A web server administrator reports that users are unable to access a newly deployed web application hosted on an internal server. The Palo Alto Networks firewall is configured with a Destination NAT policy to translate the public IP address to the internal web server's private IP. Security policies are in place to allow the traffic. Using the 'test security-policy-match' command on the firewall, the administrator observes that the traffic is hitting the correct security policy, but the 'action' shown is 'deny' even though the policy is configured to 'allow'. What is the MOST likely reason for this discrepancy?
- AThe source zone in the security policy does not match the zone from which the traffic is arriving after NAT.
- BThe Destination NAT policy is misconfigured and not translating the destination IP.
- CThe service configured in the security policy is incorrect for the web application.
- DThe application-id of the traffic is not matching the application configured in the security policy.
Show answer & explanationAnswer & explanation
Correct answer: D. The application-id of the traffic is not matching the application configured in the security policy.
If the 'test security-policy-match' command shows the policy being hit but the action is 'deny' despite the policy being configured to 'allow', it strongly suggests that a criteria *within* the policy itself is not being met. Since the security policy is processed after NAT, and the question implies the policy is found, the most subtle and common reason for this behavior in a Palo Alto Networks firewall is an application mismatch. The policy might allow 'web-browsing' but the actual application might be 'ssl' or a custom application, leading to a deny.
Why the other options are wrong
- A. The source zone is evaluated *before* policy match. If the source zone was incorrect, the policy wouldn't be matched at all.
- B. If NAT was misconfigured, the traffic wouldn't hit the correct security policy in the first place, or it would hit a default deny rule.
- C. If the service (port) was incorrect, the policy wouldn't be matched, or it would match a different policy/deny rule. The scenario states it hits the correct policy.
Security Policy Application Mismatch
Palo Alto Networks firewalls perform deep packet inspection to identify the actual application. If a security policy allows traffic based on a particular application, but the firewall identifies a different application, the policy's 'allow' action may not apply, resulting in a deny.
- Application-ID is critical for policy enforcement.
- Policies can be hit, but still deny if application criteria are not met.
- Default 'any' application is broad; specific applications are more restrictive.
Memory trick: The guard knows you, but not your secret handshake to enter!