Palo Alto Networks Certified Network Security Engineer (PCNSE)Manage and OperateMedium
A security engineer configured a new security policy rule to block all traffic from a specific malicious IP address. After committing the changes, users report that legitimate traffic from other internal subnets is also being blocked when trying to access internal resources. Upon review, the engineer notices the new 'block' rule is placed at the very top of the security policy rulebase. What is the most likely cause for the unintended blocking of legitimate traffic?
- AThe security policy rulebase is processed from bottom to top.
- BNAT policies are misconfigured, redirecting legitimate traffic to the block rule.
- CThe new block rule has a broader application than intended, matching legitimate traffic.
- DThe firewall is operating in a fail-open state due to the new rule.
Show answer & explanationAnswer & explanation
Correct answer: C. The new block rule has a broader application than intended, matching legitimate traffic.
Palo Alto Networks firewalls process security policy rules from top to bottom, stopping at the first rule that matches the traffic. If a new block rule is placed at the top and its match criteria (e.g., source, destination, application) are too broad, it can inadvertently match and block legitimate traffic that would otherwise be allowed by lower, more specific rules.
Why the other options are wrong
- A. Security policies are processed top-to-bottom, not bottom-to-top.
- B. NAT policies primarily affect address translation, not the order or evaluation logic of security policies.
- D. A misconfigured security rule does not typically cause a firewall to enter a fail-open state; it simply misapplies policy.
Security Policy Rule Order
Palo Alto Networks firewalls process security policy rules sequentially from top to bottom, applying the first rule that matches the traffic.
- Rules are evaluated in numerical order, from top to bottom.
- The first matching rule's action (Allow, Deny, Drop) is applied.
- More specific rules should generally be placed above more general rules to avoid unintended blocks or permits.
Memory trick: Top-down processing means the first match wins the traffic's fate.