A network administrator is troubleshooting an issue where users are unable to access a newly deployed internal web application. The application server is located in the 'Internal-Server' zone, and users are in the 'Internal-User' zone. The security policy allowing this traffic is configured as Source: Internal-User, Destination: Internal-Server, Application: web-browsing, Service: application-default, Action: Allow. However, the firewall traffic logs show sessions being dropped with the 'incomplete' application. What is the most likely cause of this issue?
- AThe firewall's decryption policy is blocking the traffic before App-ID can identify it.
- BThe 'web-browsing' application is incorrectly configured to block HTTP/HTTPS traffic.
- CThe Application-ID engine is unable to identify the application because the initial packets (SYN/SYN-ACK) are not reaching the server or the server is not responding.
- DThe security policy rule is placed too low in the rulebase, and another rule is blocking the traffic.
Show answer & explanationAnswer & explanation
Correct answer: C. The Application-ID engine is unable to identify the application because the initial packets (SYN/SYN-ACK) are not reaching the server or the server is not responding.
The 'incomplete' application in traffic logs typically indicates that the firewall saw the initial packets of a session (e.g., SYN) but did not see the complete TCP handshake (SYN-ACK, ACK) or subsequent application data. This suggests a routing issue, a server not listening, or a network path problem preventing the session from fully establishing, and thus App-ID cannot identify the application.
Why the other options are wrong
- A. If decryption was blocking, the logs would show a decryption-related action (e.g., 'decrypt-no-resource', 'decrypt-block'), not 'incomplete' as the application.
- B. The 'web-browsing' application itself does not block traffic; it identifies it. The 'Action: Allow' in the policy would permit it if identified.
- D. If another rule was blocking, the action would likely be 'deny' or 'drop' by that rule, not 'incomplete' on a later rule.
Palo Alto Networks 'incomplete' Application
The 'incomplete' application in Palo Alto Networks traffic logs signifies that the firewall observed the initial packets of a session but the session did not fully establish (e.g., TCP handshake did not complete), preventing App-ID from identifying the actual application.
- Indicates an unestablished session.
- Often points to routing, server availability, or network path issues.
- App-ID cannot function without a complete session setup.
Memory trick: Incomplete: Handshake Not Done, App-ID Can't Run.