Palo Alto Networks Certified Network Security Engineer (PCNSE)Manage and OperateHard

A large enterprise uses Panorama to manage hundreds of Palo Alto Networks firewalls globally. They have implemented a standard security policy that applies to most firewalls, defined in a Device Group. However, a specific branch office firewall requires two unique security rules that must always be evaluated *before* any of the standard rules from the Device Group. How should these unique rules be configured in Panorama to ensure they take precedence?

  1. APlace the rules in a Post-Rulebase in the Device Group or Shared policy.
  2. BCreate the rules in a new Device Group with higher priority.
  3. CConfigure the rules directly on the branch firewall's local configuration.
  4. DPlace the rules in a Pre-Rulebase in the Device Group or Shared policy.
Show answer & explanation

Correct answer: D. Place the rules in a Pre-Rulebase in the Device Group or Shared policy.

In Panorama, policies are evaluated in a specific order: Shared Pre-Rulebase > Device Group Pre-Rulebase > Device Group Rulebase > Device Group Post-Rulebase > Shared Post-Rulebase > Local Firewall Rulebase. To ensure unique rules are evaluated *before* standard Device Group rules, they must be placed in a Pre-Rulebase (either at the Device Group level or Shared level, depending on scope).

Why the other options are wrong

  • A. Post-Rulebase rules are evaluated *after* the main Device Group rulebase, so they would not take precedence.
  • B. Device Group priority affects which Device Group's rules are applied to a firewall, but not the order of rules within the policy stack.
  • C. Local firewall rules are evaluated *after* all Panorama-managed rules (Pre, Rulebase, Post), so they would not take precedence.

Panorama Policy Rule Evaluation Order

Panorama evaluates security policy rules in a hierarchical order: Shared Pre-Rulebase, Device Group Pre-Rulebase, Device Group Rulebase, Device Group Post-Rulebase, Shared Post-Rulebase, and finally, Local Firewall Rulebase.

  • Pre-Rulebase rules are evaluated first, used for high-priority or exceptions.
  • Main Rulebase contains the general, standard policies.
  • Post-Rulebase rules are evaluated last, often for cleanup or specific overrides.
  • Local firewall rules are always evaluated last, after all Panorama rules.

Memory trick: Pre-rules prevail, Post-rules prevail not, Local rules last, that's the policy plot.

More Manage and Operate questions