Palo Alto Networks Certified Network Security Engineer (PCNSE)Manage and OperateEasy

A network security engineer is tasked with configuring a Palo Alto Networks firewall to allow only specific applications to access the internet, while blocking all other traffic. The security policy currently contains a broad 'allow-all-outbound' rule at the bottom. Which of the following actions should the engineer take to ensure only the approved applications are permitted?

  1. ADelete the 'allow-all-outbound' rule and rely on the implicit deny rule at the very bottom of the policy list.
  2. BCreate new 'allow' rules for specific applications above the 'allow-all-outbound' rule, and keep the 'allow-all-outbound' rule as is.
  3. CCreate new 'allow' rules for specific applications above the 'allow-all-outbound' rule, and then change the 'allow-all-outbound' rule to 'deny'.
  4. DCreate new 'deny' rules for all unapproved applications below the 'allow-all-outbound' rule.
Show answer & explanation

Correct answer: C. Create new 'allow' rules for specific applications above the 'allow-all-outbound' rule, and then change the 'allow-all-outbound' rule to 'deny'.

To achieve a 'whitelist' approach where only specific applications are allowed, you must explicitly permit the desired traffic and then explicitly deny all other traffic. Placing specific 'allow' rules above a 'deny-all' rule ensures only the intended traffic passes.

Why the other options are wrong

  • A. While deleting the 'allow-all-outbound' rule and relying on the implicit deny is an option, it's generally better practice to have an explicit 'deny-all' rule for clarity and control, especially when managing specific 'allow' rules.
  • B. This would still allow all other traffic due to the broad 'allow-all-outbound' rule at the bottom.
  • D. Rules are evaluated from top to bottom; 'deny' rules below an 'allow-all' rule would never be hit.

Security Policy Logic

Palo Alto Networks firewalls evaluate security policy rules from top to bottom. The first rule that matches the traffic criteria is applied, and no further rules are evaluated for that session.

  • Rules are processed sequentially from top to bottom.
  • The first match determines the action (allow/deny).
  • A 'deny' rule at the bottom acts as a catch-all for unwanted traffic.

Memory trick: Top-Down Traffic Cop: The first rule matched directs the flow.

More Manage and Operate questions