Palo Alto Networks Certified Network Security Engineer (PCNSE)Plan and DesignEasy
A company is implementing a new application that requires a specific set of ports for communication between the web server (DMZ) and the database server (Internal). The network security team wants to ensure that only these specific ports are allowed, and no other traffic is permitted between these two servers. Which type of security policy rule is best suited to achieve this granular control?
- AZone-based policy with 'any' service.
- BUser-based policy with specific user groups.
- CService-based policy with specific port objects.
- DApplication-based policy with 'any' application.
Show answer & explanationAnswer & explanation
Correct answer: C. Service-based policy with specific port objects.
To allow only a 'specific set of ports' and deny all others between two servers, a service-based policy defining custom service objects for those exact ports is the most granular and appropriate method. This ensures only the required L4 ports are open.
Why the other options are wrong
- A. Using 'any' service would allow all ports, violating the requirement for 'only these specific ports'.
- B. User-based policies control access based on users, not specific ports between servers, making it irrelevant for this scenario.
- D. Using 'any' application would allow all applications, which is too broad. While App-ID can identify applications, the requirement specifically mentions 'ports', making Service the primary focus.
Service-Based Security Policy
A security policy rule that controls network traffic based on specific TCP/UDP ports and protocols (services).
- Uses Layer 4 (port/protocol) information.
- Allows granular control over which services are permitted.
- Often combined with Application-ID for deeper inspection.
Memory trick: To hit the right port, use the Service report.