A large enterprise uses Panorama to manage hundreds of Palo Alto Networks firewalls globally. They have implemented a standard security policy that applies to most firewalls, defined in a Device Group. However, a specific branch office firewall requires two unique security rules that must always be evaluated *before* any of the standard rules from the Device Group. How should these unique rules be configured in Panorama to ensure they take precedence?
- APlace the rules in a Post-Rulebase in the Device Group or Shared policy.
- BCreate the rules in a new Device Group with higher priority.
- CConfigure the rules directly on the branch firewall's local configuration.
- DPlace the rules in a Pre-Rulebase in the Device Group or Shared policy.
Show answer & explanationAnswer & explanation
Correct answer: D. Place the rules in a Pre-Rulebase in the Device Group or Shared policy.
In Panorama, policies are evaluated in a specific order: Shared Pre-Rulebase > Device Group Pre-Rulebase > Device Group Rulebase > Device Group Post-Rulebase > Shared Post-Rulebase > Local Firewall Rulebase. To ensure unique rules are evaluated *before* standard Device Group rules, they must be placed in a Pre-Rulebase (either at the Device Group level or Shared level, depending on scope).
Why the other options are wrong
- A. Post-Rulebase rules are evaluated *after* the main Device Group rulebase, so they would not take precedence.
- B. Device Group priority affects which Device Group's rules are applied to a firewall, but not the order of rules within the policy stack.
- C. Local firewall rules are evaluated *after* all Panorama-managed rules (Pre, Rulebase, Post), so they would not take precedence.
Panorama Policy Rule Evaluation Order
Panorama evaluates security policy rules in a hierarchical order: Shared Pre-Rulebase, Device Group Pre-Rulebase, Device Group Rulebase, Device Group Post-Rulebase, Shared Post-Rulebase, and finally, Local Firewall Rulebase.
- Pre-Rulebase rules are evaluated first, used for high-priority or exceptions.
- Main Rulebase contains the general, standard policies.
- Post-Rulebase rules are evaluated last, often for cleanup or specific overrides.
- Local firewall rules are always evaluated last, after all Panorama rules.
Memory trick: Pre-rules prevail, Post-rules prevail not, Local rules last, that's the policy plot.