Palo Alto Networks Certified Network Security Engineer (PCNSE)Manage and OperateEasy

A network administrator needs to troubleshoot an issue where users are reporting slow access to an external SaaS application. The firewall's traffic logs show sessions to the SaaS application, but the 'Action' column indicates 'deny' for some connections, while others show 'allow'. The security policy contains multiple rules that could potentially match this traffic based on source, destination, and application. What is the most effective first step to identify which specific security policy rule is responsible for denying the traffic?

  1. AReview the security policy rules from top to bottom, looking for a 'deny' rule matching the traffic.
  2. BCheck the firewall's session browser for active sessions to the SaaS application.
  3. CFilter the traffic logs for the affected source IP and destination IP, then examine the 'Rule' column for denied sessions.
  4. DRun a packet capture on the firewall interface facing the internet.
Show answer & explanation

Correct answer: C. Filter the traffic logs for the affected source IP and destination IP, then examine the 'Rule' column for denied sessions.

The 'Rule' column in the traffic logs explicitly identifies which security policy rule was matched for a given session. Filtering for denied sessions and examining this column is the quickest way to pinpoint the problematic rule.

Why the other options are wrong

  • A. Manually reviewing policies is time-consuming and error-prone, especially with many rules. The logs provide direct evidence.
  • B. The session browser shows active sessions but doesn't provide historical 'deny' information or the matching rule for denied sessions.
  • D. Packet captures are useful for low-level network issues but are overkill and less efficient for identifying a specific policy rule match.

Traffic Log Rule Column

The 'Rule' column in Palo Alto Networks traffic logs explicitly displays the name of the security policy rule that was matched and applied to a specific network session.

  • Directly identifies the matched security policy rule.
  • Crucial for troubleshooting policy-related issues.
  • Available for both allowed and denied sessions.

Memory trick: When traffic is denied, the 'Rule' column in logs points fingers.

More Manage and Operate questions