Palo Alto Networks Certified Network Security Engineer (PCNSE)Manage and OperateHard

A network security administrator is configuring a new firewall for a data center. The data center hosts multiple critical servers, and the security policy requires that all servers in the 'DMZ' zone can initiate connections to servers in the 'Internal_Prod' zone on specific ports, but 'Internal_Prod' servers should never initiate connections back to the 'DMZ'. Additionally, 'Internal_Prod' servers must not initiate connections to each other, except for specific database replication traffic. How should the administrator design the security policy rules to enforce these requirements with the principle of least privilege?

  1. ACreate specific 'allow' rules from DMZ to Internal_Prod. Create a 'deny-all' rule within Internal_Prod zone. Allow specific database replication rules within Internal_Prod above the deny-all.
  2. BCreate specific 'allow' rules from DMZ to Internal_Prod. Create a 'deny-all' rule between Internal_Prod and DMZ. Allow specific database replication rules within Internal_Prod.
  3. CCreate specific 'allow' rules from DMZ to Internal_Prod. Use an 'intrazone-block' policy for Internal_Prod. Allow specific database replication rules within Internal_Prod.
  4. DCreate specific 'allow' rules from DMZ to Internal_Prod, and a general 'deny' rule from Internal_Prod to DMZ. Allow specific database replication rules within Internal_Prod.
Show answer & explanation

Correct answer: C. Create specific 'allow' rules from DMZ to Internal_Prod. Use an 'intrazone-block' policy for Internal_Prod. Allow specific database replication rules within Internal_Prod.

The 'intrazone-block' policy (or a 'deny' rule with source/destination being the same zone) is the most efficient way to prevent traffic *within* a zone by default. Then, specific 'allow' rules for database replication can be placed above it. For inter-zone traffic, specific 'allow' rules from DMZ to Internal_Prod, and relying on the implicit deny for Internal_Prod to DMZ or an explicit 'deny' rule is appropriate.

Why the other options are wrong

  • A. A 'deny-all' rule *within* Internal_Prod zone is the correct concept for intrazone blocking, but 'deny-all' is too broad if it's not specifically an intrazone block, and the 'intrazone-block' is a more precise and efficient feature.
  • B. A 'deny-all' rule *between* Internal_Prod and DMZ is too broad; it would block the allowed DMZ to Internal_Prod traffic. This option also doesn't efficiently handle intrazone blocking.
  • D. This addresses inter-zone but not intrazone. A general 'deny' rule from Internal_Prod to DMZ would be correct, but it doesn't solve the intrazone restriction within Internal_Prod.

Intrazone Policy

Palo Alto Networks firewalls allow explicit security policies to control traffic *within* the same security zone (intrazone traffic). By default, intrazone traffic is allowed, but this can be changed to 'deny' and then specific 'allow' rules added.

  • Default: intrazone traffic is allowed.
  • Can be set to 'deny' for strict segmentation.
  • Requires explicit 'allow' rules for permitted intrazone communication.

Memory trick: Intrazone is like managing roommates: deny all by default, then allow specific shared activities.

More Manage and Operate questions