Palo Alto Networks Certified Network Security Engineer (PCNSE)Manage and OperateHard

A network administrator is implementing a new application on a server in the DMZ. The application uses a non-standard port 8443 for HTTPS communication and port 8080 for HTTP. The administrator needs to create an Application Override policy to ensure these applications are correctly identified and inspected by the Palo Alto Networks firewall, rather than being identified as 'web-browsing' or 'ssl'. What is the correct configuration approach for the Application Override policy?

  1. AModify the default 'web-browsing' and 'ssl' application definitions to include ports 8080 and 8443, respectively.
  2. BCreate two Application Override rules: one for port 8443 overriding to 'ssl-custom' and one for port 8080 overriding to 'http-custom'.
  3. CCreate two Application Override rules: one matching TCP/8443 to 'custom-app-https' and another matching TCP/8080 to 'custom-app-http', and then define these custom applications.
  4. DCreate one Application Override rule for the server's IP, specifying port 8443 as 'ssl' and port 8080 as 'web-browsing'.
Show answer & explanation

Correct answer: C. Create two Application Override rules: one matching TCP/8443 to 'custom-app-https' and another matching TCP/8080 to 'custom-app-http', and then define these custom applications.

Application Override is used to force specific traffic on non-standard ports to be identified as a custom application. The correct approach is to define custom applications (e.g., 'custom-app-https', 'custom-app-http') and then create Application Override rules that match the specific port and protocol, overriding the default App-ID to these custom applications.

Why the other options are wrong

  • A. Modifying default application definitions is generally not recommended and can lead to unintended consequences for other traffic. Application Override is the intended mechanism for specific non-standard port applications.
  • B. Overriding to 'ssl-custom' or 'http-custom' doesn't exist as built-in applications. You need to define new custom applications first.
  • D. Overriding to 'ssl' or 'web-browsing' is not the purpose of Application Override for non-standard ports; it's to ensure accurate identification of specific custom applications, not to force it back to general web traffic.

Application Override

A Palo Alto Networks feature that allows administrators to force traffic on specific ports and protocols to be identified as a custom application, bypassing the default App-ID engine for that traffic.

  • Used for custom or non-standard port applications.
  • Ensures consistent application identification.
  • Requires defining custom applications first.

Memory trick: Override: Custom App, Custom Port, Custom Rules.

More Manage and Operate questions