just IP addresses, by mapping IP addresses to usernames.
- Policies applied based on user identity.
- Requires User-ID agent or other mapping methods.
- Enables granular access control.
Memory trick: Source User: User-ID Groups Target People, Not Just IPs.