Palo Alto Networks Certified Network Security Engineer (PCNSE)Manage and OperateHard

A network administrator is troubleshooting an issue where users are unable to access a newly deployed internal web application. The application server is located in the 'Internal-Server' zone, and users are in the 'Internal-User' zone. The security policy allowing this traffic is configured as Source: Internal-User, Destination: Internal-Server, Application: web-browsing, Service: application-default, Action: Allow. However, the firewall traffic logs show sessions being dropped with the 'incomplete' application. What is the most likely cause of this issue?

  1. AThe firewall's decryption policy is blocking the traffic before App-ID can identify it.
  2. BThe 'web-browsing' application is incorrectly configured to block HTTP/HTTPS traffic.
  3. CThe Application-ID engine is unable to identify the application because the initial packets (SYN/SYN-ACK) are not reaching the server or the server is not responding.
  4. DThe security policy rule is placed too low in the rulebase, and another rule is blocking the traffic.
Show answer & explanation

Correct answer: C. The Application-ID engine is unable to identify the application because the initial packets (SYN/SYN-ACK) are not reaching the server or the server is not responding.

The 'incomplete' application in traffic logs typically indicates that the firewall saw the initial packets of a session (e.g., SYN) but did not see the complete TCP handshake (SYN-ACK, ACK) or subsequent application data. This suggests a routing issue, a server not listening, or a network path problem preventing the session from fully establishing, and thus App-ID cannot identify the application.

Why the other options are wrong

  • A. If decryption was blocking, the logs would show a decryption-related action (e.g., 'decrypt-no-resource', 'decrypt-block'), not 'incomplete' as the application.
  • B. The 'web-browsing' application itself does not block traffic; it identifies it. The 'Action: Allow' in the policy would permit it if identified.
  • D. If another rule was blocking, the action would likely be 'deny' or 'drop' by that rule, not 'incomplete' on a later rule.

Palo Alto Networks 'incomplete' Application

The 'incomplete' application in Palo Alto Networks traffic logs signifies that the firewall observed the initial packets of a session but the session did not fully establish (e.g., TCP handshake did not complete), preventing App-ID from identifying the actual application.

  • Indicates an unestablished session.
  • Often points to routing, server availability, or network path issues.
  • App-ID cannot function without a complete session setup.

Memory trick: Incomplete: Handshake Not Done, App-ID Can't Run.

More Manage and Operate questions